The EU AI Act (Regulation (EU) 2024/1689) applies to every business whose employees use ChatGPT, Gemini, Copilot or other AI tools - regardless of company size. Since 2 February 2025, Article 4 requires you to support people using AI in understanding how the tool works, its limitations and its risks. From 2 August 2026 enforcement begins - breaches of operator obligations carry fines up to 15M EUR or 3% of turnover, while the top tier (35M EUR or 7%) applies only to prohibited practices, not to ordinary business use of AI. Three concrete obligations for a small business: 1) documented AI Literacy training for every person using AI, 2) a register of AI tools in use (Shadow AI counts too), 3) GDPR compliance when entering client data - the free ChatGPT trains on your prompts. Preparing the audit, training and documentation takes 2-4 weeks.
If your employees use ChatGPT for writing emails, Gemini for data analysis, or Copilot in Excel - you have been subject to the AI Act since February 2025. It does not matter whether you have 3 people in your company or 300.
Most small business owners across Europe are unaware of this obligation. Yet the key deadlines begin on 2 August 2026. This article explains what you need to do, how much time you have, and how to prepare - without legal jargon.
Updated August 2026. The Digital Omnibus package was published as Regulation (EU) 2026/1744 - high-risk systems under Annex III have a 2 December 2027 deadline. Earlier updates clarified the scope of Art. 50 (what needs a label and what does not), distinguished a chat built on an AI model from a plain decision tree, and updated the status of the Polish act on artificial intelligence systems.
Note: This article is for informational purposes only and does not constitute legal advice. For specific legal questions, consult a lawyer specialising in technology law.
What is the AI Act and why it applies to you
The AI Act (Regulation (EU) 2024/1689 of the European Parliament and of the Council, OJ L, 2024/1689, 12.7.2024, ELI: data.europa.eu/eli/reg/2024/1689/oj) is the world's first comprehensive law regulating artificial intelligence. The European Parliament and the Council adopted it jointly - the act was signed on 13 June 2024 and published on 12 July 2024. It applies across all EU member states.
The regulation does not only concern companies that build AI systems. It applies to any entity that uses AI. If your employee uses an AI tool at work - even the free version of ChatGPT - your company is a "deployer" under the AI Act.
That means concrete obligations. The most important one for small businesses is Art. 4 - the duty to support the development of AI literacy among people who use these tools.
Art. 4 - the AI Literacy obligation
Article 4 of the AI Act is clear: providers and deployers of AI systems must take measures to "support the development of AI literacy" among people who operate or use those systems (wording amended by the Digital Omnibus, Regulation (EU) 2026/1744).
In practice, this means:
- You need to know which AI tools are used in your business - including those employees installed on their own (Shadow AI).
- Everyone using AI should understand how these tools work, their limitations, and potential risks.
- You need to document this - saying "they know" is not enough. You need evidence: training records, materials, attendance lists.
Key point: AI Literacy does not mean every employee must become an AI expert. It means that people using AI at work understand what they are doing, what the tool's limitations are, and when a result needs human verification.
Art. 4 does not require trainer accreditation - it requires documented team competency and training quality. What counts is practical knowledge, complete documentation, and genuine preparation of staff to work with AI.
What you specifically need to do
Preparing for Art. 4 of the AI Act comes down to three steps.
Step 1: Audit of AI tools in your business
Create a list of every AI tool your business uses. Not just the official ones - check what employees have installed on their own too. Common places where AI "hides":
- ChatGPT, Claude, Gemini - for writing emails, proposals, content
- Microsoft Copilot - built into Office 365
- Canva AI, Adobe Firefly - for graphics
- Grammarly, DeepL - for translations and proofreading
- CRM tools with AI features (e.g. HubSpot, Salesforce Einstein)
- Browser extensions with AI
For each tool, record: who uses it, what for, and what data it processes. This will be the basis for scoping your training. The tool audit is also a good moment to plan AI process automation -- which of these tools can be combined into a coherent workflow.
