Skip to content
← All posts
· 6 min read· By

EU AI Act Since August 2026 – What SMBs Using ChatGPT, Copilot & Co. Must Do Now

Since 2 August 2026 new obligations under the EU AI Act apply. What small businesses really need to take care of – and what is pure scaremongering.

AIEU AI ActComplianceGDPRSMBLaw

Hardly any business works without AI these days: ChatGPT drafts proposals, Microsoft Copilot summarises emails, a chatbot answers customer questions on the website. And with the EU AI Act, the world's first major AI law has now arrived in everyday business: since 2 August 2026 the regulation has been generally applicable. Many business owners are asking themselves: do I have to do something now, or is this only for tech giants?

The short answer: taking some action is sensible, but for most small businesses the list of obligations is manageable. This post puts into perspective what has applied to small and medium-sized businesses since then – soberly and without panic.

Update (as of 11 August 2026): This post was updated after the AI Act became generally applicable on 2 August 2026. It also incorporates the changes to the timeline that entered into force at the end of July 2026 (the package long discussed as the "Digital Omnibus", see below).

Note: This post is not legal advice. If in doubt, have your specific situation reviewed by a lawyer.

The timeline in brief

The AI Act already entered into force on 1 August 2024 and has applied in stages since then:

  • 2 February 2025: Prohibited AI practices and the AI literacy obligation (Article 4) have applied since this date.
  • 2 August 2025: The rules for general-purpose AI models (GPAI) and the governance framework apply.
  • 2 August 2026: Since this date the regulation has been generally applicable – including the transparency obligations (Article 50). The European Commission's AI Office and the national authorities have also been enforcing the AI Act since then.
  • 2 December 2027 and 2 August 2028: The obligations for high-risk systems follow later – for sensitive areas (such as biometrics, education, employment) from 2 December 2027, for AI in regulated products (such as lifts or toys) from 2 August 2028.

So 2 August 2026 was the date on which the law became noticeable for normal users.

First, the all-clear: providers vs. deployers

The decisive point that often gets lost in the excitement: the AI Act distinguishes between providers (whoever develops an AI system and places it on the market) and deployers, i.e. users (whoever simply uses it).

The heavy obligations – building an AI system in a legally compliant way, technically labelling AI outputs, maintaining extensive documentation – fall on the providers: OpenAI, Microsoft, Google and the like. A typical trade business, an agency or a medical practice in Recklinghausen, by contrast, is a deployer. That makes the list of your own obligations considerably shorter. "We only use ChatGPT" therefore does not mean: nothing to do – but it also does not mean: everything changes.

What small businesses specifically need to take care of

For SMBs as deployers, essentially three topics remain:

1. AI literacy in the team (Article 4)

Since February 2025 the rule has been: whoever uses AI in the business must ensure a sufficient level of AI literacy among the staff involved. This is not a certification and not an expensive programme, but the obligation that your team knows what it is doing: how do the tools fundamentally work, where are their limits, which data may go in – and which absolutely must not?

In concrete terms this means: a short internal AI usage policy and raising awareness in the team. Since 2 August 2026 the authorities have also been overseeing this obligation – if you do not have a policy yet, you should catch up on this quickly now.

2. Transparency and labelling (Article 50)

Since 2 August 2026 the transparency obligations have applied: people must be able to tell when they are dealing with AI:

  • Chatbots: AI systems that interact with humans must inform users that they are talking to an AI – not to a human. Legally, this obligation falls primarily on the provider of the system; with common chatbot solutions the notice is therefore usually already built in. If you run a chatbot on your own website, you should still check that the notice is visible.
  • AI-generated content: So-called deepfakes (artificially generated or manipulated images, audio, video) must be clearly disclosed as such by deployers – at the latest on first exposure.
  • Published AI texts: AI-generated texts that are published to inform the public on matters of public interest must be marked accordingly. Exception: the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.

Two points of reassurance: content created before 2 August 2026 does not have to be labelled retroactively (the Commission merely encourages this where feasible). And for most businesses a clear notice such as "You are chatting with an AI assistant" on the chatbot remains sufficient in practice.

The obligations should still be taken seriously: violations of Article 50 can be punished with fines of up to 15 million euros or 3% of worldwide annual turnover – for SMEs the lower of the two values applies.

3. Data protection remains mandatory (GDPR)

The AI Act does not replace the GDPR – it comes on top. Whoever enters personal data into AI tools (customer names, health data, application documents) still needs a legal basis, a data processing agreement with the provider, and should – when in doubt – not enter sensitive data in the first place. That is often a bigger lever than the AI Act itself.

What you can sensibly do now

  1. Take stock: Which AI tools does your business actually use – including unofficially on private accounts?
  2. Set up an AI usage policy: One page is enough: permitted tools, taboo data, responsible persons, a short training. That satisfies Article 4.
  3. Label chatbots and AI content: Wherever AI is visible to the outside, add a clear notice.
  4. Review GDPR: Go through the contracts and data flows of your AI tools once, properly.

A word on the deadlines

The revision of the timetable long discussed as the "Digital Omnibus" has meanwhile been adopted: the omnibus amendment package to the AI Act entered into force on 27 July 2026. What was postponed were above all the deadlines for high-risk applications – to 2 December 2027 for sensitive areas (such as biometrics, education, employment) and to 2 August 2028 for AI in regulated products. The transparency obligations under Article 50 were not affected and have applied since 2 August 2026. In addition, the AI Act's reliefs for smaller companies were extended to so-called small mid-caps. The basic direction for SMBs changes little as a result.

Conclusion

The EU AI Act is no reason to abolish AI in your business – quite the opposite. For small businesses everything comes down to three sensible steps: train the team, label AI transparently and stay clean on data protection. That is less a compliance burden than good practice that builds trust.

Unsure which AI obligations specifically apply to your business? In a free initial consultation we sort out your tools, your policy and your data protection – pragmatically and at eye level.

Note: The articles on this blog are produced with the help of AI and are editorially reviewed before publication. Editorial responsibility lies with Emre Yurtbay (see the Impressum).

Discuss your project