It depends on what your AI touches, not your size. Data-protection law such as the GDPR applies whenever AI handles personal data. If you sell to customers in the EU, the EU AI Act adds staff AI literacy, chatbot and deepfake transparency, and stricter rules for AI in hiring or education decisions. Consumer, copyright and sector rules apply as usual.
This checklist is organised by what you do with AI, so you can skip the parts that don't apply. It's a map, not legal advice: where an item applies to you and the stakes are high, ask a solicitor or data-protection adviser. Dates are correct as of September 2026, and several have already been moved once, so check official sources before relying on any of them.
Start with a ten-minute inventory of your AI uses
Compliance follows use, so list your uses first. For each AI tool or feature the business uses, answer seven questions:
- What is it used for?
- Does any personal information go into it (customers, staff, pupils, candidates)?
- Do customers interact with it directly, or see its output?
- Does it make, or feed into, a decision about a person?
- Do you publish anything it produces (text, images, audio, video)?
- Are any of your customers in the EU?
- Is your business in a regulated sector, such as financial advice, legal services, health, childcare or education?
Here are the seven answers for one use at an illustrative two-van mobile dog-grooming business, where an AI assistant replies to booking messages on WhatsApp:
USE: AI assistant answering WhatsApp booking messages
1. Used for: prices, availability, booking and moving slots
2. Personal data: yes. Owners' names, mobile numbers, home
addresses. Also notes about the dog ("she's on
joint medication"), which are about the animal
3. Customers: yes, they talk to it directly
4. Decisions: no. It offers free slots; it can't refuse anyone
5. Publishes: no
6. EU customers: not at present
7. Regulated: no
That points to data protection (names, numbers and addresses stored by the chat vendor), consumer law (it quotes prices, so it must quote the right ones) and the platform's own rules: if the assistant runs on the WhatsApp Business Platform, Meta's terms allow bots tied to a business task such as bookings but bar general-purpose AI assistants, so its instructions should keep it to bookings and prices. The dog's medication is not the owner's health data, but a message like "I can't lift him since my operation" is about a person, so it's worth telling the assistant not to repeat or store such details in booking notes.
Most small businesses end up with three to eight uses. The table below shows which rules each kind of use tends to trigger.
Which rules each kind of AI use triggers
| If you use AI to… | Rules likely to apply | Main actions |
|---|---|---|
| Draft, summarise or analyse work containing personal data | Data protection; EU AI Act AI-literacy duty if you sell in the EU | Business plan with data-processing terms; data rules; staff training record |
| Talk to customers (chatbot, phone or message assistant) | EU AI Act transparency (from 2 Aug 2026); data protection; consumer law on what it tells people | Say it's AI at the first contact; update the privacy notice; limit what it can promise; easy route to a person |
| Create realistic images, audio or video | EU AI Act deepfake disclosure; platform rules; permission for any real person's likeness | Label AI media; get written consent |
| Screen, rank or assess job candidates or staff | EU AI Act high-risk rules (from 2 Dec 2027); data protection, including rules on automated decisions; equality law | A person makes every decision; test for bias; tell candidates |
| Place, admit, assess or mark learners | EU AI Act high-risk rules for education (from 2 Dec 2027); data protection; extra care with children | A teacher confirms outcomes; learners can ask for a human assessment |
| Monitor staff or read emotions | EU AI Act ban on inferring emotions in workplaces and education (since 2 Feb 2025); data protection; employment law | Don't use emotion-reading tools; take advice before any monitoring |
| Publish marketing, product copy or reviews | Consumer protection (misleading claims, fake reviews); copyright; marketplace rules | Check every claim; never generate reviews; follow platform labelling |
| Assess creditworthiness or price life or health insurance | EU AI Act high-risk rules; sector regulation | Take specialist advice before using AI here at all |
Data protection: the part that applies to almost everyone
If AI handles information about identifiable people, data-protection law applies whatever the business's size. Work through these:
- Know your lawful basis for each AI use of personal data. Using data collected for bookings to train or profile customers may need a different basis, or consent.
