AI in business
Even a company that does not develop AI but only uses it has obligations under the EU Artificial Intelligence Act, although they differ from, and are usually lighter than, those of AI providers. We explain the roles, risk levels, specific obligations and deadlines, with the position verified as of 16 September 2026.
Talk of the European regulation on artificial intelligence quickly prompts a familiar reaction: we don’t develop AI, we only use it, so it doesn’t apply to us. That is not accurate. The AI Act, formally Regulation (EU) 2024/1689 (the Artificial Intelligence Act), divides obligations between those who develop AI systems and those who use them. Users have fewer obligations, but they are not exempt.
Illustrative example: the same language model might write the newsletter in one company, where AI literacy is the main requirement, and screen job applicants in another, where the strict regime for high-risk systems may apply from 2 December 2027. That is because EU AI Act obligations depend not on the tool, but on the company’s role and the purpose for which AI is used. This article reflects the position as verified on 16 September 2026 and is not legal advice on any specific case.
The first source of confusion lies in the rules for general-purpose AI models, the large models on which applications such as ChatGPT are built. Those rules apply to model providers. However, according to the Commission, anyone who integrates a model into their own AI system, such as a customer chatbot under their own brand, must comply with the relevant obligations for AI systems.
The second is an overlooked definition. A deployer is any person or organisation using an AI system under its authority, except in the course of a personal non-professional activity. As a rule, that includes a company whose employees use AI at work. This is a common situation: according to Eurostat, of EU enterprises with 10 or more employees outside the financial sector that used AI in 2024, almost 58% used ready-to-use commercial software and just under 22% used AI developed by their own employees.
The AI Act entered into force on 1 August 2024 and applies in stages. The timetable and some obligations were amended by Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, which has been in force since 27 July 2026. This is not a proposal but adopted law that is already in force. Key dates for companies:
Do not confuse the Digital Omnibus on AI with the separate Digital Omnibus Regulation proposal on data, the GDPR and cookies, which, according to the European Parliament, was still only at the proposal stage as of 1 August 2026 and therefore imposes no obligations on companies. At national level, oversight lies with the market surveillance authorities designated by each member state, and the national implementing rules differ from country to country, so check the current arrangements in the countries where you operate.
A provider develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. Illustrative example: the developer of a CV screening tool is the provider, and a business that subscribes to the tool is the deployer.
Your role, however, is not determined by the contract alone, but above all by what you do with the AI. Under Article 25, you also become the provider of a high-risk system if you put your name or trademark on it, make a substantial modification to it, or change the intended purpose of another system, including a general-purpose AI system, in such a way that it becomes high-risk. Illustrative example: the HR department starts systematically using a general-purpose chatbot to assess job applicants, which may put the company in the role of provider.
EU AI Act obligations also depend on which of the four risk levels a specific use falls into.
AI literacy means the skills, knowledge and understanding needed to use AI in an informed way. Under Article 4, as amended with effect from 27 July 2026, providers and deployers “shall take measures to support the development of AI literacy” of their staff and other persons using AI on their behalf, without being required to guarantee any specific level. According to the Commission, this also applies to a company whose staff use ChatGPT to write advertising copy, and employees should be aware of, for example, the risk of hallucinations, meaning false outputs presented convincingly. This is not a mere formality: in a global survey by KPMG and the University of Melbourne, 66% of employees who use AI said they rely on its output without checking it, and 56% had made mistakes at work because of AI. According to the Commission, neither a certificate nor a role such as an AI officer is required, and a company can keep internal records of training.
The rules under Article 50 have applied since 2 August 2026. For chatbots, it is the provider that must ensure people are informed they are dealing with AI, so if you have bought a ready-made solution, check this with your supplier; if the chatbot is built under your own brand, the obligation is yours. A deployer must inform people exposed to emotion recognition or biometric categorisation and must label deep fakes, meaning AI-generated image, audio or video content that imitates real people or events and could pass as genuine. If AI generates or edits text published to inform the public on matters of public interest, this must be disclosed, unless the text has undergone human review or editorial control and someone holds editorial responsibility for its publication.
For the high-risk systems listed in Annex III, the deployer obligations under Articles 26 and 27 apply from 2 December 2027. They apply to systems placed on the market or put into service before that date only once those systems undergo significant changes in their design. In particular, a deployer must:
The AI Act does not replace the GDPR: if a system processes personal data, both regulations apply. Under the amended Article 27, the deployer of a high-risk system may, in its fundamental rights impact assessment, refer to the data protection impact assessment or reuse the parts of it through which it has already met its obligations. There is therefore no need to carry out the same analysis twice.
With everyday tools, keep an eye on inputs too: in the KPMG survey mentioned above, almost half of employees admitted using AI in ways that breach company policies, including uploading sensitive company information to free public tools. We discuss how to set permissions and limit the data sent to models in the article AI in business without chaos.
Maximum fines are set in three tiers, and as a rule the higher of the two amounts applies:
For small and medium-sized enterprises (SMEs), the lower of the two amounts applies, and in the second and third tiers this also holds for small mid-cap enterprises that are no longer SMEs. The Omnibus did not change the level of the caps. The amount of a specific fine is decided by the authority based on the circumstances, such as the gravity and duration of the infringement, the size of the company and its cooperation with the authorities (Article 99(7)). The Act does not set fine levels for AI literacy; penalties will be laid down in national law and, according to the Commission, are more likely where an incident occurs because of inadequate training.
Where the risk is minimal, you do not need specialist software or a major project; a spreadsheet, clear rules and a short training session are often enough. Initial guidance is available from the European Commission’s AI Act Service Desk and, according to the Commission, SMEs can also turn to the European Digital Innovation Hubs.
Free prototype
Describe your project and within days you hold a working prototype built on your real data. We build it at our own cost: the work should convince you, not a presentation.
No payment, no commitment. You pay once you decide to continue.
Free consultation
Pick a slot and tell us how your company works today. We'll show you the three places where you lose the most time, and which of them we can take over first. No slide decks, no commitment.

Juro
jur0.com
A website, an app, an AI system or automation. Describe what you are dealing with in two sentences and I will get back to you within 24 hours with a concrete proposal. We build anything that saves your company time.
Or directly: WhatsApp · juro@jur0.com