What the AI Act requires of your business
If your business uses a third-party AI assistant for ordinary tasks, it is a deployer. You do not need to obtain CE marking, register in European databases or carry out a conformity assessment. There is no general requirement for an independent audit either. Article 4 on AI literacy applies to every business, including small companies. The starting point is knowing which tools you use and what data they handle.
What AI compliance covers
AI compliance starts with identifying the duties that apply to each system your company uses or provides. Those duties depend on your role as a provider or deployer and on how the system is used. We use that assessment to define the work required and the evidence to keep.
The problems to solve
Sales pitches lead with fines
Audits, certifications, courses presented as mandatory, million-euro fines in the opening line. When everything sounds essential, it is hard to tell what your business actually needs.
Your company's role is unclear
Providers and deployers have different duties. Your role needs to be checked for each system: you can be the deployer of an assistant and, at the same time, the provider of a chatbot on your website.
There is no record of the tools in use
Teams may have their own subscriptions, including personal accounts, and customer data may end up in tools the company knows nothing about. Without an inventory, there is no starting point for checking which duties apply.
What we do
We establish your role for each system
We check whether your company is the provider or deployer of each system. If you offer a service under your own name or change its intended purpose, we review your role and the duties that follow.
We record which tools are in use
We record which tools are used, which teams use them, what they do and what data they handle. That includes tools people use without authorisation.
We organise the evidence
We bring together written usage rules, the list of approved tools, records of staff guidance and notices where needed. The documentation must reflect what you actually do.
We review how personal data is used
AI Act compliance does not remove your GDPR obligations. We review the legal basis, privacy notices, where data goes and whether a data protection impact assessment is needed.
What we do not do
We do not issue certifications
We are neither a certification body nor a notified body, and we do not sell compliance badges. If certification is required, we tell you and point you to a body that can issue it.
We do not sell audits you do not need
Ordinary use of a third-party assistant carries no general requirement for an independent audit. If that applies to you, we say so and keep the scope to the work you need.
We do not use fines to sell our services
We do not use maximum fines to persuade you to buy a service. You need to know which duties apply to your business and what meeting them involves.
The work your company remains responsible for
Tools change, people move into different roles and new uses emerge. Your company must keep track of what is in use and under what conditions. A new use can change your role from deployer to provider without anyone noticing.
Keeping the tool inventory up to date
Add each new subscription and remove tools you no longer use. The inventory must reflect what people actually use: your rules and checks depend on it.
Making sure new users know how to use the tools
Anyone starting to use AI on your company's behalf needs to know which tools they may use, what data they must not enter and why answers always need checking. This guidance is part of the AI literacy measures required by Article 4, the duty that applies to every business.
Reviewing your role and duties when uses change
When an internal assistant becomes a service for customers, your role and duties need to be reviewed. Make that check when you decide to change its use, before the service goes live.
The questions to start with
- How many AI systems are in use in your company, including those accessed through personal subscriptions?
- For each system, is your company the provider or the deployer?
- Which of these systems process personal data about customers, staff or suppliers?
- Do the people using them know what data they must not enter and why answers need checking?
- If asked, could you show what you did and when?
Facts and sources
Article 4 of the AI Act applies to providers and deployers alike: both must take measures to ensure that their staff and anyone operating AI on their behalf have a sufficient level of AI literacy. It has applied since 2 February 2025, together with the general provisions and the prohibited practices.
The European Commission clarifies that the AI literacy duty does not require a specific level of competence to be guaranteed for each individual. There is no mandatory course, minimum number of hours or officer to appoint. What matters is that measures are proportionate to the risk and to how the systems are used.
The rules on high-risk systems in Annex III — biometrics, critical infrastructure, education, employment, essential services, justice — apply from 2 December 2027. Until then, these duties do not apply to those systems, despite being presented as already in force in many commercial offers.
For high-risk systems covered by points 2 to 8 of Annex III, the conformity assessment is based on internal control and does not involve a notified body (Article 43). This is the provider's duty, not the deployer's.
In Italy, Law No. 132 of 23 September 2025 has been in force since 10 October 2025, alongside the AI Act. The law also covers professional practices: practitioners must inform clients about the AI systems they use in clear, simple and comprehensive language (Article 13).
Questions we often hear
- Does a chatbot bought from a provider need certification?
- If you use it as supplied, certification is normally not your responsibility: the technical duties belong to the provider. That can change if you offer it to customers under your own name or change its intended purpose.
- Do staff have to take an AI training course?
- No. Article 4 requires AI literacy measures proportionate to the risk and how the tools are used, without prescribing courses or minimum hours. People using the tools need to understand their limitations, what data they must not enter and why answers need checking.
- When can a deployer become a provider?
- Your role can change if you offer a system under your own name or brand, or substantially change its intended purpose. Check this before launching a new service.
- Do some sectors have additional duties?
- There can be. Banking, insurance, healthcare and the public sector have their own rules, while Italian law 132/2025 adds provisions on employment and the professions. We check which apply to your business.
- When is a data protection impact assessment needed?
- It depends on the data being processed and how the system is used, not on whether it is labelled AI. The need is assessed case by case. Where an assessment is required, it must be completed before the system goes live.
- What is the risk of leaving this unchecked?
- The practical concern for a small business is not knowing which tools handle customer data. You may only find out when something goes wrong or a client asks for that information during a tender.
- Does a small business need an AI Act audit?
- There is no general requirement for an independent audit when you use a third-party assistant for ordinary tasks. We start with your tool inventory and your role for each system, then establish usage rules and the evidence to keep. If a more complex case emerges, we discuss it with you before proceeding.
Tell us which AI tools you already use
Start with a list of the tools in use and who uses them, even if it is incomplete. We review it with you to distinguish your company's duties from your providers' and identify the work required.