AI Compliance Checklist for Small Businesses: What Applies to You

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for AI Compliance Checklist for Small Businesses: What Applies to You.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for AI Compliance Checklist for Small Businesses: What Applies to You.

It depends on what your AI touches, not your size. Data-protection law such as the GDPR applies whenever AI handles personal data. If you sell to customers in the EU, the EU AI Act adds staff AI literacy, chatbot and deepfake transparency, and stricter rules for AI in hiring or education decisions. Consumer, copyright and sector rules apply as usual.

This checklist is organised by what you do with AI, so you can skip the parts that don't apply. It's a map, not legal advice: where an item applies to you and the stakes are high, ask a solicitor or data-protection adviser. Dates are correct as of September 2026, and several have already been moved once, so check official sources before relying on any of them.

Follow me on Instagram@sagnikteaches

Start with a ten-minute inventory of your AI uses

Compliance follows use, so list your uses first. For each AI tool or feature the business uses, answer seven questions:

Connect on LinkedInSagnik Bhattacharya
  1. What is it used for?
  2. Does any personal information go into it (customers, staff, pupils, candidates)?
  3. Do customers interact with it directly, or see its output?
  4. Does it make, or feed into, a decision about a person?
  5. Do you publish anything it produces (text, images, audio, video)?
  6. Are any of your customers in the EU?
  7. Is your business in a regulated sector, such as financial advice, legal services, health, childcare or education?

Here are the seven answers for one use at an illustrative two-van mobile dog-grooming business, where an AI assistant replies to booking messages on WhatsApp:

Subscribe on YouTube@codingliquids
USE: AI assistant answering WhatsApp booking messages
1. Used for:     prices, availability, booking and moving slots
2. Personal data: yes. Owners' names, mobile numbers, home
                 addresses. Also notes about the dog ("she's on
                 joint medication"), which are about the animal
3. Customers:    yes, they talk to it directly
4. Decisions:    no. It offers free slots; it can't refuse anyone
5. Publishes:    no
6. EU customers: not at present
7. Regulated:    no

That points to data protection (names, numbers and addresses stored by the chat vendor), consumer law (it quotes prices, so it must quote the right ones) and the platform's own rules: if the assistant runs on the WhatsApp Business Platform, Meta's terms allow bots tied to a business task such as bookings but bar general-purpose AI assistants, so its instructions should keep it to bookings and prices. The dog's medication is not the owner's health data, but a message like "I can't lift him since my operation" is about a person, so it's worth telling the assistant not to repeat or store such details in booking notes.

Most small businesses end up with three to eight uses. The table below shows which rules each kind of use tends to trigger.

Which rules each kind of AI use triggers

If you use AI to…Rules likely to applyMain actions
Draft, summarise or analyse work containing personal dataData protection; EU AI Act AI-literacy duty if you sell in the EUBusiness plan with data-processing terms; data rules; staff training record
Talk to customers (chatbot, phone or message assistant)EU AI Act transparency (from 2 Aug 2026); data protection; consumer law on what it tells peopleSay it's AI at the first contact; update the privacy notice; limit what it can promise; easy route to a person
Create realistic images, audio or videoEU AI Act deepfake disclosure; platform rules; permission for any real person's likenessLabel AI media; get written consent
Screen, rank or assess job candidates or staffEU AI Act high-risk rules (from 2 Dec 2027); data protection, including rules on automated decisions; equality lawA person makes every decision; test for bias; tell candidates
Place, admit, assess or mark learnersEU AI Act high-risk rules for education (from 2 Dec 2027); data protection; extra care with childrenA teacher confirms outcomes; learners can ask for a human assessment
Monitor staff or read emotionsEU AI Act ban on inferring emotions in workplaces and education (since 2 Feb 2025); data protection; employment lawDon't use emotion-reading tools; take advice before any monitoring
Publish marketing, product copy or reviewsConsumer protection (misleading claims, fake reviews); copyright; marketplace rulesCheck every claim; never generate reviews; follow platform labelling
Assess creditworthiness or price life or health insuranceEU AI Act high-risk rules; sector regulationTake specialist advice before using AI here at all

Data protection: the part that applies to almost everyone

If AI handles information about identifiable people, data-protection law applies whatever the business's size. Work through these:

  • Know your lawful basis for each AI use of personal data. Using data collected for bookings to train or profile customers may need a different basis, or consent.
  • Update your privacy notice to describe AI processing and the vendors involved, such as a chat provider that stores conversations. The difference is easiest to see as before and after. Before: "We may share your information with trusted partners to improve our services." After (illustrative wording, to adapt with your adviser): "Our website chat is an AI assistant provided by [vendor]. Your messages are stored by [vendor] for [period] so we can review conversations and correct mistakes. They are [not] used to train the vendor's AI models. You can ask us to delete a conversation at any time." Every bracket is something to confirm in the vendor's terms before publishing.
  • Have data-processing terms with each vendor. Business plans usually include them; free consumer accounts usually don't give you what you need.
  • Check where the vendor processes and stores data, and what safeguards apply when it's handled in another jurisdiction. The vendor's trust or privacy pages normally say.
  • Minimise: remove names and identifiers wherever the task works without them.
  • Do a data protection impact assessment (a written risk assessment) when the use is likely to be high risk: children's or health data, systematic monitoring, or new technology used at scale.
  • Keep a person in significant decisions. The GDPR gives people rights around decisions based solely on automated processing that have legal or similarly significant effects on them, such as refusing a service or a job.
  • Be able to answer rights requests: know where AI inputs and outputs are stored so you can find or delete someone's data.
  • Set retention: how long chat logs, transcripts and generated files are kept.

The tutorial on GDPR and AI tools for a small business works through each step in more detail.

EU AI Act duties, if you sell to customers in the EU

Most small businesses are deployers under the Act (they use AI systems in their work), not providers (the companies that build them or put them on the market). Deployers have fewer duties, but not none.

  • AI literacy (Article 4), applying since 2 February 2025. The Digital Omnibus on AI, in force since 27 July 2026, reworded this duty: businesses must take steps to help their staff understand AI well enough for their roles, but no longer have to ensure a set level of literacy. Short role-based training plus a record of it is a sensible response; see AI literacy requirements for staff.
  • Prohibited practices (Article 5), applying since 2 February 2025. These include manipulative techniques that cause significant harm, exploiting people's vulnerabilities due to age, disability or social or economic situation, social scoring, and inferring emotions in workplaces and education settings (except for medical or safety reasons). New bans on generating non-consensual intimate imagery and child sexual abuse material apply from 2 December 2026; these mainly concern tool providers.
  • Transparency (Article 50), applying since 2 August 2026. Chatbots and similar systems must make clear to people that they're dealing with AI, unless that's already obvious; the provider carries this duty, but the notice shows up on your site, so confirm it's there. As a deployer, you must flag deepfakes you publish. AI-written text meant to inform the public about matters of public interest also needs a label, except where a person has reviewed it and someone takes editorial responsibility for it. Providers of systems already on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking to AI-generated content. Writing an AI disclosure statement covers the customer-facing wording.
  • High-risk uses (Annex III), deferred to 2 December 2027. Relevant areas for small firms include recruitment and selection (filtering applications, evaluating candidates), decisions about promotion, termination, task allocation and monitoring of workers, access to and assessment in education and training, creditworthiness checks, and pricing of life and health insurance. Deployers of high-risk systems must follow the provider's instructions, assign trained people to human oversight, keep the system's logs for at least six months, monitor it, inform workers before using it in the workplace, and tell people when such a system is used in decisions about them. AI embedded in regulated products under Annex I has until 2 August 2028.

The "monitoring of workers" and "task allocation" wording catches features owners don't think of as hiring or HR tools. Suppose a contract-cleaning firm with 30 cleaners finds its scheduling software has added an optional AI feature: it hands out next week's shifts using a "reliability score" built from each cleaner's check-in times and customer ratings. That is allocating work on the basis of monitored behaviour, which is exactly the kind of use Annex III lists, so for a firm with EU operations it would likely fall under the high-risk rules from December 2027. Practical steps now: leave the feature off, or keep a manager making the final allocation; ask the vendor in writing how it will meet provider duties; and tell staff what data feeds the score before it's ever used.

If you're considering AI in hiring, test it before 2027 regardless; bias checks for AI CV screening explains how.

Consumer, advertising and copyright rules

  • What your chatbot says can bind you. A wrong price or a promised refund from an AI assistant is still your business talking. A realistic way it shows up: a furniture-restoration workshop's website chat, asked "do you collect?", replies "Yes, collection is free for all orders", because the site's FAQ page says collection is "free on orders over $500" and the assistant dropped the condition. The customer books a $180 repair and sends a screenshot when the $45 collection charge appears on the invoice. Most owners honour it, then restrict the assistant to answering prices and charges from a fixed list, word for word. Who is liable when your AI chatbot gets it wrong covers the practical steps.
  • No fake reviews or testimonials, and no invented statistics or claims in AI-written marketing. Misleading-advertising rules apply however the text was produced.
  • Marketplace rules: Google's guidance, for example, requires AI-generated product titles and descriptions in Merchant Center to be labelled as AI-generated, and AI-generated images to carry specific metadata.
  • Copyright and ownership: check each vendor's terms on who owns outputs and whether they offer any protection if an output infringes someone's rights. Don't feed in material you're not licensed to use.
  • Client contracts: some clients restrict or ban AI use on their work. Check before you use it on their material.