- Update your privacy notice to describe AI processing and the vendors involved, such as a chat provider that stores conversations. The difference is easiest to see as before and after. Before: "We may share your information with trusted partners to improve our services." After (illustrative wording, to adapt with your adviser): "Our website chat is an AI assistant provided by [vendor]. Your messages are stored by [vendor] for [period] so we can review conversations and correct mistakes. They are [not] used to train the vendor's AI models. You can ask us to delete a conversation at any time." Every bracket is something to confirm in the vendor's terms before publishing.
- Have data-processing terms with each vendor. Business plans usually include them; free consumer accounts usually don't give you what you need.
- Check where the vendor processes and stores data, and what safeguards apply when it's handled in another jurisdiction. The vendor's trust or privacy pages normally say.
- Minimise: remove names and identifiers wherever the task works without them.
- Do a data protection impact assessment (a written risk assessment) when the use is likely to be high risk: children's or health data, systematic monitoring, or new technology used at scale.
- Keep a person in significant decisions. The GDPR gives people rights around decisions based solely on automated processing that have legal or similarly significant effects on them, such as refusing a service or a job.
- Be able to answer rights requests: know where AI inputs and outputs are stored so you can find or delete someone's data.
- Set retention: how long chat logs, transcripts and generated files are kept.
The tutorial on GDPR and AI tools for a small business works through each step in more detail.
EU AI Act duties, if you sell to customers in the EU
Most small businesses are deployers under the Act (they use AI systems in their work), not providers (the companies that build them or put them on the market). Deployers have fewer duties, but not none.
- AI literacy (Article 4), applying since 2 February 2025. The Digital Omnibus on AI, in force since 27 July 2026, reworded this duty: businesses must take steps to help their staff understand AI well enough for their roles, but no longer have to ensure a set level of literacy. Short role-based training plus a record of it is a sensible response; see AI literacy requirements for staff.
- Prohibited practices (Article 5), applying since 2 February 2025. These include manipulative techniques that cause significant harm, exploiting people's vulnerabilities due to age, disability or social or economic situation, social scoring, and inferring emotions in workplaces and education settings (except for medical or safety reasons). New bans on generating non-consensual intimate imagery and child sexual abuse material apply from 2 December 2026; these mainly concern tool providers.
- Transparency (Article 50), applying since 2 August 2026. Chatbots and similar systems must make clear to people that they're dealing with AI, unless that's already obvious; the provider carries this duty, but the notice shows up on your site, so confirm it's there. As a deployer, you must flag deepfakes you publish. AI-written text meant to inform the public about matters of public interest also needs a label, except where a person has reviewed it and someone takes editorial responsibility for it. Providers of systems already on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking to AI-generated content. Writing an AI disclosure statement covers the customer-facing wording.
- High-risk uses (Annex III), deferred to 2 December 2027. Relevant areas for small firms include recruitment and selection (filtering applications, evaluating candidates), decisions about promotion, termination, task allocation and monitoring of workers, access to and assessment in education and training, creditworthiness checks, and pricing of life and health insurance. Deployers of high-risk systems must follow the provider's instructions, assign trained people to human oversight, keep the system's logs for at least six months, monitor it, inform workers before using it in the workplace, and tell people when such a system is used in decisions about them. AI embedded in regulated products under Annex I has until 2 August 2028.
The "monitoring of workers" and "task allocation" wording catches features owners don't think of as hiring or HR tools. Suppose a contract-cleaning firm with 30 cleaners finds its scheduling software has added an optional AI feature: it hands out next week's shifts using a "reliability score" built from each cleaner's check-in times and customer ratings. That is allocating work on the basis of monitored behaviour, which is exactly the kind of use Annex III lists, so for a firm with EU operations it would likely fall under the high-risk rules from December 2027. Practical steps now: leave the feature off, or keep a manager making the final allocation; ask the vendor in writing how it will meet provider duties; and tell staff what data feeds the score before it's ever used.
