EU AI Act checklist for small businesses: a matte clipboard with seven rounded checkboxes, several marked with a teal check, on a solid navy background
Guide6 min read

The EU AI Act Checklist for US Businesses: 7 Duties, in Plain English

TL;DR

The EU AI Act boils down to seven concrete duties: disclose that it's an AI, offer a path to a person, and handle data properly. It's not just big-tech paperwork. If you take calls from or handle data of EU residents, it applies to you—and since August 2, 2026, much of the regulation is in general force. Even if you don't serve the EU, these duties are fast becoming the baseline.

The EU AI Act sounds like regulation built for OpenAI, Google, and a handful of giants with legal departments the size of your town. But if you have a voice bot answering the phone or a chatbot handling WhatsApp—and any of your callers or contacts are in the EU—the rules reach you too. The AI Act's duties for a small business come down to seven, all concrete and far more manageable than they look, and most boil down to three ideas: disclose that it's an AI, always leave a door open to a person, and handle data properly. Here's the full checklist, in a list you can run through in ten minutes and one worth closing out now. And even if you serve only US customers today, these are fast becoming the baseline your regulators and clients expect.

You don't have to "build" artificial intelligence for the rules to touch you. The EU's AI Act separates whoever creates the system (the provider) from whoever uses it with customers (the deployer, which in plain English is you) (Regulation (EU) 2024/1689 —the AI Act—, art. 3, points 3 and 4). And when you deploy an AI that talks to people, you inherit some obligations, mainly around transparency (AI Act, art. 50) and AI literacy for your staff (art. 4). For a US business the practical trigger is simple: if you take calls from or handle data of people in the EU, these apply to you directly; if you don't, they're still the strictest baseline out there—and the one Totem is built to. Either way, the question isn't whether the rules could reach you, but what you need to have ready; with the right tool, that part shrinks dramatically.

Key takeaways

  • The AI Act can reach you even if you only use a bought-in AI: you're the deployer.
  • A customer-service agent almost always falls under 'limited risk': its headline duty is transparency.
  • The 7 obligations boil down to disclosing it's an AI, offering a person, and handling data properly.
  • Each party answers for its own: as the deployer you can be penalized too, not just the provider.
  • A tool with compliance built in checks 6 of the 7 boxes without you lifting a finger.

Why the EU AI Act can reach your US business even if you don't "build" AI

The regulation classifies AI systems by level of risk, and that's where your obligations come from. The vast majority of a small business's uses (answering, informing, booking) fall under limited risk, a category whose central duty is simple: the person needs to know they're interacting with an AI (Regulation (EU) 2024/1689 —the AI Act—, art. 50.1). High risk exists, yes, but it's reserved for Annex III uses like screening résumés, deciding on credit, or managing critical infrastructure (AI Act, art. 6.2 and Annex III). An agent that picks up your clinic's phone and offers a Thursday slot at five isn't there.

That changes the tone of the whole thing. You don't need a six-month conformity audit; you need clear disclosures, a clean handoff to a person, and data handling in line with GDPR. One nuance is worth clearing up: GDPR does not require that data physically stay in the EU; it permits international transfers as long as adequate safeguards are in place (Regulation (EU) 2016/679 —GDPR—, ch. V). Keeping data in the EU is therefore a best practice that simplifies compliance, not a literal requirement of the regulation. (If you operate purely in the US, the analogous baseline is a law like California's CCPA.) If you want the full GDPR-plus-AI-Act picture, we lay it out in the guide on whether it's legal to use an AI voice agent or chatbot for customer service, and we compare point by point what each rule asks of you in EU AI Act vs GDPR: what each one requires.

General application of the EU AI Act for small businesses: a matte wall calendar with August 2, 2026 circled with a teal ring on a solid navy background
August 2, 2026: the reference point from which the applicable obligations are no longer a countdown.

The 7 EU AI Act obligations, one by one

Here's the heart of it: the full checklist of obligations a small business takes on when it deploys a voice agent or a chatbot with customers. For each one we tell you what, in practice, is enough to comply.

