On August 2, 2026, the Artificial Intelligence Regulation, or the AI Act, enters its general deployment phase. In other words, compliance becomes mandatory for companies operating in Spain and the rest of the EU, though some requirements are postponed until December 2027 due to the Digital Omnibus Regulation. For U.S. businesses, this regulation applies only if you process data of EU residents or operate within the EU market.
Therefore, in this guide we break down how to , taking into account the most common uses of this technology by small and midsize businesses (SMBs) and with concrete examples from different sectors.
What obligations does the AI Act impose for the use of AI in businesses?
Uses and prohibited practices
They are subject to a total ban due to their threat to fundamental rights:
- Cognitive manipulation: Systems that use subliminal techniques to distort human behavior.
- Social scoring: Classification of people by public authorities based on their conduct or profile.
- Remote biometric identification or categorization: Real-time use in public spaces (with very strict exceptions).
- Emotion recognition: Its use in workplace and educational settings.
High-risk systems: The core of the obligations
Affects systems that evaluate people (credit, employment, education, justice, biometrics). You must comply with:
- Bias mitigation and control: Obligation to use clean, representative training data free from discriminatory biases.
- Mandatory human oversight: Systems must be designed so that qualified people can monitor, correct, or turn off the AI at any time.
- Activity logging (Logs): Automatic traceability of events and decisions to audit AI behavior.
Limited-risk systems: Basic transparency obligations
Affects common systems such as chatbots, image generators, or spam filters:
- User information: Always inform users when they are interacting with AI.
- Watermarks: Watermark synthetic content (deepfakes, automatically generated informative texts, generated audio) obligatorily.
No obligations
AI-powered video games, photo filters, or spell-checkers do not have added legal obligations, though voluntary codes of conduct are encouraged.
What to do to comply with the AI Act in a small business?
Analyze the AI tools your company uses and their risk level
Recent studies indicate that 73% of SMBs do not know whether they use high-risk AI systems, and 82% do not even have an inventory of the tools that deploy this technology.
The most advisable course in this case is to seek specialized help. For example, compliance-focused firms like Atico34 offer their own software to comply with the AI Act, Atico34 AI Governance, an affordable solution for SMBs that also provides legal advice from AI and data protection experts.
Create the inventory and the internal digital literacy policy
Once the assessment is completed, the company should formalize the management of its technological assets through a centralized and confidential registry of the programs it uses.
This documentation must be backed by a training program for the workforce, a legal requirement aimed at ensuring employees use technology with ethical safety criteria.
Apply the mandatory transparency measures
In practice, companies that use virtual assistants or automated support channels must obligatorily configure clear notifications informing the user about the nature of the system.
They must also include watermarks or legible labels on any content—visual, written, or audio—generated synthetically.
Establish human oversight for high-risk systems
When contracted systems intervene in critical areas such as human resources management or financial evaluation, the SMB must structure a rigorous internal control protocol.
This implies designating a qualified professional to audit algorithmic results, ensuring that high-sensitivity processes like resume filtering or shift assignments always require human validation before final application, as noted in Article 14 of the AI Act.
Review contracts and conduct ongoing security audits
SMBs should require explicit compliance clauses and data-handling immunity from their tech partners.
It is advisable to set up a schedule of periodic reviews to ensure the security of the digital environment whenever a new application is integrated into the daily workflow.
Practical examples: How it applies in each area of the business
Customer service and front desk
If you implement automatic voice assistants to manage phone reservations at a restaurant or hotel, or if you install a chatbot on an e-commerce site to resolve common questions, you are operating in the Limited Risk category.
The regulation requires strict adherence to the transparency principle: the system must notify the user with a clear message or an audible cue that they are interacting with artificial intelligence and not a human.
Human resources and personnel management
Here, AI use is automatically classified as High Risk, even if you manage retail staff, waiters, or consultants.
If you use platforms to sift candidate resumes, evaluate staff performance, or design work shifts, the SMB is legally obliged to establish active human oversight. A supervisor must monitor the algorithm to avoid discriminatory bias and ensure that AI never makes critical employment decisions autonomously.
Marketing and commercial design
The use of content-generation tools like Midjourney, ChatGPT, or Claude to draft ad copy, program website code, or design catalog backgrounds generally falls under Minimal or Limited Risk.
The primary obligation lies in visual honesty: if you create hyperrealistic images, audio, or videos that could mislead consumers by appearing real, you must clearly label them as AI-generated content.
Operations, logistics, and purchasing
AI systems used for purely operational tasks, such as real-time route optimization based on traffic, inventory forecasting for a store, or raw-material cost control in a kitchen, fall into the Minimal risk category.
These algorithms process logistical or numeric data that do not impinge on freedoms or fundamental rights, so your SMB can continue to use these technologies normally without additional legal obligations.
Security and access control
The regulation prohibits installing smart cameras or facial recognition software intended to analyze customers’ mood and emotions when viewing storefronts.
Private biometric systems may not be used to create automated admission blacklists for establishments.