If you're considering AI in hiring, test it before 2027 regardless; bias checks for AI CV screening explains how.
Consumer, advertising and copyright rules
- What your chatbot says can bind you. A wrong price or a promised refund from an AI assistant is still your business talking. A realistic way it shows up: a furniture-restoration workshop's website chat, asked "do you collect?", replies "Yes, collection is free for all orders", because the site's FAQ page says collection is "free on orders over $500" and the assistant dropped the condition. The customer books a $180 repair and sends a screenshot when the $45 collection charge appears on the invoice. Most owners honour it, then restrict the assistant to answering prices and charges from a fixed list, word for word. Who is liable when your AI chatbot gets it wrong covers the practical steps.
- No fake reviews or testimonials, and no invented statistics or claims in AI-written marketing. Misleading-advertising rules apply however the text was produced.
- Marketplace rules: Google's guidance, for example, requires AI-generated product titles and descriptions in Merchant Center to be labelled as AI-generated, and AI-generated images to carry specific metadata.
- Copyright and ownership: check each vendor's terms on who owns outputs and whether they offer any protection if an output infringes someone's rights. Don't feed in material you're not licensed to use.
- Client contracts: some clients restrict or ban AI use on their work. Check before you use it on their material.
Employment and sector rules
- Staff monitoring: any AI that records or analyses what staff do needs a clear purpose, transparency with staff, and usually advice first.
- Hiring: equality and discrimination law applies to AI-assisted decisions exactly as to human ones.
- Regulated sectors: financial advice, legal services, health, childcare and education often have regulator or professional-body guidance on AI. Search your regulator's website for "artificial intelligence" and read what's there.
Worked example: a language school maps its AI uses
As an illustration, consider a language school teaching adults in person and online, with some online students in the EU. Its inventory produced six uses:
| Use | What applies | Action taken |
|---|---|---|
| Teachers draft lesson materials with Gemini in Google Workspace | AI literacy; minimal personal data | Short training session, recorded; no student details in prompts |
| Website chat assistant answers enquiries | Transparency; data protection; consumer law | "I'm an AI assistant" first line; privacy notice updated; fees answered only from a fixed list; handover to staff |
| Online placement test recommends a course level | High-risk area (assessing the appropriate level of education) from 2 Dec 2027 | A teacher confirms every placement; students can ask for a teacher assessment; vendor asked how it will meet provider duties |
| AI suggests marks and feedback on writing homework | High-risk area (evaluating learning outcomes) from 2 Dec 2027 | Teacher reviews every mark; AI marks never used alone for certificates |
| AI note-taker summarises recorded online lessons | Data protection | Students told at enrolment and at the start of each recorded lesson; recordings deleted after 30 days |
| Vendor pitch: webcam "engagement and emotion" tracking for online classes | Prohibited: inferring emotions in education | Declined |
Two of the six uses fall in areas the Act treats as high-risk, which surprised the owner: the placement test and the homework marking both looked like ordinary software features. Because the high-risk date is December 2027, the school had time to put teacher sign-off in place and ask its vendors the right questions, rather than scrambling later.
What to keep on file
If anyone asks how you manage AI, whether a customer, a client's procurement team or a regulator, these documents answer most questions:
- The AI inventory from the first step, with the date you last updated it.
- Your AI usage policy and staff acknowledgements.
- Training records: who attended what, and when.
- Vendor data-processing terms for each tool.
- Any data protection impact assessments.
- Screenshots or copies of your AI disclosures (chat opening line, website statement, labels).
- A risk or decisions log, especially for any use in a high-risk area.
- An incident log, even if it's empty.
Alongside the legal questions, run each use through the AI ethics checklist too. Several things that are lawful are still worth not doing.
