Picture two 20-person firms. One is a marketing agency in Manchester that drafts blog posts with ChatGPT. The other is a recruiter in Dublin that ranks CVs with an AI screening tool. The same European law covers both of them, and almost nothing it asks of one does it ask of the other.
For most small businesses, the EU AI Act asks for less than the headlines suggest, and the Digital Omnibus that became law this summer pushed its hardest rules back to 2 December 2027. If you use AI in the EU, or the output of your AI is used there, you must support your staff's AI literacy, tell people when they are talking to a bot or looking at a deepfake, and stay clear of a short list of banned practices. The heavy rules apply only where AI helps decide things about people: who gets hired, how staff are judged, who gets credit.
This is a plain-English reading for owners, not legal advice. If you build AI products, sell them under your own name or use AI to make decisions about people at scale, talk to a lawyer as well.
What changed in the EU AI Act this summer?
The EU delayed the high-risk rules and softened the AI literacy duty, but it did not switch off the parts that already touch everyday business. The changes arrived in Regulation (EU) 2026/1744, the "Digital Omnibus on AI", signed on 8 July 2026 and in force since 27 July 2026.
Three changes matter to an owner.
First, the timetable. According to the Council of the EU's announcement of 29 June 2026, obligations for stand-alone high-risk AI systems now apply from 2 December 2027 instead of 2 August 2026, and for high-risk AI built into regulated products from 2 August 2028.
Second, the AI literacy duty. The original Article 4 told businesses to ensure, to their best extent, a sufficient level of AI literacy among their staff. The amended text says providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". The duty is now to support learning, not to guarantee a level of it.
Third, a new ban and a firm date. The European Parliament's release of 16 June 2026 records a ban on AI systems that create sexual images of identifiable people without their consent, and sets 2 December 2026 as the date by which AI-generated content from systems already on the market must be labeled in a machine-readable way.
What did not change: the banned practices that have applied since February 2025, and the transparency duties in Article 50 that took effect on 2 August 2026. Most of the relief aimed at small firms, such as simpler technical paperwork now extended to small mid-caps, helps businesses that build AI systems, not the far larger number that simply use them.
Does the EU AI Act apply to a UK or US small business?
It applies to you if you use AI inside the EU, or if the output of an AI system you use is used in the EU. The Act calls a business that uses AI under its own authority a "deployer", which is what almost every small business is, and Article 2 reaches deployers outside the EU when their AI's output is used in the Union.
In practice, a UK accountancy practice with clients in Dublin, a US online shop selling to customers in France, or a design studio whose chatbot answers enquiries from Germany should assume the Act has something to say to them. A plumber in Leeds with no EU customers can treat it as a preview of where rules elsewhere may go.
At home, the picture is different. The UK has no equivalent AI law; a UK firm's duties around AI sit mainly in data protection law, which the ICO enforces. In the US there is no federal AI act, and the rules come from existing consumer protection law and a growing patchwork of state laws. That is a reason to keep your house in order once, in a way that would satisfy the strictest rulebook your customers live under.
The Four Shelves: how to sort your AI uses
The quickest way to see what the Act asks of you is to sort your AI uses by what the AI touches, not by which tool you bought.
The Four Shelves is how I suggest a small business works out what the EU AI Act asks of it: sort the jobs, not the tools. List every job where AI is used and put each on one of four shelves by what the AI touches. Never: the few practices the Act bans outright, such as reading your staff's emotions. People: AI that helps decide who gets hired, how staff are judged or who gets credit, which carries the heavy high-risk duties. Public: AI that talks to customers or makes realistic images, audio or video, which must be disclosed. Everything else: the ordinary drafting, summarizing and analysis most businesses do, where the duty is to support your staff's AI literacy.
The shelves stack from the bottom. A job on the People shelf also carries the literacy duty; a job on the Public shelf also needs people who know what the tool can get wrong. Here is what sits on each.
The Never shelf
These are the practices Article 5 bans outright, and they have applied since 2 February 2025. Most are far from small-business life: social scoring, scraping faces to build recognition databases, manipulating people through techniques they cannot perceive. One is closer than owners think. Article 5(1)(f) bans using AI to infer the emotions of people in the workplace, except for medical or safety reasons.
That matters because emotion and sentiment features creep into ordinary software. A call-handling tool that scores a customer's tone is one thing. The same tool scoring your own staff's mood on calls, and feeding it into how they are managed, is on this shelf. If a product you use offers that feature, switch it off.
The People shelf
This is where the heavy rules live, and where the December 2027 deadline matters. Annex III lists AI used "to analyse and filter job applications, and to evaluate candidates", AI used to make decisions about promotion or termination or "to monitor and evaluate the performance and behaviour of persons" at work, and AI used to evaluate the creditworthiness of individuals.
The Manchester agency from the opening never touches this shelf. The Dublin recruiter lives on it. For businesses that use such tools, Article 26 asks three practical things: use the system as its maker's instructions say, give oversight to a named person with the competence, training and authority to do it, and, as an employer, tell workers and their representatives before the system is used on them.
