Two pieces of legislation govern the use of artificial intelligence in a European business: the GDPR, whenever personal data is processed, and the EU Artificial Intelligence Act (the AI Act), which has been phased in since 2024. For most small and medium-sized businesses — which use AI rather than build it — the obligations are reasonable: train your people, be transparent, choose serious tools and document anything involving personal data. Here is the essential, without the jargon.
This article sets out a general framework, current at the time of publication; it is not a substitute for legal advice tailored to your situation.
Provider or deployer: what is your role?
The AI Act distinguishes several actors. The two main ones:
- The provider develops an AI system (or has one developed) and places it on the market under its own name.
- The deployer uses an AI system in the course of its professional activity.
A business using an AI assistant, a chatbot or an agent built into its tools is generally a deployer. A company that develops and sells software with AI inside becomes the provider of that system, with broader obligations depending on the level of risk.
The AI Act timeline
Regulation (EU) 2024/1689, published in the Official Journal of the European Union, applies in stages:
| Date | What applies | What it means for a small business |
|---|---|---|
| 1 August 2024 | The regulation enters into force | The application timeline starts |
| 2 February 2025 | Ban on certain practices (social scoring, manipulation, emotion recognition at work) and the AI literacy obligation | People who use AI must be trained to do so |
| August 2025 | Rules for general-purpose AI models | Mainly concerns model providers: favour well-documented tools |
| 2 August 2026 | General application, including transparency rules | Tell people when they are dealing with an AI; label generated content |
| 2 December 2027 | Rules for high-risk systems in certain areas, including employment | AI used to recruit or manage staff: stricter obligations |
The timeline and any adjustments are published on the European Commission’s official page on the regulatory framework for AI, which is worth checking for updates.
What the AI Act actually requires of a small business
Train your people (AI literacy)
Since 2 February 2025, organisations using AI systems must take measures to ensure a sufficient level of AI literacy among the people who use them. A short, practical training session is often enough: what the tool can do, its limits, the data never to share with it, and checking every answer.
Respect the prohibitions
Some practices are banned whatever the size of the business: social scoring, manipulative techniques, exploiting vulnerabilities, emotion recognition in the workplace (except for medical or safety reasons), among others. They rarely concern everyday uses but should be known.
Be transparent
People must know when they are interacting with an AI (a chatbot on your website, for instance), and certain AI-generated or manipulated content must be labelled as such. A clear notice at the start of a conversation is enough in most cases.
Check for high-risk uses
Certain areas are classed as high-risk: recruitment and staff management, access to credit, education, essential services, among others. If you use AI to screen applications or assess employees, the obligations are much heavier (human oversight, documentation, informing the people concerned). Better to identify this early.
What the GDPR requires whenever personal data is involved
The AI Act does not replace the GDPR; it adds to it. As soon as an AI tool processes personal data — a name in an email, a customer file, a CV — the usual principles apply.
- Purpose and lawful basis. Why is the data processed, and on what legal ground?
- Data minimisation. Send the AI only the data strictly needed. Data that is never sent cannot leak.
- Processors. The AI tool’s provider is usually your processor: you need a contract meeting Article 28 of the GDPR, specifying in particular how the data is used and where it is processed.
- Transfers outside the EU. If data is processed outside the European Union, the contract must cover it (standard contractual clauses, for example).
- Retention periods. Conversation histories and logs need a defined, justified retention period.
- Impact assessment. Processing likely to result in a high risk requires a data protection impact assessment (DPIA).
- Records. The processing must appear in your record of processing activities.
National data protection authorities, such as France’s CNIL, publish dedicated guidance on artificial intelligence that is worth reading.
Choosing compliant tools
Your choice of tool does most of the compliance work.
- Business offerings rather than consumer ones. Enterprise plans and API access generally come with contractual commitments: no model training on your data, a data processing agreement, defined retention periods.
- Commitments in writing. Check the clauses in the provider’s contract, not just its marketing page.
- Anonymise sensitive data. When personal or confidential information must be submitted to a model, replacing it with decoys before it is sent greatly reduces the risk. That is the job of our software AIGuard, which also logs every exchange for your GDPR obligations without storing the sensitive content.
- Controlled hosting. Stored data (document libraries, histories) is best kept in-house or with a host in France or the EU.
Our article Using ChatGPT, Claude or Copilot without exposing your data goes through these good practices.
When you build AI into your own product
If your business develops software or a service that includes AI and sells it under its own name, you move from deployer to provider of that system. For most products — an assistant, a document tool, an agent that drafts but does not decide — the obligations remain manageable: transparency towards users, clear documentation, and attention to the risk classification. If the product touches a high-risk area such as recruitment, the provider’s obligations become substantial: risk management, data governance, technical documentation, human oversight and conformity assessment. It pays to establish this at the design stage rather than after launch.
A six-point roadmap
- Inventory the AI tools used in the business, including those adopted informally by staff.
- Classify the uses: everyday, involving personal data, high-risk area.
- Train the people concerned and write a simple usage policy.
- Contract with serious providers, on business plans.
- Inform: transparency notices on chatbots and generated content.
- Document: record of processing, impact assessments where needed, usage log.
When an AI project is designed with these requirements from the start, compliance does not slow it down: it is part of it. That is how we run our artificial intelligence projects.
Frequently asked questions
Does the AI Act apply to a very small business?
Yes, as soon as it uses AI systems in its activity. For everyday use, the obligations boil down mainly to training users, respecting the prohibitions and being transparent.
Can we use ChatGPT with customer data?
Only with care: a business plan with contractual commitments, minimised data and, ideally, personal information anonymised before it is sent.
Do we have to notify a regulator that we use AI?
There is no general notification duty. However, processing of personal data must appear in your records and, where the risk is high, be covered by an impact assessment.
Who is liable if the AI gets it wrong?
The business using the AI remains responsible for the decisions it takes. That is why human review is essential for decisions that affect people.
The Step By Step studio in Ajaccio, Corsica, builds these requirements into every AI project. Let’s discuss your use cases.