Skip to content

EU AI Act

The AI Act, without the legal jargon

The European AI Regulation is already in force. If you use artificial intelligence in your business — a chatbot, a system that scores customers, a tool that screens CVs — it is natural to wonder whether it affects you and what you are supposed to do. This guide explains it in plain terms: what it is, whether it applies to you, what you are on the hook for and where to start. No legal language and no alarmism.

The regulation

What the AI Act is, in plain terms

The AI Act — also called the AI Regulation or, by its official name, the European Artificial Intelligence Regulation — is the world's first general law regulating artificial intelligence. It is European, it applies to anyone operating in the EU, and its logic is simple: not all AI is equal, so not all AI is regulated equally. It classifies systems by the risk they pose to people, and the greater the risk, the more obligations you have.

Four levels, from lowest to highest:

Minimal risk

The everyday uses: a spam filter, a chatbot answering questions, a tool that helps you draft. Minimal obligations or none. Most SMEs live here — worth knowing, because the AI Act sounds more threatening than it turns out to be for normal use.

Limited risk

Systems that interact with people and call for transparency: if a customer is talking to a bot, they have the right to know it is a bot. The obligation is to disclose, not to hide.

High risk

Systems that weigh on important decisions about someone’s life: hiring, credit decisions, access to essential services. Here the obligations are serious: documentation, human oversight, traceability. If you use AI for anything like this, it is where to look carefully.

Unacceptable risk

Prohibited uses: manipulation, mass social scoring. Not the territory of a normal SME; it is mentioned so it is clear there is a ceiling.

The idea to take away: the AI Act does not go after your use of AI — it orders how to use it according to what is at stake. For most small companies, the work is not meeting a thousand requirements; it is knowing which level you fall into.

Your case

Does it apply to you? And which category are you in?

The first question is not “am I compliant?” — it is “what am I even talking about?”. Many companies use AI without having it located: it lives inside a CRM, a marketing tool, an assistant someone signed up for without telling anyone. Before anything else, you need to know which AI systems you have and what you use them for.

With that list in front of you, the category usually deduces itself from two questions:

Does the system make — or influence — a decision that affects a specific person?

If your AI only sorts information, drafts text or answers general questions, you are almost certainly in minimal or limited risk. If it decides who you hire, who gets credit or who you accept as a customer, you are entering high-risk territory and it is time to look seriously.

Does the person know they are dealing with an AI?

If a customer interacts with an automated system — a chatbot, a voice — transparency is mandatory: you have to tell them. It is not optional and it is not expensive; it is a notice.

Most SMEs, doing this exercise, discover that their uses are minimal or limited risk, and that the real work is keeping them in order and being transparent where it matters. Companies using AI for sensitive decisions have a bigger job — but also a more bounded one: they know exactly which system to look at.

The hard part usually is not complying — it is being clear about what you have and what applies to you. That map is half the work.

In practice

What your obligations are, in practice

The AI Act's obligations sound like jargon until you translate them into what they mean day to day. The main ones, for the range an SME moves in:

Knowing what you have: the inventory.

A list of your AI systems — what they are, what they are used for, who provides them. It is not red tape: it is what lets you answer if someone asks, and what prevents surprises.

Being transparent.

Wherever a person interacts with AI, they should know. Wherever content is generated by AI, it should be distinguishable. It is more a matter of operational honesty than of paperwork.

Documenting how it works.

For systems that weigh on decisions, being able to explain what the system does, with what data and under what rules. You do not need a treatise; you need it not to be a black box nobody can explain.

Human oversight.

A person who can review, correct and stop the system. AI adds capacity to the team; it does not replace it, and it does not decide alone on what matters.

Traceability.

Being able to reconstruct what went in and what the system decided. If a decision needs reviewing tomorrow, there is a trail.

None of this is, at bottom, a legal problem. It is a problem of data, processes and systems — having things in order, documented and under control. Which is exactly the terrain you can work on without a law firm.

From rule to system

How it lands: from the regulation to something that works

Here is the turn that matters. The AI Act sets requirements, but meeting a requirement is not filling in a form: it is leaving a system in place that genuinely works and that your team can maintain.

I don't know whether my AI systems fall under the regulation, or in which category.

Your AI uses are inventoried and each case is classified by its real risk.

I'm asked for an inventory, documentation and traceability, and I don't know what level is enough.

Each requirement is translated into something concrete and proportionate to your size, without over-engineering.

I fear a huge, expensive legal project disconnected from my operation.

It is treated as what it is — data, processes and systems — integrated into how you already work.

This is what Dateliers does: not a legal opinion, but turning AI Act requirements into inventories, controls, documentation, traceability and review flows that stay up and running. The assessment already looks at what applies to you and where you stand; the projects build whatever is missing.

We do not issue legal opinions and we do not certify compliance. We turn AI Act requirements into systems, controls and evidence that genuinely work. Where a question of legal interpretation appears, you or your specialist advisors validate it — that is where our terrain ends and theirs begins.

Questions

Frequently asked questions

Does the AI Act apply to my company if it is small?

It applies by the type of use you make of AI, not by your size. But most SME uses fall into minimal or limited risk, where the obligations are light. What matters is knowing which category you are in, not how many people you employ.

Does a chatbot on my website oblige me to anything?

Mainly transparency: whoever talks to it should know it is an automated system, not a person. If the chatbot also makes sensitive decisions, there would be more to look at; if it only answers questions with approved information, the work is minimal.

What happens if I do nothing?

The AI Act provides for penalties, and they arrive in phases. But for an SME with low-risk uses, “doing something” is rarely a big project: it usually means putting in order what you already have and being transparent where it matters. The cost of ignoring it is higher than the cost of looking at it.

Do I need a lawyer?

For fine legal interpretation, yes — and we do not replace that. But a good part of the AI Act's work is not legal; it is technical and organisational: inventory, documentation, controls. That gets done without a law firm. The legal and the technical split the work, and it pays not to confuse one with the other.

Does this concern me if I use third-party AI (ChatGPT, Copilot and the like)?

Using third-party tools does not exempt you: you are still responsible for how you use them and what data you put into them. Part of the work is precisely deciding what may and may not be done in those tools, and writing it down for the team.

Where do I start?

With the inventory: knowing which AI you use and what for. With that, the category and the obligations follow almost by themselves. If you want, we take that first picture with you in the assessment.

Let's talk

Using AI and not sure where to start with the AI Act?

Book an assessment

A first 30-minute call with direct senior input, no commitment and no sales pitch.