Step 2: Employee training
Training should cover:
- How AI works - what a language model is, why it "hallucinates", what a prompt is
- Tool limitations - when AI gets things wrong, what data can be entered and what cannot
- Data security - what happens to data entered into ChatGPT, the difference between the free and paid versions
- Practical use - how to prompt effectively, how to verify outputs, when not to trust AI
- Legal context - key facts about the AI Act and company obligations
Training does not need to last a week. For most small businesses, a one-day workshop tailored to your sector and the tools you actually use is enough. Also check whether you qualify for AI training funding from KFS or BUR -- it covers up to 80% of costs.
Step 3: Documentation
After training you should have:
- Training plan - a programme tailored to roles in the business (different for sales, different for accounting)
- Training materials - presentation, exercises, checklists
- Attendance records - who participated and when
- Completion certificates - for each participant
- Post-training report - findings, recommendations, follow-up plan
This documentation is your proof of compliance with Art. 4. In the event of an inspection, you present specific files - not promises.
Implementation timeline
The AI Act does not take effect all at once. Different provisions have different deadlines:
-
February 2, 2025
Art. 4 - AI Literacy and prohibited AI practices. Chapters I and II of the regulation: the duty to support the development of AI literacy plus the ban on social scoring, subliminal manipulation, and emotion recognition in the workplace.
-
August 2, 2025
Penalty rules and supervisory bodies. Chapter XII (fines under Art. 99) plus the rules for general-purpose models and the governance structure. From this date, sanctions for prohibited practices are enforceable.
-
August 2, 2026
The regulation's main application date. Art. 50 (transparency) and the obligations of AI deployers take effect - together with the fines for breaching them. This is the deadline you need to prepare for.
-
December 2, 2027
High-risk AI systems. Full requirements for AI systems in recruitment, lending, and healthcare. Deferred from August 2026 by the Digital Omnibus package (Parliament adopted it on 16 June, the Council on 29 June, and it was published as Regulation EU 2026/1744). AI embedded in Annex I products has an even later deadline: 2 August 2028.
What affects you first: the AI Literacy obligation (Art. 4) has applied since 2 February 2025 - 2 August 2026 is when the regulation starts to apply in full, together with the sanctions for breaching those provisions. The same date brings transparency (Art. 50): a chat built on an AI model must make clear it is not a person, and content that could pass for authentic needs a label. Preparing the audit, training, and documentation takes several weeks, so the earlier you start, the calmer the rollout. Full requirements for high-risk systems are a separate, later deadline (December 2027).
Polish supervisory body - KRiBSI
The AI Act is enforced at the national level. In Poland, market supervision over AI will be carried out by the Commission for AI Development and Security (KRiBSI - Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji) - a new body established under the Polish AI Systems Act.
Legal status: The Sejm passed the act on 11 June 2026, the Senate returned amendments, the Sejm accepted almost all of them, and the President signed the act on 24 July 2026. The Polish AI Systems Act (Journal of Laws 2026, item 1003) has been in force since 11 August 2026, and the provisions on KRiBSI itself apply from 28 October 2026. The Chair is to be appointed within two months and the full Commission within three, so KRiBSI is expected to start work in November. Until then, sector regulators perform supervisory functions within their remit - UODO (data protection), UOKiK (consumers), KNF (financial sector).
What KRiBSI does:
- Issue administrative decisions - including imposing fines for AI Act violations
- Run regulatory sandboxes - safe testing of AI systems before they reach the market
- Issue individual opinions - businesses may seek interpretation of specific cases
- Run education and awareness initiatives - training, materials, market information campaigns
Important: the Polish AI Systems Act (Journal of Laws 2026, item 1003) has been in force since 11 August 2026. Either way, EU Regulation 2024/1689 (the AI Act) applies directly - the Art. 4 obligation (AI Literacy) has been in force since 2 February 2025. The act establishes KRiBSI as the body that will handle complaints and run inspections, and it opens regulatory sandboxes - free of charge for small businesses. Enforcement of Art. 50 begins on 2 August 2026.
