Social Digital
← All articlesTendencias

The EU AI Act: what your small business needs to know if it uses ChatGPT

13 September 2026 · 7 min read

TendenciasTendencias

In short

The AI Act has been in force since August 2024 and applies in phases. AI literacy applies from February 2025 and transparency (warning in your chatbot) from 2 August 2026. If you use ChatGPT or Claude in your business you are already a deployer. The big fines are for serious breaches and small businesses get the lower figure. This is not legal advice.

Let us start with the important bit so nobody panics: using ChatGPT in your small business is neither illegal nor going to earn you a fine tomorrow for writing emails with AI. But the EU AI Act is already in force and applies in phases. It is worth knowing what falls to you, without drama and without burying your head in the sand.

Since when it exists and how it applies

The AI Act has been in force since 1 August 2024 and does not switch on all at once: it enters in stages over several years. The logic is to give companies and public bodies time to adapt according to the risk of each AI use.

The dates that matter to you

There are two milestones a normal small business should keep in mind. The first has already passed: since 2 February 2025 the AI literacy obligation (article 4) is in force, which in plain terms means your team must know how to use these tools with judgement, understanding their limits and risks. It is not an official exam; it is making sure whoever uses AI in your business knows what they are doing.

The second is coming soon: on 2 August 2026 the transparency obligations (article 50) kick in and market surveillance authorities start operating. The most practical part for you: if you have a chatbot serving customers, you must warn them they are talking to an AI, not a person. It is common sense and now, on top of that, mandatory.

Careful with the dates you have heard elsewhere

You will have read that the toughest obligations, those for high-risk systems, were arriving in 2026 or 2027. Watch out, because it changed: the Digital Omnibus (EU Regulation 2026/1744, in force since 27 July 2026) postponed those high-risk obligations to December 2027 and August 2028. For the vast majority of small businesses this is good news and, in any case, something that probably does not even apply to you: using a customer-service chatbot is not a high-risk system.

You are already a "deployer"

Here is the concept many people miss. If your business uses ChatGPT, Claude or an AI copilot, you are legally a deployer. You did not create the AI, but you are using it in your activity, and that carries responsibilities: above all, using it transparently and sensibly. Do not be scared by the word; it is your role, and the obligations for a small business using common tools are reasonable.

And the fines?

The penalties exist and look huge on paper: up to 35 million euros or 7% of turnover for prohibited practices, and up to 15 million or 3% for other breaches. But two important caveats: for small businesses and startups the lower figure of the two applies, and those amounts target serious breaches, not a freelancer using ChatGPT to draft text. The regulator's aim is not to hunt you down.

Three simple steps and you are set

You do not need a legal department. First, if you have a chatbot or any AI that talks to your customers, clearly warn that it is an AI. Second, train your team: one session so they understand what they can and cannot feed these tools (no sensitive personal customer data, for instance). And third, make a small inventory of which AI you use and for what; a spreadsheet is plenty. With that, a normal small business is more than in order.

One final note, and we mean it: this is not legal advice. It is a guide to orient you. For your specific case, talk to a professional. At Social Digital we help you with the technical and communication side (the notice in your chatbot, the basic training), and for the legal part we tell you honestly to consult a lawyer.

Frequently asked questions

Do I have to warn that my chatbot is an AI?

Yes. From 2 August 2026 the article 50 transparency obligation requires warning anyone interacting with an AI. A clear message at the start of the chat is enough to comply.

I use ChatGPT in my business, can I be fined?

Not for using it sensibly and transparently. Penalties target serious breaches, and small businesses get the lower of the two figures. Warn in your chatbot, train your team and rest easy.

Do high-risk obligations affect me in 2026?

Almost certainly not. The Digital Omnibus postponed them to December 2027 and August 2028, and a customer-service chatbot is not a high-risk system anyway. For most small businesses this does not apply.

Ready to take the digital leap?

Book a free session or run your audit with our team in Madrid.