How Small Businesses Can Comply with the AI Act

July 28, 2026

On August 2, 2026, the Artificial Intelligence Regulation, or the AI Act, enters its general deployment phase. In other words, compliance becomes mandatory for companies operating in Spain and the rest of the EU, though some requirements are postponed until December 2027 due to the Digital Omnibus Regulation. For U.S. businesses, this regulation applies only if you process data of EU residents or operate within the EU market.

Therefore, in this guide we break down how to , taking into account the most common uses of this technology by small and midsize businesses (SMBs) and with concrete examples from different sectors.

What obligations does the AI Act impose for the use of AI in businesses?

Uses and prohibited practices

They are subject to a total ban due to their threat to fundamental rights:

  • Cognitive manipulation: Systems that use subliminal techniques to distort human behavior.
  • Social scoring: Classification of people by public authorities based on their conduct or profile.
  • Remote biometric identification or categorization: Real-time use in public spaces (with very strict exceptions).
  • Emotion recognition: Its use in workplace and educational settings.

High-risk systems: The core of the obligations

Affects systems that evaluate people (credit, employment, education, justice, biometrics). You must comply with:

  • Bias mitigation and control: Obligation to use clean, representative training data free from discriminatory biases.
  • Mandatory human oversight: Systems must be designed so that qualified people can monitor, correct, or turn off the AI at any time.
  • Activity logging (Logs): Automatic traceability of events and decisions to audit AI behavior.

Limited-risk systems: Basic transparency obligations

Affects common systems such as chatbots, image generators, or spam filters:

  • User information: Always inform users when they are interacting with AI.
  • Watermarks: Watermark synthetic content (deepfakes, automatically generated informative texts, generated audio) obligatorily.

No obligations

AI-powered video games, photo filters, or spell-checkers do not have added legal obligations, though voluntary codes of conduct are encouraged.

What to do to comply with the AI Act in a small business?

Analyze the AI tools your company uses and their risk level

Recent studies indicate that 73% of SMBs do not know whether they use high-risk AI systems, and 82% do not even have an inventory of the tools that deploy this technology.

The most advisable course in this case is to seek specialized help. For example, compliance-focused firms like Atico34 offer their own software to comply with the AI Act, Atico34 AI Governance, an affordable solution for SMBs that also provides legal advice from AI and data protection experts.

Warning, scroll to continue reading

Create the inventory and the internal digital literacy policy

Once the assessment is completed, the company should formalize the management of its technological assets through a centralized and confidential registry of the programs it uses.

This documentation must be backed by a training program for the workforce, a legal requirement aimed at ensuring employees use technology with ethical safety criteria.

Apply the mandatory transparency measures

In practice, companies that use virtual assistants or automated support channels must obligatorily configure clear notifications informing the user about the nature of the system.

They must also include watermarks or legible labels on any content—visual, written, or audio—generated synthetically.

Establish human oversight for high-risk systems

When contracted systems intervene in critical areas such as human resources management or financial evaluation, the SMB must structure a rigorous internal control protocol.

This implies designating a qualified professional to audit algorithmic results, ensuring that high-sensitivity processes like resume filtering or shift assignments always require human validation before final application, as noted in Article 14 of the AI Act.

Review contracts and conduct ongoing security audits

SMBs should require explicit compliance clauses and data-handling immunity from their tech partners.

It is advisable to set up a schedule of periodic reviews to ensure the security of the digital environment whenever a new application is integrated into the daily workflow.

Practical examples: How it applies in each area of the business

Customer service and front desk

If you implement automatic voice assistants to manage phone reservations at a restaurant or hotel, or if you install a chatbot on an e-commerce site to resolve common questions, you are operating in the Limited Risk category.

The regulation requires strict adherence to the transparency principle: the system must notify the user with a clear message or an audible cue that they are interacting with artificial intelligence and not a human.

Human resources and personnel management

Here, AI use is automatically classified as High Risk, even if you manage retail staff, waiters, or consultants.

If you use platforms to sift candidate resumes, evaluate staff performance, or design work shifts, the SMB is legally obliged to establish active human oversight. A supervisor must monitor the algorithm to avoid discriminatory bias and ensure that AI never makes critical employment decisions autonomously.

Marketing and commercial design

The use of content-generation tools like Midjourney, ChatGPT, or Claude to draft ad copy, program website code, or design catalog backgrounds generally falls under Minimal or Limited Risk.

The primary obligation lies in visual honesty: if you create hyperrealistic images, audio, or videos that could mislead consumers by appearing real, you must clearly label them as AI-generated content.

Operations, logistics, and purchasing

AI systems used for purely operational tasks, such as real-time route optimization based on traffic, inventory forecasting for a store, or raw-material cost control in a kitchen, fall into the Minimal risk category.

These algorithms process logistical or numeric data that do not impinge on freedoms or fundamental rights, so your SMB can continue to use these technologies normally without additional legal obligations.

Security and access control

The regulation prohibits installing smart cameras or facial recognition software intended to analyze customers’ mood and emotions when viewing storefronts.

Private biometric systems may not be used to create automated admission blacklists for establishments.

Garrett Mercer

I cover business, startups, and the companies shaping today’s economy. My work focuses on breaking down complex topics into clear, useful insights, with a strong interest in growth strategies and market shifts. I aim to deliver content that is both informative and easy to understand for a wide audience.

Get in Touch with Our Team
Have a question, a partnership opportunity, or a story to share? Reach out to us and connect with a media platform focused on business insights and growth.