AI Guides › Playbooks
By Nigel Guy · 7 min read
Most small operators do one of two things with the EU AI Act: ignore it because it sounds like a rule for banks and carmakers, or download a 40-point checklist and tick boxes without knowing which ones apply to them. Both feel sensible and both fail. The Act does not regulate "AI businesses" as a block. It regulates specific uses, and your obligations depend on what you do with each tool and what role you play.
The rule: list every AI use in your business, give each one a role and a risk tier, and do only the work that tier demands, with a dated record of what you did.
This is plain-English orientation, not legal advice. If your use touches hiring, credit, education, health or anything that decides things about people, speak to a qualified adviser.
The Act applies by what you do, not where you sit. In outline, it can reach you if you place AI systems on the EU market or if the output of a system you use is used in the EU. Selling to EU customers, or running a site or service EU residents use, is the trigger to check. If you only serve UK customers with no EU link, the Act is mostly background, though UK-based AI tools you rely on may change their terms because of it.
One table, one row per AI use. Not per tool: the same tool used for two jobs gets two rows.
| Column | What to write |
|---|---|
| Use | One line, e.g. "chatbot answering product questions on our site" |
| Tool and vendor | Who makes it |
| Role | Provider (you build or put your name on it) or deployer (you use someone else's system) |
| Who is affected | Customers, staff, the public, nobody outside the team |
| Tier | Prohibited, high-risk, transparency, or minimal |
| Action | What you do about it |
| Date reviewed | Today's date, and when you will look again |
Most small businesses are deployers of someone else's tools. Becoming a provider happens when you build a system, or rebrand and sell one under your own name. Check that carefully, because provider duties are much heavier.
| Tier | Plain meaning | Your action |
|---|---|---|
| Prohibited | A short list of banned practices, such as harmful manipulation, social scoring and emotion recognition in workplaces | Do not do it. Check each use against the current list |
| High-risk | Systems used in areas such as employment, education, essential services, critical infrastructure and law enforcement | Stop and get advice before you go further |
| Transparency | Systems that talk to people, or that generate or alter content | Tell people, and label content where Article 50 requires it |
| Minimal | Most everyday tools: spam filters, drafting aids, internal summarisers | No specific AI Act duty beyond staff understanding |
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibitions and the AI literacy duty |
| 2 August 2025 | General-purpose AI model rules (aimed at model makers) |
| 2 August 2026 | Most remaining rules and enforcement |
| 2 December 2026 | New prohibitions added by the Digital Omnibus on AI, and a transition deadline for Article 50(2) marking |
| 2 December 2027 | High-risk rules for Annex III areas |
| 2 August 2028 | High-risk rules for AI built into regulated products |
The Commission's own timeline page notes that the Digital Omnibus amended some provisions and points to its FAQ for detail. Dates have moved before, so check the Commission page (linked below) before you rely on any of them.
Hour 1: build the register. Include anything an assistant, freelancer or contractor uses on your behalf. Staff using free AI accounts you did not know about count.
Hour 2: check prohibitions and high-risk. Read the Commission's page on the risk categories against each row. Be honest about hiring, customer scoring and anything involving emotions or biometrics.
Hour 3: handle transparency. Article 50, in summary: people must be told when they are dealing with an AI system unless that is obvious; deployers of deepfakes must disclose that content is artificially generated or manipulated; and providers of systems that generate synthetic content must mark outputs in machine-readable form, with exceptions for assistive editing. In practice for a deployer: put a plain "you are chatting with an AI assistant" line at the start of a chatbot, and label synthetic images or video of real-looking people or events. Disclosure must come at the latest at first interaction or exposure.
Hour 4: AI literacy and records. Article 4 requires providers and deployers to take measures to support AI literacy among staff and others using AI on their behalf. It does not require a certificate or a guaranteed level for each person. A short written note covering who uses what, what they were told about limits, and when, is a proportionate record. The Digital Omnibus changed the wording of this duty, so check the current text.
Optional prompt to speed up the register:
You are a careful compliance-minded assistant helping a small business owner organise, not give legal advice.
Goal: turn the list of AI uses below into an AI Use Register with columns: Use, Tool, Role (provider or deployer), Who is affected, Likely tier (prohibited, high-risk, transparency, minimal), Suggested action, Questions I need answered.
Inputs: [LIST_OF_AI_USES], [WHERE_CUSTOMERS_ARE_LOCATED], [WHETHER_WE_BUILD_OR_REBRAND_ANY_TOOL]
Rules: Ask me for anything missing instead of guessing. Mark any row touching hiring, credit, education, health or decisions about people as "needs adviser". Do not state legal conclusions as certain. Quote no article numbers you are not sure of.
Before answering, check that every use has a row and every uncertain row is flagged.
Fill in the three bracketed items. Check the output against the Commission pages yourself.
A one-person shop in Leeds sells printed art to customers across the EU. Uses: a chatbot on the site (transparency, deployer), Midjourney-style image generation for product mock-ups shown to customers (transparency, label if it looks like a real photograph of events or people), an AI tool that drafts emails (minimal), and a spreadsheet tool that ranks freelance applicants (flag: hiring, high-risk area, get advice before using it). Result: one chatbot disclosure line, a labelling habit, one tool paused, and a register dated and filed. About three hours.
| Mistake | Fix |
|---|---|
| Treating yourself as a provider when you are a deployer, or the reverse | Ask: do I put my name on it or sell it? |
| One row for "ChatGPT" | One row per use |
| Forgetting staff and contractors' tools | Ask them directly |
| Writing the register once | Put a review date in the calendar, and re-check when a tool changes |
You can answer, in under a minute, what AI you use, on whom, in which tier, and when you last looked. A customer who asks gets a straight answer.