EU AI Act for Small Businesses: What Counts as High Risk?

A clear breakdown of the EU Artificial Intelligence Act for small teams, startups, and agencies using or deploying AI tools.

CyberChecklist Editorial Team3 min read
Key Takeaways
  • The EU AI Act classifies AI systems into Unacceptable Risk, High Risk, Specific Transparency Risk, and Minimal Risk.
  • Using standard tools like ChatGPT, Copilot, or Midjourney generally falls under Transparency obligations (Article 50).
  • Deploying AI in hiring, employee evaluation, credit scoring, or biometric categorization triggers strict High-Risk obligations.
  • Fines can reach up to €35M or 7% of global turnover for prohibited AI practices.

The European Union Artificial Intelligence Act (EU AI Act) is the world's first comprehensive legal framework governing artificial intelligence. While major tech headlines focus on foundation model developers like OpenAI or Google, the regulation applies to any business in the EU—or serving EU citizens—that uses or integrates AI systems.

For small businesses, freelancers, and growing agencies, the critical first step is understanding your risk classification under the Act.

The 4 Risk Tiers Under the EU AI Act

The EU AI Act takes a strictly risk-based approach:

1. Unacceptable Risk (Prohibited)

Systems that pose a clear threat to safety or fundamental human rights are banned outright. Examples include: - Cognitive behavioral manipulation targeting vulnerable individuals. - Social scoring systems based on social behavior or personality traits. - Real-time biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions).

2. High Risk (Strict Compliance Required)

AI systems used in critical sectors and processes that impact health, safety, or fundamental rights. Key business triggers include: - HR & Employment: Automated CV filtering, candidate ranking software, or AI-driven worker performance evaluation. - Access to Essential Services: AI credit scoring, insurance risk pricing, or eligibility evaluation for public benefits. - Critical Infrastructure: AI managing water, electricity, or digital traffic systems. - Education & Vocational Training: AI tools evaluating student exam results or admission choices.

If you deploy high-risk AI, you must maintain extensive risk management systems, ensure data governance, keep continuous event logs, provide human oversight mechanisms, and undergo conformity assessments.

3. Specific Transparency Risk (GenAI & Chatbots)

If you deploy AI systems that interact directly with humans (e.g. customer support chatbots) or generate synthetic media (deepfakes, audio, AI marketing content), Article 50 requires clear disclosure: - Inform users they are interacting with an AI system. - Watermark or visibly label AI-generated images, audio, and video.

4. Minimal / Low Risk

Everyday AI applications such as spam filters, AI-powered inventory forecasts, and basic recommendation engines face zero additional regulatory barriers under the Act.

Are You a 'Provider' or a 'Deployer'?

Most small businesses are Deployers (users of AI systems under their own authority) rather than Providers (developers putting an AI system on the market).

As a deployer: - You must use AI systems according to the provider's instructions for use. - You must ensure human oversight by competent, trained personnel. - You must monitor system performance and immediately report serious incidents to the provider and national market authority. - When using high-risk AI for workplace decisions, you must inform affected workers and employee representatives.

Checklist: 3 Practical Steps for SMEs Today

  1. Conduct an Internal AI Inventory: Document every AI tool your team currently uses (chatbots, copy generators, screening tools, analytics).
  2. Review HR & Customer-Facing Tools: Confirm none of your screening or customer evaluation tools inadvertently trigger High-Risk requirements.
  3. Add Transparency Disclaimers: If your website uses customer service chatbots or synthetic visuals, ensure clear disclosure notices are visible.