The EU AI Act officially entered into force this month, creating the first comprehensive legal framework for artificial intelligence. Here's what you need to know.
The Key Rules
Risk-Based Framework
AI systems are classified by risk level:
- Minimal risk: AI chatbots, spam filters - no regulation
- Limited risk: AI systems with specific transparency obligations (chatbots must disclose they're AI)
- High risk: AI used in critical infrastructure, education, HR, law enforcement - requires conformity assessment
- Unacceptable risk: Social scoring, real-time biometric surveillance - banned outright
What This Means for SMBs
If you use AI tools for customer support, content generation, or internal processes, you're likely in the "minimal" or "limited" risk category. The main requirement is transparency - tell customers when they're interacting with AI.
Action Items
- Audit your AI usage: List every AI tool you use and what it does
- Add disclaimers: Chatbots must disclose they're AI
- Review data practices: Ensure customer data used with AI tools has proper consent
- Document your compliance: Keep records of your AI risk assessments