The EU AI Act is in force. And it applies to everyone who uses AI tools for business purposes, including simple applications like ChatGPT. Many solopreneurs and SMEs don’t yet know exactly which obligations apply to them. In most cases, the requirements are more manageable than expected, but they need to be actively addressed. Everyone is responsible for acquiring the knowledge they need.
Legal notice: This article is a personal summary of publicly available legislation, in particular Regulation (EU) 2024/1689. It represents the author’s personal interpretation, does not claim to be complete, and does not constitute legal advice. Laws continue to evolve. Current status: EUR-Lex. For binding legal assessments, please consult a qualified legal professional.
What Is AI Competency Under Art. 4 EU AI Act?
Art. 4 EU AI Act requires everyone who uses AI systems for business purposes to ensure sufficient AI competency is in place. This applies to yourself, your team, and any external parties using AI on your behalf. What counts as sufficient depends on the specific use case. A formal certificate is not required – documented training or courses can be a suitable building block. This obligation has applied since February 2, 2025.
What Is AI Compliance?
AI compliance means knowing, keeping track of, and systematically addressing the relevant legal and ethical requirements when using artificial intelligence for business purposes. The most important frameworks are the EU AI Act and the GDPR; depending on your industry, other regulations may also be relevant. AI compliance is not a one-off task but an ongoing process.
Provider or Deployer – Which Role Do You Have?
The EU AI Act distinguishes two main roles.
AI providers develop AI systems, for example OpenAI, Anthropic or Adobe. As a solopreneur or SME, you are almost certainly not one of these.
AI deployers use finished AI systems for their business activities. If you use ChatGPT for texts, Canva AI for graphics, or an AI tool for social media, you are typically a deployer.
As a deployer, you generally have fewer obligations than a provider – but you do have obligations.
The EU AI Act evaluates AI applications by risk level. What matters is not just the tool itself, but above all the specific use case.
- Prohibited: Covert manipulation, social scoring, deliberate exploitation of vulnerabilities.
- High risk: AI systems for personnel decisions, credit assessment, medicine, or biometric identification. Strict requirements apply here.
- Limited risk: Systems with transparency obligations, for example chatbots or AI-generated content.
- Minimal risk: Many everyday AI applications such as text assistance, AI image editing, or spam filters.
Important: The risk classification depends on the specific use. A tool like ChatGPT can be minimal risk in marketing but fall under stricter rules in an HR process.
Typical classifications as guidance:
- ChatGPT for blog posts: in many cases minimal risk
- AI-assisted applicant screening: can mean high risk
- AI chatbots in customer service: transparency obligation relevant
These classifications are not a legal assessment for your specific case.
Must AI Content Be Labelled?
The labelling requirement under Art. 50 EU AI Act does not apply across the board to all AI-generated content. Normal marketing texts such as social media posts or newsletters often do not need to be labelled as AI-generated. It can be different for synthetic media, meaning AI-generated images or videos in which real people are recognisably depicted. Chatbots must make clear that users are interacting with an AI. The exact classification depends on the individual case.
What you enter into an AI tool is processed on the provider’s servers, often outside the EU. If personal data is entered, a data processing agreement may be required under GDPR. Many providers offer such an agreement. Check whether it is active for your account. Confidential customer or business data should generally not be entered into AI tools unfiltered.
The EU AI Act and GDPR apply simultaneously – one does not replace the other.
What Solopreneurs and SMEs Should Specifically Address
These points are guidance. The specific implementation always depends on the individual case.
How do I demonstrate AI competency when I work alone?
In the course AI Competency & Compliance we go through exactly that step by step – practical, without legal jargon, tailored to solopreneurs and SMEs.
Key Deadlines at a Glance
| Date | What applies |
|---|
| February 2, 2025 | Prohibited AI practices (Art. 5) and AI competency obligation (Art. 4) |
| August 2, 2025 | GPAI obligations for providers of AI models |
| August 2, 2026 | Transparency obligations under Art. 50 |
| From 2027 | High-risk AI obligations, subject to the Digital Omnibus |
As of July 2026. Deadlines may still change due to the Digital Omnibus. Always check the current status on EUR-Lex or your national supervisory authority.
Conclusion
The EU AI Act is not a bureaucratic monster for solopreneurs and SMEs. The key basics are manageable: don’t use prohibited practices, label chatbots, don’t enter confidential data into AI tools unfiltered, and document your AI competency. Anyone who knows this and addresses it in a structured way is well positioned.
Implementation is up to you. This article provides orientation but does not replace individual legal advice.
Sources
This article was created with AI assistance and has been editorially reviewed. It does not constitute legal advice.
This article was created with AI assistance and editorially revised.