As of early July 2026. This article puts legal texts into plain language — carefully researched and linked to primary sources, but not legal advice. In keeping with this site's ethos, we don't guess on legal questions.
Two equally wrong summaries of Europe's AI law are in circulation: "only concerns the big AI companies" and "is about to ban everything". This article sorts out what the AI Act means in practice for small operators — freelancers and small firms that use AI: in their operations, on their website, in customer contact. Much like us.
What the AI Act is
Behind the buzzword sits Regulation (EU) 2024/1689 of 13 June 2024, officially just the "Artificial Intelligence Act". Published on 12 July 2024, in force since 1 August 2024 — but with a staggered start: the prohibitions and the AI-literacy duty have applied since 2 February 2025, the rules for providers of large general-purpose models and the penalty framework since 2 August 2025. The main stage — and with it almost everything that concerns small operators — kicks in on 2 August 2026.
That timetable saw one late shift in June 2026: with the "Digital Omnibus", Parliament and Council stretched parts of the schedule. The strict duties for high-risk systems now start on 2 December 2027 (2 August 2028 for AI embedded as a safety component in regulated products), and providers of systems already on the market get until 2 December 2026 for the machine-readable labelling of AI-generated content. New on the list is a ban on AI systems that generate abuse material or nude images of real people without their consent ("nudifier" apps) — effective from December 2026. The core is untouched: the main stage on 2 August 2026 stands. (The Council gave its final approval on 29 June 2026; in early July, publication in the Official Journal was imminent.)
The basic approach is risk-based: the greater the harm potential of an AI use, the stricter the rules — from banned practices through tightly regulated high-risk applications down to light transparency duties for everyday AI.
The four tiers, each with examples from the regulation text: Banned (Article 5) are, among others, deliberately manipulative techniques, the untargeted scraping of facial images from the internet for recognition databases, and emotion recognition in workplaces or schools. High-risk (Annex III) is AI that decides about people — say, in recruiting and candidate selection, or in creditworthiness assessments. Transparency-bound (Article 50) is everyday AI that interacts with people or generates content: chatbots, generated images and voices. Everything else — the vast majority, from spellcheckers to spam filters — carries no new duties.
The decisive fork: provider or deployer?
The law distinguishes roles. Whoever develops an AI system and puts it on the market carries different duties than whoever uses a finished system professionally.
A "provider", under Article 3, is whoever develops (or has developed) an AI system and puts it on the market under their own name or trademark. A "deployer" is whoever uses an AI system under their own authority — except for purely personal, non-professional use: if you plan and write with a chatbot privately, none of this concerns you. The boundary gets interesting at the question many small firms ask: does wiring an AI interface into your own website — a bought-in chat widget, say — make you a provider? As a rule, no. The fork (Article 25) only flips for high-risk systems if you put your own name or trademark on someone else's system, substantially modify it, or repurpose it in a way that turns it into a high-risk system. If you simply use a tool and present it as what it is, you remain a deployer.
For most small businesses, the deployer role is likely the relevant one — and its duty catalogue is the core of this article:
AI literacy (Article 4, in effect since February 2025): providers and deployers alike must ensure, "to their best extent", that their staff have enough AI understanding for the context they work in. That sounds like a training mandate but is deliberately softer: the Commission's questions and answers make clear there are no prescribed trainings and no one-size-fits-all — what counts is what fits the concrete use; enforcement sits with national authorities from 2 August 2026. Transparency in customer contact (Article 50, from 2 August 2026): if a chatbot answers your customers, a reasonably informed person must be able to tell; if you publish deepfakes, you must disclose them (more below). High-risk deployer duties (Article 26, from 2 December 2027): whoever uses AI in hiring, for instance, must use it as the manufacturer intends, keep a human in charge of oversight — and inform the affected employees and their representatives beforehand. If you run such systems today, put the date in the calendar and don't postpone the diligence to 2027.
Labelling what AI generates?
The question website operators ask most: do AI-generated texts and images have to be labelled as such?
Article 50 splits the duty across two levels. The machine-readable marking of generated content — watermarking in the broad sense — is the job of the tools' providers, not their users (for systems already on the market before August 2026, postponed by the omnibus to 2 December 2026). For deployers, the disclosure duty applies in two cases: deepfakes — deceptively real image, audio or video content of real people or events — and published texts informing the public on matters of public interest. Even there, exceptions apply: for evidently artistic or satirical works an unobtrusive disclosure suffices, and the text duty falls away where a human reviews the content editorially and a person takes editorial responsibility for the publication. Turned around: the AI-assisted blog post, the generated illustration, the AI-polished newsletter of a small business is not subject to labelling under the AI Act — as long as it doesn't become a deepfake or an unreviewed news item.
About our own practice, only this much: this site is built in close collaboration with AI and makes no secret of it — wherever the legal line ends up running.
What's at stake for violations — and what isn't
The penalty framework (Article 99) has three tiers and has applied since August 2025: up to €35 million or 7 percent of worldwide annual turnover for banned practices, up to €15 million or 3 percent for breaches of the operational duties (including the deployer and transparency duties), up to €7.5 million or 1 percent for supplying false information to authorities. For small and medium-sized enterprises, the lower of the two values applies in every case — explicitly. The headline sums aim at corporations; a small business using a bought-in tool properly is not what these provisions are hunting. In Germany, the Bundestag passed the national implementation act in June 2026: supervision is being bundled at the Federal Network Agency (Bundesnetzagentur), which is building a competence centre, involves the sectoral authorities — and starts its work with the main stage on 2 August 2026.
What you can do today
Even without the research pass, some advice is safe — not as law, but as good housekeeping: keep a list of where AI is in use in your business; for customer-facing tools, check whether people can tell they're talking to a machine; and treat anything touching decisions about people (applications, creditworthiness, prices) with special care — those are exactly the zones the law has its eye on.
With the facts in hand, the list can be sharpened. First: actually keep that AI inventory — it doubles as the evidence base for the AI-literacy duty that already applies. Second: make customer-facing chatbots and voice assistants recognisable by August 2026; it costs one sentence. Third: if you generate images or voices of real people, or publish AI text unreviewed, you need a disclosure from August 2026 — if a human reviews everything, there is nothing to do here. Fourth: AI in hiring or credit decisions means high-risk duties from December 2027 — note the date, request the manufacturer's documentation, involve your staff. And fifth: the Commission's Q&A pages and the Federal Network Agency's AI pages are meant as first stops — free, official, and considerably more readable than the regulation itself.
/compact — the essentials, if context is running low:
The AI Act (Regulation (EU) 2024/1689) applies in stages: prohibitions and AI literacy since February 2025, the main stage from 2 August 2026 — the June 2026 Digital Omnibus only postpones the high-risk duties (December 2027/August 2028) and machine-readable labelling for existing systems (December 2026). Small businesses are almost always "deployers": they must keep their team AI-literate, make chatbots recognisable and disclose deepfakes — AI-assisted, editorially reviewed texts and images carry no labelling duty. The million-euro fines target banned practices and corporations; for SMEs the lower value always applies, and in Germany the Federal Network Agency will bundle supervision.