None of that needs a data team. It needs a person who would notice when the tool gets it wrong and the authority to overrule it. This is where the Loop Test earns its keep. "Oversight that survives all three is a safeguard. Oversight that fails any of them is a signature." Ask of your named person: would they notice a wrong result without being told to look for it?
The Public shelf
These duties are live now. Article 50, which has applied since 2 August 2026, says AI systems that interact directly with people must be designed so that people know they are dealing with AI. It also says a business that publishes a deepfake, meaning AI-made or altered image, audio or video that would falsely appear real, must disclose that it is artificial.
For a small business that comes down to two checks. If a chatbot answers your customers, make sure its first message says it is an AI. The duty to build that in sits with the tool's maker, but your customers will hold you to it, and the Promise Rule already keeps the bot's answers in line with what the business has written down. If your marketing uses realistic AI-generated people, voices or scenes, label them. A stylized illustration nobody would mistake for a photograph is a different matter from a lifelike "customer" in an advert.
Text is lighter. AI-written text published to inform the public on matters of public interest must be disclosed, unless a person has reviewed it and someone holds editorial responsibility. A business that has a person check every claim against a receipt is already doing what that exception describes.
The Everything Else shelf
This is where most of a small business's AI lives: drafting emails and quotes, summarizing meetings, tidying spreadsheets, first drafts of policies and proposals. The Act asks one thing here, and it asks it of every shelf: support your staff's AI literacy.
What does the AI literacy duty mean now?
It means you must take reasonable steps to help the people who use AI for your business understand it, judged against their role and experience. The amended Article 4 drops the old wording about ensuring "a sufficient level" of literacy, and adds that EU countries and the Commission should help businesses, smaller ones in particular, meet the duty.
Softer is not the same as gone. A receptionist using a chatbot console and a manager using an AI screening tool need different things. The receptionist needs to know what the bot can and cannot promise. The manager needs to know how the tool ranks people, where it is likely to be wrong and when to overrule it. Both need to know what must never go into the tool.
When I published the One-Page Five in September, the duty still used the stronger wording. The practical advice has not changed: short, role-specific training, practiced on real work within the week, with a dated record of who learned what. That record is your evidence that you took measures.
What I Tell Business Owners
When the EU AI Act comes up in my sessions with business teams, it usually arrives as a worried question near the end, from the owner or the operations lead: are we compliant? The question is almost always too big to answer in that form, and the worry usually sits on the wrong shelf.
Owners worry most about the ordinary drafting their team does every day, which sits on the Everything Else shelf and asks for training. They worry least about the feature they switched on without thinking: the sentiment score on staff calls, the CV filter that arrived in a routine update to a recruitment platform. Those are the jobs worth an hour of attention this month.
I have advised governments and system leaders on AI, including the UK Department for Education, KHDA in Dubai and the Ministry of Education in Kazakhstan, and I give an owner the same advice about this law that I would give about any rule: write down what you do, and then do what you wrote down. A one-page list of your AI jobs, each on its shelf with a named owner, will answer most questions a client, an insurer or a regulator is likely to ask.
The delay to 2027 is a gift only if you use it. A business that waits until November 2027 to ask its HR software vendor how the screening tool will meet the high-risk rules is asking at the same moment as every other customer.
What should you do this week?
You can do all of this in a week without a lawyer, a consultant or a new tool.
- List the jobs. In a 30-minute team meeting, ask "What has AI saved you this month?" and write down every job people name, including features switched on inside software you already pay for. If staff are using tools nobody approved, bring those into the daylight first.
- Shelve each job. Never, People, Public or Everything Else. Most will land on the last shelf. Mark anything you are unsure of as People until you know better.
- Empty the Never shelf. Check any tool that analyzes calls, video or messages for an emotion or sentiment feature aimed at staff, and switch it off.
- Fix the Public shelf. Make sure every chatbot introduces itself as AI, and agree a simple label for realistic AI-generated images, audio and video.
- Write to your People-shelf vendors. Ask each in writing how its tool will meet the EU high-risk rules by 2 December 2027, and who in your business will oversee it. Tell staff and applicants where AI is part of decisions about them.
- Record the training. Give each role a short session on its own AI jobs and keep a dated note of who attended. That is your Article 4 evidence.
- Give the list an owner. Put the shelved list beside your AI policy and hand both to your AI steward, who keeps it current.
Where to go next
If your shelf list shows People or Public jobs and you want a clear set of rules and owners around them, that is the strategy and governance work I do with leadership teams at The AI Educator for business. If the gap is the literacy duty, my AI training for business teams is built to give each role what it needs on its own work. And if you want to know where you stand before you start, the free Business AI Readiness Scorecard takes five minutes.
Sources and further reading
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), European Parliament and Council of the EU, 8 July 2026, published in the Official Journal 24 July 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), European Parliament and Council of the EU, 13 June 2024
- Artificial Intelligence: Council gives final green light to simplify and streamline rules, Council of the EU, 29 June 2026
- AI Act: EP approves simplification measures and "nudifier" app ban, European Parliament, 16 June 2026
Dan Fitzpatrick is The AI Educator: a Forbes contributor, keynote speaker and bestselling author who helps business teams use AI well, safely and every day. More about Dan.



