EU AI Act for SMEs: Practical Steps for Small Businesses
Understanding the EU AI Act for SMEs
The European Union's Artificial Intelligence Act (AI Act) is a landmark piece of legislation designed to regulate AI systems based on their potential risk level. While much of the discussion has focused on large AI developers and high-risk applications, many small and medium-sized enterprises (SMEs) are wondering how this new regulation impacts their day-to-day use of AI tools. The good news is that for most SMEs simply using off-the-shelf AI tools, the immediate burden is less severe than often portrayed.
Focus on AI System Providers and High-Risk AI
The primary obligations of the AI Act fall on providers of AI systems, especially those developing or deploying 'high-risk' AI. High-risk AI systems are those that could cause significant harm to people's health, safety, or fundamental rights. Examples include AI used in critical infrastructure, medical devices, employment, law enforcement, and democratic processes. If your SME is developing such a system, the requirements are substantial, involving conformity assessments, risk management systems, data governance, and human oversight.
What if Your SME is a User of AI Tools?
Most SMEs are 'deployers' or 'users' of AI systems developed by others. For these businesses, the requirements are generally less onerous, particularly if they are not using high-risk AI. Here’s what you need to know:
- Transparency and Information: If you use an AI system classified as high-risk (e.g., an AI-powered recruitment tool), you have obligations to ensure human oversight and provide information to individuals affected by the AI's decisions. The provider of the high-risk AI system is primarily responsible for ensuring it meets the technical and legal requirements, but you, as the deployer, must ensure it's used appropriately.
- No New Obligations for Low-Risk AI: For AI systems that are not classified as high-risk (e.g., most general-purpose AI like ChatGPT for content generation, AI for basic customer support, or AI-powered marketing analytics), the Act imposes very few direct obligations on users. The focus here is on transparency from the provider side (e.g., clearly stating when content is AI-generated).
- General-Purpose AI (GPAI): The Act introduces specific rules for General-Purpose AI models, like large language models. Providers of these models have obligations related to transparency, technical documentation, and compliance with copyright law. As a user, you benefit from these requirements, as it means the tools you use should be more transparent and accountable.
- Prohibited AI Practices: Regardless of your size, you must not use AI systems that fall under the 'prohibited' category. These include AI that manipulates human behaviour in a way that causes harm, social scoring, or real-time remote biometric identification in public spaces by law enforcement (with very limited exceptions).
Practical Steps for Your SME
Even if you're not developing high-risk AI, adopting a proactive approach is wise:
- Inventory Your AI Tools: List all AI tools your company uses. Understand what they do and how they function.
- Assess Risk: For each tool, consider its potential impact. Is it making critical decisions affecting individuals? Does it process sensitive data? This helps identify if any tools might fall into a 'high-risk' category.
- Understand Provider Responsibilities: If you use third-party AI, familiarise yourself with your provider's compliance statements regarding the AI Act. They should be able to clarify if their system is considered high-risk and what your responsibilities are as a deployer.
- Ensure Human Oversight: For any AI system that impacts critical decisions, ensure there's a human in the loop who can review, override, and understand the AI's output.
- Stay Informed: The AI landscape and regulations are evolving. Keep an eye on official guidance from national authorities.
For a small or mid-sized Estonian company, the immediate priority is to understand which AI tools you are using, assess their potential impact, and ensure you are not inadvertently deploying high-risk systems without proper oversight. While the direct compliance burden for simple AI tool usage is low, understanding the framework helps you make informed choices and mitigate future risks.