  1. Disclose that it's an AI. The customer should know, from the start, that they're talking to an automated system. A natural opening line is enough; the hard part is saying it without scaring anyone off, and we cover exactly that in how to disclose AI use without losing customers.
  2. Offer a path to a person. More than a universal legal obligation, this is a trust best practice. It's worth being precise about GDPR Article 22: it is not a "right to talk to a human" in any customer-service setting. It only kicks in for decisions made solely by automated means that produce legal effects or similarly significant effects on someone (GDPR art. 22.1, mirrored by comparable laws elsewhere); a bot that books, answers questions, or routes normally doesn't reach that threshold. Even so, always leaving an exit toward a person is strongly recommended.
  3. Handle data in line with GDPR. Legal basis, informing the people whose data you hold, and minimization (Regulation (EU) 2016/679 —GDPR—, arts. 6 and 13). GDPR does not require that data stay in the EU: it permits transfers with adequate safeguards (ch. V), but keeping data in the EU simplifies compliance. (For US-only operations, a law like the CCPA is the analogous baseline.)
  4. Disclose recording, if you record calls. The core duty is to inform people that the call is recorded and why. In the US, whether you also need consent depends on your state—some are one-party consent, others two-party—and the FCC's TCPA rules govern automated calls and texts; under GDPR, consent isn't always required, because the legal basis can be a contract or legitimate interest depending on the case (GDPR art. 6). Either way, add a clear retention policy.
  5. Don't use the AI for prohibited purposes. No manipulation, no social scoring, none of the other uses the regulation bans (AI Act, art. 5; in force since February 2, 2025). For customer service, this is a formality.
  6. Keep human oversight. There should be a person who can review, correct, and take control. The hybrid model (the AI handles it, a human steps in with one click) is exactly this.
  7. Leave a trail of interactions. A record of what was said and what was decided, in case anyone asks. Transparency inward, not just toward the customer.

Myth

The AI Act is paperwork for multinationals; my hair salon doesn't have to do anything.

Reality

If you use a bot with customers, you're the deployer and you inherit transparency obligations.

Myth

My chatbot is high-risk, I need a massive audit.

Reality

Answering, informing, and booking is 'limited risk': the central duty is disclosing that it's an AI.

Myth

If the AI gets it wrong, it's always the software provider's fault.

Reality

Each party answers for its own obligations: as the deployer you can be penalized too, so choose the tool well.

Who does what: you vs. your provider

Here's the trap that costs the most. A lot of people assume that when you buy the software, the whole legal headache leaves with the vendor. It doesn't, but the nuance matters: each party answers for its own obligations, and there's no automatic joint liability. Under the AI Act, both the provider and the deployer are "operators" who can be penalized, each for their own part (AI Act, art. 99 read with art. 3, point 8). And under GDPR, the processor—not only the controller—can be penalized too. The provider answers for the system being well built; you answer for how you use it with your customers (live disclosures, oversight, staff training). That's why the choice of tool matters so much: one that brings the AI disclosure, the processing notice, and EU data hosting out of the box takes almost all of the work off your plate. One that leaves you to improvise the disclosures does not. We spell it out, no hedging, in your AI provider isn't the one on the hook: you pay the fine.

The provider answers for the software. For how you use it with your customers, you answer. That's why the tool you choose isn't a technical detail: it's part of your compliance.

ObligationWhat it means in practiceWho covers it
Disclose that it's an AIClear, natural opening lineProvider (comes built in)
Path to a personWarm handoff with contextProvider
Data in line with GDPRLegal basis and notice; data in the EU (best practice)Provider + you (legal basis)
Recording noticeDisclose the recording and its retentionProvider
Human oversightA person who can take controlProvider (hybrid model)
Trail of interactionsRecord of calls and chatsProvider (analytics)
No prohibited usesLegitimate customer-service usesYou (it's your business)

As you can see, six of the seven can be covered by your provider if it's well built. The seventh (not using the AI for something prohibited) is on you, but for serving customers, booking, and following up it's practically automatic.