When to pay for legal advice
You can work through most of this list yourself. Get a solicitor or data-protection adviser involved when:
- you plan to use AI in any high-risk area: hiring, managing staff, education decisions, credit or insurance;
- children's, health or other sensitive data would go into an AI tool;
- you want to monitor staff with any AI tool;
- AI would make or heavily shape decisions with significant effects on people;
- you're in a regulated profession and your regulator's guidance is unclear;
- personal data may have leaked through an AI tool, since data-breach reporting deadlines can be short.
An hour of advice on one of these costs far less than getting it wrong, and a completed inventory and table like the ones above make that hour much more productive.
Compliance questions owners ask
Does the EU AI Act apply if my business isn't based in the EU?
It can. The Act reaches businesses outside the EU when the output of their AI system is used in the EU, for example when EU customers talk to your chatbot or receive decisions it helped make. If you have EU customers, assume the transparency rules apply to anything they interact with, and take advice before using AI in any high-risk area such as hiring or assessing learners.
Are small businesses exempt from the EU AI Act?
No. There's no general exemption by size. The Act does include measures meant to help small firms, and for SMEs each fine is capped at the lower of the percentage or fixed amount it sets, rather than the higher. But the prohibitions, transparency duties and high-risk rules apply according to what the AI does, not how big the business is.
How often should I re-check this list?
Every six months, and whenever you add an AI tool, start using AI with a new kind of personal data, or begin selling into a new market. Several AI Act dates fall in 2026 to 2028, and dates have already moved once, so check official sources at each review rather than relying on this list.
Further reads
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the main AI assistants handle data-protection duties.
- What to Check in an AI Tool's Privacy Policy and Terms — What to read in a vendor's terms before approving it.
- A Simple AI Risk Register for Small Businesses (With Template) — Somewhere to record the risks this checklist turns up.
- AI Incident Response Plan for Small Businesses (With Template) — What to do if personal data leaks through an AI tool.
- How to Write an AI Usage Policy for Your Small Business — Turn the checklist's answers into staff rules.
- Can You Legally Use AI-Generated Images in Your Marketing? — The legal side of AI images in marketing.
- AI Governance for a Small Business: Who Decides, Approves, Checks — Who says yes to AI in a small firm, and who looks back: a decision-rights table, three approval tiers, a 30-minute monthly check and a one-page register.
- What Are the Risks of Using AI in My Small Business? — Eight risks of using AI in a small business, a four-factor score for your own exposure, three example risk profiles, and the cheapest control for each risk.
- AI Bias in Small Business Decisions: Hiring, Pricing and Credit — How AI tools pick up bias in hiring, quotes and payment terms, the proxies to strip out, and an afternoon test to check any AI-assisted decision.
- Does a Five-Person Business Really Need an AI Policy? — Why a five-person business needs a one-page AI policy rather than a handbook: six triggers, a complete template, and when one page stops being enough.
- Should You Tell Customers You Use AI? A Disclosure Guide — When to tell customers you use AI and when you needn't, with a decision table for 11 everyday uses and wording you can copy for chats, quotes and emails.
- Does Your Business Insurance Cover AI Mistakes? — Match each kind of AI mistake to the policy that would respond, spot the new AI exclusions at renewal, and send your broker five precise questions.
- How Property Managers Use AI to Screen Tenant Applications Fairly — Written criteria, one summary format for every applicant, human decisions with recorded reasons, and a monthly check that your rules aren't quietly unfair.
- Does Cyber Insurance Cover AI Incidents? What Insurers Ask — Which AI incidents a cyber policy usually covers, where the grey areas are, and how to answer the new AI questions on insurers' proposal forms.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: EU AI Act text (Articles 4, 5, 26, 50, 99 and Annex III); the EU's FAQ on Article 50 transparency obligations; published summaries of the Digital Omnibus on AI and its revised dates; Google Search Central guidance on generative AI content. Checked September 2026. Not legal advice.