The EU AI Act is the first major law dedicated to artificial intelligence, sorting AI tools into different levels of risk and applying stronger rules where the potential for harm is greater. It came into force in August 2024, with rules being introduced in stages between 2025 and 2028, and the timetable has recently changed.
The good news is that most day-to-day business tools, such as spell checkers, spam filters and basic scheduling software, are not affected. However, the Act can apply to any business using AI, including off-the-shelf tools such as chatbots, AI writing assistants and recruitment software, and there is no exemption simply because a business is small.
Our experienced data protection consultant Jo Brianti has put together these ten practical actions to help you get organised and understand what you need to do:
1. List every AI tool you use
Include the obvious ones (chatbots, AI writing tools) and the hidden ones built into software you already pay for.
2. Work out who is affected
Check whether each tool touches customers, job applicants or staff, not just your own admin.
3. Sort each tool by risk
Most small business tools are minimal or limited risk. Flag anything used for recruitment, credit decisions or biometrics as high-risk.
4. Add an AI disclosure where needed
If customers interact with a chatbot or see AI-generated content, tell them plainly. A simple line is enough.
5. Check your AI-generated marketing content
From December 2026, AI-generated images, video or text shown to the public need a clear label.
6. Build basic AI literacy
Make sure you and your team understand what each AI tool does, and its limits. This is a legal requirement, not just good practice.
7. Review any recruitment or HR AI tools
CV screening, shortlisting or staff monitoring tools count as high-risk. Start understanding the requirements now, ahead of December 2027.
8. Ask your AI suppliers the right questions
For any high-risk tool, ask your supplier for evidence they meet the rules. You shouldn’t have to work this out alone.
9. Update your privacy notice and policies
Reflect any AI use in your customer-facing notices and internal policies, in plain English.
10. Put a date in the diary
Revisit this list every few months. AI tools and the rules around them are both moving quickly.
The EU AI Act is already in force, with further obligations coming into effect over the next few years. The key is to understand which AI tools you use, how they are being used and where the Act may apply, rather than trying to overhaul everything at once.
Start by mapping your AI tools, understanding their risk level and making sure your team has the right level of AI literacy. Keep an eye on upcoming requirements, particularly around transparency and the use of AI in recruitment and staff management, and revisit your position regularly as the rules continue to develop.
If you need help understanding how the EU AI Act applies to your business, our team can help you review your AI use and put practical compliance measures in place. For a deeper look at what the Act means for businesses, read our EU AI Act: Does it apply to your business? guide, or get in touch at info@legaledge.co.uk.
