There is a European regulation on AI, and for many business owners that mainly means uncertainty. Do you now have to register something, apply for something, or keep a file. The short answer for most SMEs: less than you think, but not nothing.
What follows is an explanation in broad strokes. It is not legal advice, and if you are in doubt about your specific application, a lawyer should look at it.
The regulation looks at risk, not at technology
The premise is simple: the more harm an AI application can do, the heavier the requirements. A system that reads in your packing slips falls into a completely different category from a system that decides who gets hired.
- Prohibited applications. Think of scoring people on social behaviour, or reading the emotions of employees on the shop floor. This is not allowed, full stop.
- High risk. Applications that have a major impact on someone’s life: recruitment and selection, employee evaluation, access to education or essential services. Extensive obligations apply here.
- Limited risk. Mainly transparency. If a customer talks to a chatbot, it must be clear that it is not a human. If you generate content with AI, that should be made known.
- Minimal risk. By far the largest group: route planning, stock forecasting, document recognition, spam filters. No special obligations apply here under this regulation.
What already applies
Two parts have been in force since early 2025. The first is the ban on the most severe applications. For an ordinary wholesaler or installation company that is no daily concern, but watch out with HR applications: software that measures the mood or attentiveness of employees comes dangerously close.
The second is AI literacy. If you use AI in your business, you must ensure that the people who work with it understand what it does and what its limitations are. That does not have to be a course with a certificate. An explanation session, a short work instruction and a record that you have done it is a reasonable approach for an SME.
The rest of the obligations, including the heavy regime for high-risk systems, will come into force in phases over the coming years. Dates and details still shift at times, so do not rely on a date someone mentions in a sales conversation; look in the regulation itself or ask your lawyer.
The regulation looks at your role. If you build an AI system yourself and put it on the market, you are a provider and more requirements apply. If you use a system from a supplier, you are a deployer and your set of obligations is lighter. Most SMEs are in the second category.
What you can do in practice
- Make a list of where you use AI. Including the things you do not think of as AI: the chatbot on your site, the assistant in your office suite, the forecasting feature in your stock package.
- For each application, write in one sentence what it does and what goes wrong if it makes a mistake. That gives you your risk picture.
- Check whether any application evaluates people. Staff, job applicants, customers you turn down. Those are the cases where you need to pay attention.
- Make sure your chatbots and AI-generated content are recognisable as such. That is cheap to arrange and it stands out if you do not.
- Give your people a short explanation of what the systems can and cannot do, and record that you have done so.
What to ask your supplier
Most of what you need does not come from you but from the party supplying the system. Ask for it specifically, and do not settle for a logo or a reassuring sentence on a product page. Three questions get you a long way: in which risk category does the supplier place this system, what documentation do you get with it, and what happens to your input.
If you get no clear answer to that, that is information in itself. A supplier who cannot classify their own product cannot help you either when a customer or regulator asks about it later. Keep the answers you do get in a folder with your other supplier documents, because they are hard to reconstruct later.
What disappoints about this
The honest answer is that practice has not yet crystallised. Standards, guidelines and supervision are still being developed, and that means nobody can tell you with certainty today how a regulator will look at your specific application in three years. Anyone who does is selling you something.
On top of that, a small AI compliance circus is emerging: expensive programmes for businesses that fall into the minimal risk category and probably do not need to do anything. Do not let anyone scare you. Determine your category first, then your measures.
When you need us and when you do not
If you are in the minimal risk category, and that applies to the vast majority of SME applications, you do not need an adviser for this. Going through the list above takes you a morning and then you are done.
We are useful if you use AI around staff, credit assessment or access to services, if you build something yourself that you supply to third parties, or if your customers ask for demonstrable compliance. Then it is about documentation, logging and human oversight in the design, and you want to arrange that up front rather than afterwards.