A pattern shows up again and again with small companies: they use ChatGPT for customer emails and
marketing copy, and nobody thinks twice about it — they weren’t building AI, just using a tool like
everyone else. Then they read Article 4 of the EU AI Act and realize: using AI tools at work is
enough to make you an “operator” under the law, with obligations of your own.
This post is the practical version of that realization — what the law actually requires, what it
means for a small business specifically, and a checklist to work through before August 2, 2026.
## What the law actually says
Article 4 of the EU AI Act requires “providers and deployers of AI systems” to ensure their staff
have a sufficient level of AI literacy — enough to understand what the tools do, their capabilities,
risks, and how they affect the people the business serves. This obligation applies regardless of
company size. There’s no small-business exemption in the text.
Article 50 adds a related duty: if your business uses a chatbot or other AI system that interacts
with people, you generally need to disclose that they’re interacting with AI, not a human.
Both obligations become enforceable **August 2, 2026**.
## What this means for your company
If any of the following is true, the law is already talking to you:
– Your team uses ChatGPT, Copilot, Claude, or a similar tool for writing, research, or customer replies
– You use an AI tool for data analysis, reporting, or internal documents
– A chatbot on your website or in your customer service answers questions automatically
– Nobody has ever documented which AI tools are in use across the business
A company that uses AI for marketing copy and customer service — without ever building anything
themselves — is still an operator. The law doesn’t care whether you built the model. It cares
whether your business uses it and whether your people understand what they’re using.
## What to do now — the checklist
1. **List every AI tool in active use.** ChatGPT, Copilot, Claude, any embedded AI feature in
existing software. Most companies have never done this — it’s usually the first gap that shows up.
2. **Note who uses each tool and for what.** Marketing copy, customer replies, internal reports,
code — a one-line description per tool is enough to start.
3. **Check for chatbot/AI disclosure.** If customers interact with an AI system directly (chat
widget, automated replies), confirm they’re told it’s AI — this is the Article 50 obligation.
4. **Give your team a basic literacy briefing.** They don’t need a certification — they need to
understand what the tool can and can’t do, and where the risks are (e.g. don’t paste customer
data into a public tool without checking the provider’s terms).
5. **Write it down.** A one-page policy — which tools, who’s responsible, what the literacy
briefing covered — is what you’d show if anyone ever asked you to prove compliance.
None of this requires a legal team. It requires an afternoon and a template to fill in.
## The real cost of waiting
Two outcomes wait for companies that don’t do this before August 2: a fine, or a rushed, expensive
fix once someone notices the gap. Neither is necessary — the actual work here is closer to an
afternoon of documentation than a legal project.
If you want a structured starting point rather than building the inventory and policy from a blank
page, the [EU AI Act Practical Handbook + Toolkit](#) has the inventory sheet, literacy checklist,
and policy template ready to fill in. There’s also a free quick-check if you just want to confirm
whether Article 4 applies to your business before doing anything else.
Done. Both links wired into POST09:
- Gumroad (Handbook, €35, pzqly):
https://frelih.gumroad.com/l/pzqly— mid-post CTA - Linktree (free check):
https://linktr.ee/frelih— both mid-post and end CTA

Leave a comment