Nora
CEO & Certified Accountant

EU’s new AI rules are now in force – what businesses need to know

Artificial intelligence has quickly become a common business tool. ChatGPT, Claude, Grok and other AI platforms are used to write and summarise texts, AI features are built into accounting systems and customer service, and businesses use AI for everything from marketing to recruitment.

Since 2 August 2026, major parts of the EU AI Act apply, including the new transparency rules. The Regulation applies throughout the EU and covers both businesses that develop AI systems and businesses that use them in their operations. In certain situations, companies outside the EU may also be covered when the output of an AI system is used within the Union.

But what do the rules actually mean for an ordinary business?

Using ChatGPT does not automatically mean that new labelling requirements apply. It is important to distinguish between businesses that provide or develop an AI system and businesses that simply use an existing AI tool.

A business that, for example, uses ChatGPT or Microsoft Copilot to improve an email, summarise a document, translate text or prepare a first draft does not normally need to label such material as having been created using AI.

However, EU rules impose specific requirements in certain situations where AI interacts directly with people or is used to create or manipulate content.

Customers should be able to understand when they are communicating with AI

One of the clearest examples is AI-based chatbots and virtual assistants.

AI systems that communicate directly with people, such as chatbots and AI assistants, should generally be designed so that users are informed that they are interacting with AI. Responsibility for the design itself primarily lies with the provider of the AI system.

This may, for example, be relevant for businesses that use AI-driven customer service on their website or a virtual AI assistant for customer communication.

Do AI-generated texts need to be labelled?

Not always. The EU AI Act includes specific transparency rules for AI-generated or AI-manipulated texts that are published for the purpose of informing the public on matters of public interest. In such cases, there may be a requirement to disclose that the text has been artificially generated or manipulated using AI.

There is, however, an important exception: this obligation does not apply where the AI-generated content has undergone human review or editorial control and a natural or legal person assumes editorial responsibility for its publication.

This means, for example, that a business can use AI as a tool to prepare a first draft of an article and then review, correct and take responsibility for the final text.

Using AI as a work tool is therefore not the same as automatically publishing AI-generated content without human oversight.

Specific rules for deepfakes

The rules are stricter when AI is used to create or manipulate images, audio or video in a way that may make the content appear real. As a general rule, anyone using an AI system to create so-called deepfakes must disclose that the content has been artificially generated or manipulated.

This does not mean that every AI-generated illustration or marketing image is automatically subject to the same visible labelling requirements. The rules are particularly aimed at content that may lead the recipient to believe that the people, objects, places or events depicted are in fact real.

Businesses must have sufficient knowledge of AI

Another part of the EU AI Act has already applied since 2 February 2025.

Businesses that use AI systems must take appropriate measures to promote AI literacy among the people who work with those systems. What measures are appropriate depends, among other things, on the employees’ knowledge, experience and how AI is used within the business. However, there is no requirement for every employee to achieve a specific predetermined level of knowledge.

The level of knowledge required depends, among other things, on how AI is used, the employees’ experience and the risks involved. For a smaller business, this does not necessarily mean advanced training programmes. However, it is wise to ensure that employees using generative AI understand basic issues relating to confidentiality, personal data, inaccurate AI-generated responses and the need for human oversight.

Stricter rules apply to high-risk AI

The EU AI Act classifies the use of AI according to risk level. Significantly more extensive requirements apply to so-called high-risk AI systems.

This may include certain uses of AI in recruitment and personnel management, education, credit assessment and other areas where an automated decision may have a significant impact on an individual.

The timeline for these rules has recently changed. Following an amendment to the EU AI Act in summer 2026, some rules for high-risk AI will start to apply from 2 December 2027 and 2 August 2028 respectively, depending on the type of system involved.

Don’t forget GDPR when using AI

The EU AI Act does not replace data protection rules. If personal data is processed through an AI system, GDPR applies in parallel. Businesses should therefore be particularly careful when entering customer data, employee data, sensitive personal data or other confidential information into external AI services.

What should businesses do now?

For most small and medium-sized businesses, the new rules are primarily about gaining a clear understanding of how AI is actually being used within the organisation.

It is therefore advisable to:

  • map which AI tools are used within the business,
  • review whether customers or other individuals communicate directly with AI systems,
  • ensure human review of important AI-generated content,
  • be cautious about which personal data, customer information and business secrets are entered into external AI services,
  • and make sure that employees who use AI have sufficient knowledge to do so responsibly.

The EU AI Act does not mean that businesses must stop using AI or label all content created with the help of AI. However, transparency, oversight and knowledge of how the technology is used are becoming increasingly important.

For businesses that already use AI in their day-to-day operations, this is therefore a good opportunity to review internal procedures and ensure that AI is being used in a considered and responsible way.

The rules are not merely recommendations. Breaches of, among other things, the transparency requirements may result in administrative penalties, although factors such as proportionality and the size of the business must also be taken into account.

 

The information above is general and should not be considered individual legal advice.

Global Accounting & Auditing SL
Accounting • Tax • Legal • Real Estate Transactions
Marbella & Stockholm
Svenska • English • Español • العربية

The information above is general and should not be regarded as individual legal or tax advice.

+34 952 82 82 52

[email protected]

DATA: