← All guides

EU AI Act for businesses: a practical guide to obligations

Understand AI Act roles, risks and current deadlines. Use a practical worksheet to identify the next checks for your business.

· 10 min

A small business uses AI to summarise meetings, draft quotes and screen job applicants. It may be the same product, but those are three different uses. The obligations under the AI Act, the EU's artificial intelligence regulation, can differ too. Start with the work the system performs, the people affected and the consequences of an error.

Choose one actual use and complete this sentence: “We use [system] for [task]; its result informs [decision or action] and is seen by [people].” If someone else needs to fill a gap, that is your first information request.

This guide helps businesses operating in Italy document a use case, separate current duties from future preparation and identify questions requiring specialist advice. It is operational guidance, not a legal assessment of your system. Sources and dates were checked on 8 October 2026.

What the AI Act covers

The AI Act is the EU's artificial intelligence regulation, Regulation (EU) 2024/1689, amended in 2026. It sets different obligations for organisations that develop, supply and use AI systems. Small businesses are included: company size affects some measures and penalties, but does not create a general exemption.

The EU connection may depend on where a system is offered, where its user is established or whether its output is used in the Union. Buying from a non-EU supplier does not settle that question. Personal, non-professional use is treated differently; this guide concerns business use. See the official scope and definitions.

Other laws continue to apply. Personal data requires an assessment under GDPR, the EU personal-data regulation; recruitment also raises employment-law questions. A supplier's AI Act statement does not replace either assessment.

First establish your role

A deployer uses an AI system under its authority, such as a business operating a customer-service assistant. A provider develops, or commissions the development of, a system and places it on the market or puts it into service under its own name or trademark.

Commissioning the code does not necessarily transfer your provider role to the developer. If you sell a branded AI product, you may be its provider even though another company supplies the underlying model. The model and the finished system are separate layers; one organisation can also hold several roles.

For high-risk systems, substantial modifications, changed intended purposes and certain rebranding arrangements can transfer provider obligations under Article 25. Compare the supplier's intended purpose with the use you are actually building.

If you buy an internal tool, collect its contract, instructions and enabled features. If you offer it to customers under your own name, assess your provider role as well. “We use someone else's model” does not answer that second question.

Which uses deserve attention first?

Labels such as minimal, limited and high risk are useful introductions, not mutually exclusive boxes that remove every other duty. A high-risk system can also have transparency obligations.

Use First question Before expanding it
Internal summaries or drafts What data is allowed, who checks the result and what training is needed? Assign review responsibility and define information that must not be entered
Customer-facing chatbot Is an AI-interaction notice required, or is the statutory obviousness exception genuinely met? Check the first interaction and the route to a human
Filtering applications or evaluating workers Could the Annex III high-risk classification apply? Assess purpose, influence on decisions and any relevant exception
AI performing a product safety function Does Annex I apply, together with the required third-party conformity assessment? Involve the product safety and conformity owner
Recognising emotions at work or in education Could this be prohibited, outside narrow medical or safety exceptions? Pause that use while the scope is clarified

These examples are not a complete classification. Article 5 covers other prohibited practices with specific conditions, including certain manipulation, exploitation of vulnerabilities, social scoring and biometric uses. Where a prohibition may apply, first establish whether the use is permitted. A disclosure notice cannot make a prohibited use lawful.

Human approval does not automatically remove high-risk status

Consider a recruitment tool that ranks applications and shows a manager only the first ten. The final decision is human, but the system has already influenced who will be considered. Assess that influence, not just who clicks the final button.

Article 6 provides two main routes: certain products or safety components under Annex I, and the uses listed in Annex III, including specified employment, education, credit and essential-service contexts. The product route also depends on the safety function and required third-party conformity assessment. A non-safety convenience feature is not a safety component merely because it uses AI.

Some Annex III systems can qualify for an exception where they pose no significant risk and meet at least one condition in paragraph 3, such as performing a narrow procedural task. Human review alone does not establish this exception. It is unavailable to Annex III systems that profile people by using personal data to evaluate or predict individual characteristics. A provider relying on it must document the assessment and check the registration obligations.

Current AI Act dates

The Act entered into force on 1 August 2024, with different provisions applying at different times. Regulation (EU) 2026/1744, in force since 27 July 2026, changed the timetable. Older tables presenting August 2026 and August 2027 as the general high-risk deadlines can therefore mislead.

Date Main provisions Practical implication
2 February 2025 Initial prohibited practices and AI literacy Check prohibited uses and measures supporting staff competence
2 August 2025 Governance and general-purpose AI model provider duties Separate the model provider's duties from your system-level responsibilities
2 August 2026 Article 50 transparency Review affected interactions, content and functions according to your role
2 December 2026 New prohibition covering specified systems for non-consensual sexual content and child sexual abuse material; end of a specific marking transition Check the exact provision: this is not a general Article 50 postponement
2 December 2027 Chapter III, Sections 1–3 for Annex III high-risk systems Prepare classification, responsibilities and relevant evidence
2 August 2028 Chapter III, Sections 1–3 for Annex I high-risk systems Coordinate AI preparation with product conformity

The transition until 2 December 2026 concerns the provider's Article 50(2) synthetic-output marking duty for systems already placed on the market before 2 August 2026. Separate transitional rules apply to existing systems and models; purchase date alone does not establish a complete exemption. Sources: Commission timetable, Article 113 and Article 111.

Transparency: check the specific situation

Article 50 distinguishes four situations: direct AI interaction; providers' technical marking of synthetic outputs; emotion recognition or biometric categorisation; and deployers showing deepfakes to people and publishing specified public-interest text.

A chatbot may require a notice at the first interaction. A manipulated image requires an assessment of whether it is a deepfake, including whether it falsely appears authentic. For AI-generated or manipulated text published to inform the public on matters of public interest, the regulation provides an exception involving human review or editorial control together with editorial responsibility for publication.

Technical marking and visible disclosure are different duties. A watermark does not automatically discharge a publisher's obligations. A footer can be too late for a notice due at first exposure. The Article 50 guide covers the conditions and examples in detail.

Training should follow the work

Article 4, as amended in 2026, calls for measures supporting the development of AI literacy, taking account of competence, context and affected people. It does not prescribe universal individual certification. Choose learning activities around what staff need to recognise and do.

For quote preparation, useful skills include distinguishing a price retrieved from an approved list from an invented one, spotting missing information and knowing when to request review. An incomplete request makes a practical training exercise. Keep the materials, participants and test result as evidence of the activity, not as an automatic certificate of compliance. See the Commission's AI literacy FAQ.

A worksheet for each use case

Copy this table into a document. Create a separate record for each significant use: the same product may appear several times if it performs different tasks.

Field What to record
Task and consequence What it does, who sees its output and which decision it influences
System and role Product, supplier, version or service; whether you use it or offer it under your brand
Data Information entering the system, destinations and access rights
Applicable checks Prohibited practices, high risk and transparency, with reasons for each conclusion
People Who operates it, reviews its output and can stop it
Evidence Contract, instructions, notice screenshot, tests or documents to request
Next action One concrete gap, an owner and a date; retain unknowns explicitly

For example, an assistant reads commercial enquiries and drafts quotes without replying to customers. An approved price list supplies fixed calculations, and a person checks and sends each quote. Record that boundary and test a request missing a product variant: it should ask for clarification. Adding automatic sending or customer chat requires reopening the assessment because the original operating conditions have changed.

My design criterion is that a change in function should reopen the relevant questions. A file reviewed only once a year can accurately describe a system that no longer exists.

A practical first thirty days

  1. Week one: list actual uses, including tools adopted by individual departments. Start with a case affecting people or producing external actions.
  2. Week two: complete its worksheet with the person responsible for the work. Request missing supplier information and check duties already applicable.
  3. Week three: test a normal request and an ambiguous one, such as missing data or an uncertain result. Check that uncertainty reaches the designated person.
  4. Week four: assign corrections and decide what can continue, what needs restrictions and what requires specialist assessment.

This is an organisational suggestion, not a legal deadline. If a use may be prohibited, restrict or pause it while clarifying its status. If a decisive high-risk classification fact is unknown, avoid expanding that use until it is established. Uncertainty about one use does not automatically require stopping all business AI.

Penalties and adjacent rules

Article 99 sets different maximum penalties: up to €35 million or 7% of the preceding year's worldwide annual turnover for prohibited practices; up to €15 million or 3% for other listed infringements, including transparency. For SMEs, including startups, the lower monetary or percentage ceiling applies. These are maximum limits, with the circumstances and statutory assessment criteria relevant to each case. See Article 99.

GDPR requires a separate personal-data assessment. DORA concerns financial-sector digital operational resilience: it can affect a financial customer's supplier contract, but is not a certificate required for every AI project. The AI Act and DORA guide explains the distinction.

Applying the guide to your system

A completed worksheet already gives you something useful: known facts, missing information and the next decision. If the uncertainty concerns data, integrations, behaviour or technical controls, bring it to an AI and automation diagnosis. We can define the technical work and questions for your legal adviser where needed. If the only missing piece is a supplier answer, request it first; not every uncertainty requires a consulting project.

FAQ

Does the AI Act apply to small businesses?

Yes. There is no general SME exemption: duties depend on the organisation's role and the system's use. Specific support measures and penalty-ceiling rules apply to SMEs.

Does using ChatGPT or Claude make a business an AI provider?

Ordinary business use of a product generally corresponds to the deployer role. Offering a branded system, commissioning its development or changing its intended use can require a different assessment. Distinguish the underlying model from the finished system.

Does every business need AI Act certification?

There is no universal certificate for every business using AI. Certain high-risk systems have specific conformity duties. Article 4 also does not prescribe universal individual certification for AI literacy.

What are the next high-risk deadlines?

Under the timetable checked on 8 October 2026, Chapter III Sections 1–3 apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Prohibitions, transparency and other duties have separate dates.

Where should a business without an internal legal team start?

Document one actual use, the task and decision it influences, the supplier and internal owner. Collect the product instructions and separate known facts from missing information. Seek targeted advice where uncertainty changes classification or whether that use can continue.