EU AI Act deployer: a matte key with a teal tag handed from one hand to another on a solid navy background, a symbol of shared responsibility between provider and business
The provider answers for the software; for how you use it, you answer: the tool is part of your compliance.

How a well-built tool covers 6 of the 7 obligations for you

This is exactly what we designed into TotemAI: AI Act compliance that comes built in instead of being a to-do list for you. The AI introduces itself as an AI when it picks up, offers to pass you to a person when needed, and that handoff is warm, with the full context of the conversation, without the customer repeating anything. If it's a call, the team joins that same call; if it's chat, they join the same thread. Data stays in the EU, recordings carry their notice and retention, and every call and chat is logged with sentiment analytics, so the trail exists without you building it. We detail it in how Totem handles the AI disclosure, consent, EU residency, and handoff to a person.

~1 s

to pick up the phone, 24/7, before routing to a person

1 click

for a human to take over the conversation with context

60%

less response time, according to our clients

The result? Compliance stops being a toll and becomes part of how you serve people better. The AI picks up the phone in about a second and answers your messages (WhatsApp, Instagram, Messenger, SMS, webchat) right away, at any hour; the lead moves across the board on its own based on the outcome of the call, no Zapier; and when someone asks for a person, they get one. According to our clients, that model translates into up to +40% more demos and −35% fewer no-shows, plus service that doesn't feel like a form.

Run through the list, check the boxes you already have, and note the ones missing. If you're left with more crosses than checks at the end, it's not a budget or a lawyer problem: it's that your tool wasn't built for this. And that has a fast fix.

Official sources

  • AI Act (Regulation (EU) 2024/1689), arts. 3, 4, 5, 6, 50, 99 and 113 — EUR-Lex
  • GDPR (Regulation (EU) 2016/679), arts. 6, 13, 22 and ch. V (international transfers) — EUR-Lex

Frequently asked questions

Does the EU AI Act apply to my business if I just use an off-the-shelf chatbot?

If you take calls from or handle data of people in the EU, yes. Even though you didn't build the AI, using it with your customers makes you the 'deployer,' and that carries transparency duties: disclose that it's an AI and offer a path to a person. The good news is these are manageable, and a serious provider leaves them all but solved for you. And even for US-only businesses, these disclosure practices are quickly becoming the norm.

What changed on August 2, 2026?

That's the date much of the regulation entered general application, including the transparency rules for AI systems that interact with people. It wasn't a blackout or an automatic fine: it's the point from which, if you serve EU residents, your disclosures and your handoff-to-a-person flow should already be in order.

Is my customer-service agent 'high-risk'?

Almost always no. An agent that answers calls or messages and books appointments falls under 'limited risk,' whose main duty is transparency. High-risk is reserved for uses like hiring or credit decisions. Even so, confirm it with your DPO or counsel if your case touches sensitive decisions.

If the AI messes up, who pays the fine—me or the provider?

It depends on who breached what: each party answers for its own obligations, and there's no automatic joint liability. As the deployer you can be penalized for your duties (disclosures, oversight, training), and the provider for theirs (AI Act, art. 99 and art. 3.8). That's why it pays to pick a tool that comes with compliance built in and leaves a trail of every interaction. We break it down in our guide on who pays the fine.

How many EU AI Act obligations does a small business using a chatbot or voice agent have?

In practice, seven concrete duties: disclose that it's an AI, offer a path to a person, handle data in line with GDPR, disclose recording if you record calls, don't use the AI for prohibited purposes, keep human oversight, and leave a trail of interactions. Six of the seven can be covered by your provider if the tool is well built.

What if I already use AI and my disclosure isn't in order?

There was no blackout or automatic fine on August 2, but since that date, if you serve EU residents, a regulator can require your disclosures and your handoff-to-a-person flow to be in order, and breaching the transparency rules is sanctionable. The sensible way to fix it is to get it documented and running as soon as possible.

Ready to activate your agent?

Launch your TotemAI pilot

Book a 20-minute call. Within 24 hours we’ll map your flows, analyze your tools, and scope a tailored pilot.

Arrow Book a demo

Made with by Totem Studio