Employment and sector rules

  • Staff monitoring: any AI that records or analyses what staff do needs a clear purpose, transparency with staff, and usually advice first.
  • Hiring: equality and discrimination law applies to AI-assisted decisions exactly as to human ones.
  • Regulated sectors: financial advice, legal services, health, childcare and education often have regulator or professional-body guidance on AI. Search your regulator's website for "artificial intelligence" and read what's there.

Worked example: a language school maps its AI uses

As an illustration, consider a language school teaching adults in person and online, with some online students in the EU. Its inventory produced six uses:

UseWhat appliesAction taken
Teachers draft lesson materials with Gemini in Google WorkspaceAI literacy; minimal personal dataShort training session, recorded; no student details in prompts
Website chat assistant answers enquiriesTransparency; data protection; consumer law"I'm an AI assistant" first line; privacy notice updated; fees answered only from a fixed list; handover to staff
Online placement test recommends a course levelHigh-risk area (assessing the appropriate level of education) from 2 Dec 2027A teacher confirms every placement; students can ask for a teacher assessment; vendor asked how it will meet provider duties
AI suggests marks and feedback on writing homeworkHigh-risk area (evaluating learning outcomes) from 2 Dec 2027Teacher reviews every mark; AI marks never used alone for certificates
AI note-taker summarises recorded online lessonsData protectionStudents told at enrolment and at the start of each recorded lesson; recordings deleted after 30 days
Vendor pitch: webcam "engagement and emotion" tracking for online classesProhibited: inferring emotions in educationDeclined

Two of the six uses fall in areas the Act treats as high-risk, which surprised the owner: the placement test and the homework marking both looked like ordinary software features. Because the high-risk date is December 2027, the school had time to put teacher sign-off in place and ask its vendors the right questions, rather than scrambling later.

What to keep on file

If anyone asks how you manage AI, whether a customer, a client's procurement team or a regulator, these documents answer most questions:

  • The AI inventory from the first step, with the date you last updated it.
  • Your AI usage policy and staff acknowledgements.
  • Training records: who attended what, and when.
  • Vendor data-processing terms for each tool.
  • Any data protection impact assessments.
  • Screenshots or copies of your AI disclosures (chat opening line, website statement, labels).
  • A risk or decisions log, especially for any use in a high-risk area.
  • An incident log, even if it's empty.

Alongside the legal questions, run each use through the AI ethics checklist too. Several things that are lawful are still worth not doing.

When to pay for legal advice

You can work through most of this list yourself. Get a solicitor or data-protection adviser involved when:

  • you plan to use AI in any high-risk area: hiring, managing staff, education decisions, credit or insurance;
  • children's, health or other sensitive data would go into an AI tool;
  • you want to monitor staff with any AI tool;
  • AI would make or heavily shape decisions with significant effects on people;
  • you're in a regulated profession and your regulator's guidance is unclear;
  • personal data may have leaked through an AI tool, since data-breach reporting deadlines can be short.

An hour of advice on one of these costs far less than getting it wrong, and a completed inventory and table like the ones above make that hour much more productive.

Compliance questions owners ask

Does the EU AI Act apply if my business isn't based in the EU?

It can. The Act reaches businesses outside the EU when the output of their AI system is used in the EU, for example when EU customers talk to your chatbot or receive decisions it helped make. If you have EU customers, assume the transparency rules apply to anything they interact with, and take advice before using AI in any high-risk area such as hiring or assessing learners.

Are small businesses exempt from the EU AI Act?

No. There's no general exemption by size. The Act does include measures meant to help small firms, and for SMEs each fine is capped at the lower of the percentage or fixed amount it sets, rather than the higher. But the prohibitions, transparency duties and high-risk rules apply according to what the AI does, not how big the business is.

How often should I re-check this list?

Every six months, and whenever you add an AI tool, start using AI with a new kind of personal data, or begin selling into a new market. Several AI Act dates fall in 2026 to 2028, and dates have already moved once, so check official sources at each review rather than relying on this list.

Further reads

Sources: EU AI Act text (Articles 4, 5, 26, 50, 99 and Annex III); the EU's FAQ on Article 50 transparency obligations; published summaries of the Digital Omnibus on AI and its revised dates; Google Search Central guidance on generative AI content. Checked September 2026. Not legal advice.

Want your AI uses mapped against the rules?

On a 1:1 call we'll list every place AI touches your business, sort out which rules each one triggers, and agree what needs changing now and what needs a legal adviser.

Book a 1:1 call with me