Artificial Intelligence
The EU AI Act: what small-business owners need to know
If you use ChatGPT to write a LinkedIn post, do you have to label it? A practical look at the EU AI Act for small-business owners, covering transparency, high-risk uses and what actually applies now.
Barry James
Founder, Blink Blue
· 5 min read
At a recent She Leads event, a question came up: if you use ChatGPT to write a LinkedIn post, do you have to label it?
It’s an understandable question. Small-business owners are using AI to write, create images and save time. They want to know what their responsibilities are.
I also attended a CeADAR webinar on Article 50, the part of the EU AI Act dealing with transparency. I found it a really useful starting point for understanding when businesses need to disclose AI use. The recording is available to everyone on YouTube.
This article takes a wider look at the Act, focusing on the parts small-business owners need to understand.
Start with how you use AI
At the Digitize Drogheda series of talk in August, I described three levels of AI use in business:
- Consumer AI: tools you use directly, such as ChatGPT, Claude or Canva’s AI features, to help with individual tasks.
- Prosumer AI: using available tools to automate parts of your workload—for example, adding AI capabilities to a workflow in Power Automate.
- Professional AI: employing a specialist such as Blink Blue to design and implement more extensive business automation.
These are my practical descriptions, not legal categories. And automation doesn’t always involve AI.
For the Act, the central question is what the AI does and how it could affect people. A familiar tool used to assess job applicants raises different questions from the same tool helping you phrase an email.
What does the Act cover?
The Act puts different requirements on different uses of AI. Some practices are prohibited. Certain uses need much closer oversight. Others carry transparency obligations, while many everyday applications fall into the minimal-risk category.
It also distinguishes between providers, who develop or supply AI systems under their own name, and deployers, who use them professionally. Most readers using existing tools will be deployers.
There are separate rules for providers of general-purpose AI models, including copyright and documentation requirements. Using ChatGPT does not make you responsible for developing its underlying model. Read the Commission’s overview of the Act.
Some uses are prohibited; others need extra care
Prohibited practices include certain harmful forms of manipulation and exploitation, and using AI to infer people’s emotions in workplaces, except for specified medical or safety purposes.
“High-risk” uses include certain systems for screening job applications, assessing creditworthiness or making decisions about access to education. These can affect someone’s opportunities and rights.
The rules for these systems include requirements around documentation, monitoring and human oversight, with responsibilities divided between suppliers and users.
For a small business, the practical lesson is to check before introducing AI into consequential decisions about people. A tool being available to buy doesn’t establish that your intended use is appropriate. Explore the official explanation of prohibited and high-risk uses.
People need to understand the tools they use
The Act’s AI literacy provisions require businesses to support the development of AI knowledge among people using systems on their behalf. The approach should reflect their experience and the work involved; there is no universal certificate everyone must obtain. Read the Commission’s AI literacy guidance.
My advice is to treat AI as a junior partner. Give it direction, question its suggestions and check its work.
For writing, that means checking facts and making sure the result represents what you actually believe. Fluent wording is no guarantee of accuracy.
When do you need to disclose AI use?
Article 50 deals with transparency. Three situations are particularly relevant to everyday business.
Customer conversations
People generally need to know when they are interacting directly with AI, unless that is already obvious. The requirement to design this disclosure into the system sits with its provider.
If you introduce a customer chatbot, check that it makes its identity clear from the beginning. See the Commission’s transparency guidance.
Images, video and audio
The disclosure rules cover “deepfakes”: AI-generated or altered images, video or audio that could falsely appear authentic. This is broader than a fake video of a celebrity. Read the official explanation of deepfakes.
In the CeADAR webinar, the presenters discussed an advertised property photograph altered with AI. Planting, the building’s appearance and the steps looked improved.
That illustrates the concern: someone viewing it could believe the property actually looks that way. An attractive image can change the impression a prospective customer forms.
LinkedIn posts and other writing
There is no blanket requirement to label every LinkedIn post written with ChatGPT.
The text disclosure rule concerns AI-generated or manipulated writing published to inform the public on matters of public interest. Being publicly visible does not, by itself, settle that question.
There is an exception where the content undergoes human review or editorial control and a person or organisation takes editorial responsibility.
That review must address the substance. Checking an AI draft’s spelling alone is not enough. Using AI to polish your own carefully reviewed writing is a different situation from publishing unchecked generated claims. Read the Commission’s explanation of text and editorial responsibility.
What applies now?
The Act has a phased timetable:
- February 2025: the original prohibited-practice rules and AI literacy obligations began applying.
- August 2026: Article 50’s transparency obligations began applying.
- December 2027: the rules for high-risk uses listed in Annex III, including certain employment systems, apply.
- August 2028: the rules for high-risk AI embedded in regulated products apply.
The high-risk dates were extended through the July 2026 amendments. Enforcement can include fines, so check the current position for your particular use. See the Commission’s implementation update.
A practical starting point
My recommendation is to begin with four questions:
- Where are we using AI in the business?
- Could it affect someone’s rights, opportunities or understanding of what we offer?
- Who checks the output and takes responsibility?
- Do customers or readers need a clear disclosure?
You can make useful progress by answering those questions before adding more tools or automation.
My underlying position is simple: if you publish something under your name or your company’s name, you must stand behind it. AI can help you do the work. You cannot hand your responsibility to ChatGPT.