The new European regulatory framework on AI
What the new European regulation says and why it may impact your business.

The European AI Act: what changes for a small business
The European AI Act came into force on 1 August 2024. It's the first piece of legislation dedicated to artificial intelligence adopted by a major jurisdiction, regulating the development, sale, and use of AI systems. Many tools already in daily use, like a chatbot on your website or software that helps screen job applications, can fall within the scope of the regulation.
What the regulation covers
The rule exists to keep AI systems safe and to protect fundamental rights across the European Union. Instead of treating every application the same way, it splits systems into four risk levels and assigns different obligations to each.
Each category carries a different set of obligations, ranging from an outright ban to no specific obligations at all. A script that tracks website visits doesn't require the same level of attention as a system used to evaluate job applications. The four risk levels are:
- Unacceptable risk: banned. This includes social scoring (assigning people a "score"), emotion recognition in the workplace, scraping facial images from the web to build facial recognition databases, and certain forms of predictive policing targeting specific individuals.
- High risk: permitted, but under strict conditions. This category includes certain AI-enabled medical devices and specific systems used in areas such as recruitment, education, access to essential services, justice, law enforcement activities, migration management, and border control.
- Limited risk: permitted, with transparency obligations. Chatbots and AI systems that interact directly with people, systems that generate or manipulate synthetic content such as deepfakes, and other systems subject to transparency requirements fall into this category. Whoever uses them must inform users when they are interacting with an AI system or when content has been artificially generated or manipulated.
- Minimal risk: no specific obligations. Spam filters, recommendation engines, and many everyday productivity tools fall here.
The obligations for high-risk systems, originally set for 2 August 2027, now roll out in two phases following the delay decided under the Digital Omnibus: from 2 December 2027 for systems such as recruitment, education, and essential services, and from 2 August 2028 for those embedded in products already regulated elsewhere, such as medical devices and elevators.
Where a small business usually falls
In most cases, small businesses don't develop AI systems themselves but use services built by others. In these cases, they are considered deployers, meaning users of the system.
The deployer's obligations depend on the risk level of the system. A customer service chatbot usually falls into the limited-risk category: the main obligation is transparency, informing whoever is chatting that they're talking to an AI system. A tool used to support recruitment, on the other hand, may fall among high-risk systems. In these cases, obligations can include human oversight, using the system according to the provider's instructions, monitoring how it performs, and, where required, keeping activity logs.
Military and defense systems, tools developed solely for research, and AI used outside a professional context remain outside the scope of the regulation.
What happens if a business ignores the rules
Penalties vary depending on the type of violation and can be calculated as a share of global annual revenue or as a fixed amount. For prohibited practices, fines can reach up to €35 million or 7% of global revenue. Violations related to other obligations, including those for high-risk systems, can reach up to €15 million or 3%. Providing false or incomplete information to authorities can result in fines of up to €7.5 million or 1.5% of revenue.
For small and medium-sized enterprises and startups, the regulation provides for the lower of the two amounts, the fixed figure or the percentage, rather than the higher one: in this case the obligations stay the same, but the financial exposure is significantly reduced.
What happens if you use AI outside of work
The AI Act doesn't touch personal use, and it doesn't require labeling content generated or manipulated with AI. The exemption ends at the boundary of a professional context.
A website built with an AI generator or a drag-and-drop builder often hides problems as plugins and scripts pile up over time, which can lead to slowdowns, security holes, and difficulty keeping up with current regulations.
If you need a website that's reliable, secure, and fast, get in touch — the first consultation is free.