Let us start with the important bit so nobody panics: using ChatGPT in your small business is neither illegal nor going to earn you a fine tomorrow for writing emails with AI. But the EU AI Act is already in force and applies in phases. It is worth knowing what falls to you, without drama and without burying your head in the sand.
Since when it exists and how it applies
The AI Act has been in force since 1 August 2024 and does not switch on all at once: it enters in stages over several years. The logic is to give companies and public bodies time to adapt according to the risk of each AI use.
The dates that matter to you
There are two milestones a normal small business should keep in mind. The first has already passed: since 2 February 2025 the AI literacy obligation (article 4) is in force, which in plain terms means your team must know how to use these tools with judgement, understanding their limits and risks. It is not an official exam; it is making sure whoever uses AI in your business knows what they are doing.
The second is coming soon: on 2 August 2026 the transparency obligations (article 50) kick in and market surveillance authorities start operating. The most practical part for you: if you have a chatbot serving customers, you must warn them they are talking to an AI, not a person. It is common sense and now, on top of that, mandatory.
Careful with the dates you have heard elsewhere
You will have read that the toughest obligations, those for high-risk systems, were arriving in 2026 or 2027. Watch out, because it changed: the Digital Omnibus (EU Regulation 2026/1744, in force since 27 July 2026) postponed those high-risk obligations to December 2027 and August 2028. For the vast majority of small businesses this is good news and, in any case, something that probably does not even apply to you: using a customer-service chatbot is not a high-risk system.
You are already a "deployer"
Here is the concept many people miss. If your business uses ChatGPT, Claude or an AI copilot, you are legally a deployer. You did not create the AI, but you are using it in your activity, and that carries responsibilities: above all, using it transparently and sensibly. Do not be scared by the word; it is your role, and the obligations for a small business using common tools are reasonable.
And the fines?
The penalties exist and look huge on paper: up to 35 million euros or 7% of turnover for prohibited practices, and up to 15 million or 3% for other breaches. But two important caveats: for small businesses and startups the lower figure of the two applies, and those amounts target serious breaches, not a freelancer using ChatGPT to draft text. The regulator's aim is not to hunt you down.
Three simple steps and you are set
You do not need a legal department. First, if you have a chatbot or any AI that talks to your customers, clearly warn that it is an AI. Second, train your team: one session so they understand what they can and cannot feed these tools (no sensitive personal customer data, for instance). And third, make a small inventory of which AI you use and for what; a spreadsheet is plenty. With that, a normal small business is more than in order.
One final note, and we mean it: this is not legal advice. It is a guide to orient you. For your specific case, talk to a professional. At Social Digital we help you with the technical and communication side (the notice in your chatbot, the basic training), and for the legal part we tell you honestly to consult a lawyer.