Fines for non-compliance
The AI Act provides for three tiers of fines:
- Prohibited AI practices: up to 35 million euros or 7% of annual turnover
- Operator obligations (including Art. 50 - transparency) and high-risk AI systems: up to 15 million euros or 3% of annual turnover
- Providing false information to supervisory authorities: up to 7.5 million euros or 1% of annual turnover
For a small business these figures may seem abstract - and the regulation accounts for that. Art. 99(6) is explicit: for SMEs and start-ups the fine may not exceed the lower of the two values, the fixed amount or the percentage of turnover. A large corporation pays the higher one, a small business the lower. Art. 99(7) additionally requires the authority to weigh the severity and duration of the breach, the size and turnover of the operator, and any mitigating factors - and documented training plus a tool register is exactly such a factor.
The worst position is doing nothing. A business that can show a training plan, documentation, and completion certificates - even if imperfect - is in a far better position than one that was unaware of the obligation.
ChatGPT and GDPR - is your business breaking the law
Pasting personal data (customer names, tax IDs, HR records, email contents) into the consumer version of ChatGPT violates GDPR. ChatGPT, Gemini, and Claude in their free tiers use your prompts to train models, which qualifies as transferring data outside the EEA without legal basis. Solution: "Team/Enterprise" tiers disable training, or choose tools with explicit "data privacy" mode.
We checked the source policies in detail in our article on where your company's data goes when you use AI.
The most common mistake by a business owner: an employee pastes a customer email into ChatGPT and asks "rewrite this in a friendlier tone". The email contains a name, email address, sometimes a phone number. That is personal data under GDPR. ChatGPT (Free, consumer Plus) stores it and may use it to train the model. This violates Art. 6 GDPR (no legal basis for processing) and Art. 44-49 (transfer of data outside the European Economic Area without safeguards).
3 most common ChatGPT data leaks in small businesses
- Customer lists for analysis: "Help me group these customers" + a spreadsheet with names, phone numbers, addresses. The entire spreadsheet goes into model training.
- Business email content: "Write a reply to this email" + the pasted message with sender data. Name, email, signature with company - all goes to OpenAI.
- HR documents: "Summarize this employment contract". Name, ID number, employee address - the whole document in the prompt, the whole document in training.
Scale of the problem: a 2024 Cyberhaven study found that 11% of data pasted into ChatGPT by employees is sensitive (customers, finance, HR). In a typical 30-person business that means several leaks per week - completely unintentional.
How to use ChatGPT in a GDPR-compliant way
- Choose a business tier: ChatGPT Team/Enterprise, Claude Team, Gemini Business. These tiers disable training on your data by default and include a Data Processing Agreement (DPA). Cost: from approximately $25/user/month.
- Create an AI policy for employees: one A4 page. What is allowed (anonymous content, code, concepts). What is not (customer personal data, HR records, financial data, passwords). Each employee signs that they have read the policy. The full document - eight sections, costs, updates - is covered in our guide to an AI policy for business.
- Run training on safe AI usage: 90% of leaks are not hacker attacks - they are employee mistakes. Training + checklist + concrete "yes/no" examples = 80% risk reduction.
GDPR and AI Act compliance go hand in hand. Art. 4 of the AI Act requires training employees on AI use - the same training covers GDPR concerns. See our AI training for small businesses - it covers both regulations in a single workshop.
Art. 50 - when you must label AI content (and when you don't)
The second obligation that reaches small businesses is transparency - Article 50 of the AI Act. It applies from 2 August 2026 and was not postponed by the Digital Omnibus package (what moved was high-risk systems, pushed to December 2027).
This is where most businesses get it wrong: the fact that a text was written with AI does not, by itself, trigger a labelling duty. Product descriptions, client emails, posts on your company blog - none of these need a label. The duty is narrower:
- Deepfakes - images, video or audio depicting people or events that never happened, which someone could reasonably take as authentic
- Text informing the public on matters of public interest (health, fundamental rights, the environment, consumer protection). Pure product advertising and corporate communications fall outside this. There is also an exception where a person has reviewed the content and holds editorial responsibility for it
- Chats talking to customers - people have the right to know they are dealing with AI, at the latest on first interaction
- Marketing materials with synthetic faces or voices - where they could pass for real people
One caveat: not every chat widget counts as an AI system. If your chat runs on rules a person wrote ("press 1 for opening hours, 2 for contact"), the AI Act does not treat it as AI. Recital 12 excludes systems based solely on rules defined by natural persons, and the deciding factor is whether the system infers. If a language model sits behind the chat and composes its own answers, it is an AI system and the duty applies to you.
In practice: if your site runs a chat built on a language model, add a notice such as "You are chatting with an AI assistant". If you use an AI-generated voice or face in advertising, label it. Ordinary business copy written with AI needs no label. And the responsibility sits with your company as the deployer, not with the vendor of the tool.
How 30Elevate can help
We combine practical AI knowledge with the realities of small business. Our AI training covers both practical skills and the documentation required under Art. 4 of the AI Act.
What you get after the workshop:
- Training plan tailored to your industry and team roles
- Training materials (presentation + checklists)
- Hands-on exercises with the AI tools you actually use
- Attendance records and completion certificates for each participant
- Post-training report with recommendations
One workshop - and your team's competency is raised and your documentation is in order. We do not promise an "AI Act compliance certificate" (because no such formal document exists), but we give you everything Art. 4 requires.
The trainer holds Google AI certifications and has hands-on experience deploying AI systems in businesses. The training is delivered in language that works for a business owner - not a developer.
Frequently asked questions
Does the AI Act apply to my small business?
Yes. If your employees use any AI tools - even ChatGPT for writing emails - Art. 4 of the AI Act requires you to support the development of AI literacy among those people. Business size and sector do not matter.
What fines apply for lack of AI Literacy compliance?
Art. 99 of the AI Act does not list Art. 4 among the provisions carrying their own penalty tier. Gaps in AI literacy act as a factor in other breaches - the supervisory authority weighs whether the company prepared its staff, and a trained team works in your favour. For small and medium businesses, a fine is capped at the lower of the two values (the fixed amount or the percentage of turnover), not the higher.
Do I need an AI Act certificate?
A formal "AI Act compliance certificate" does not exist. Art. 4 requires documented competency - a training plan, materials, attendance records, and a completion certificate. What matters is the trainer's expertise and the quality of documentation.
When does AI Act enforcement begin in the EU?
Art. 4 (AI Literacy) has applied in Poland since February 2, 2025, because the regulation applies directly. The penalty rules in Chapter XII have applied since August 2, 2025, and from August 2, 2026 Art. 50 and the obligations of AI deployers are added. Poland's supervisory body, KRiBSI, is created by the Polish AI Systems Act (Journal of Laws 2026, item 1003), in force since August 11, 2026, and is expected to start work in November.
What is the AI Literacy obligation under Art. 4 of the AI Act?
Art. 4 requires the company to support the development of AI literacy in every person operating an AI system. This includes understanding how AI tools work, recognizing limitations and risks, and being able to critically evaluate AI-generated outputs. The obligation applies to both employees and the business owner.
How do I conduct an AI tools audit in my company?
Create a list of all AI tools used in your company - from ChatGPT to Canva AI to CRM automations. For each tool, record: who uses it, what for, what data it processes, and what risk category it falls under according to the AI Act. Most small business tools fall into the minimal or limited category.
What AI documentation must a business maintain?
Art. 4 requires documentation of: a list of AI tools used, a training plan with scope and timeline, training materials, attendance records, and completion certificates. A simple folder with these elements is sufficient in case of an inspection.
Get your business ready for the AI Act
AI Literacy workshop for your team - practical skills and complete documentation for Art. 4 of the AI Act. See training details or get in touch.
Book a workshop