Free guide
The EU AI Act, explained for small businesses.
If your business uses a virtual assistant to answer its clients, this guide tells you in five minutes what changes, when, and what you have to do. No jargon and no scaremongering.
General guidance, not legal advice. The timeline and the detail may be updated: check official sources and, for your specific case, a professional.
1. What it is and who it affects
Regulation (EU) 2024/1689 is the world's first comprehensive law on artificial intelligence. It does not regulate “AI” as a block: it regulates it by risk level, so the obligations are proportionate to what the system can actually affect.
It affects whoever develops AI systems (the provider) and whoever uses them in their professional activity (the deployer). If you take on a virtual assistant, you are the latter, and the bulk of the technical obligations does not fall on you.
2. The four risk levels
Understanding this pyramid is understanding the whole regulation.
Unacceptable risk
Prohibited practices: manipulating people in ways that cause them harm, exploiting vulnerabilities, social scoring or emotion recognition at work, among others.
High risk
Systems that can seriously affect rights or safety: recruitment, access to essential services or triaging patients in emergency care, among others. Demanding obligations.
Limited risk
This is where most conversational assistants sit. The core obligation is transparency: the person must know they are talking to an AI.
Minimal risk
Every other system, with no specific obligations.
An assistant that replies to messages, informs and books appointments generally sits in limited risk: it does not evaluate people or decide anyone's access to an essential service.
3. When each part applies
- August 2024
Enters into force
Regulation (EU) 2024/1689 enters into force, applying in phases over time.
- February 2025
Prohibitions and AI literacy
The prohibited practices start to apply, along with the obligation for those using these systems to have sufficient training on them.
- August 2025
General-purpose models
Obligations for general-purpose AI models and most of the penalty and governance regime.
- August 2026
General application
The bulk of the regulation applies, including the transparency obligation that affects conversational assistants.
- August 2027
Final phase
AI systems embedded as a safety component in products already regulated by other legislation.
4. Checklist
If you use a virtual assistant, go through these nine points. None of them needs a technical department.
- I know exactly what the assistant I use does, and what it does not do.
- Whoever talks to it knows it is an AI, without having to work it out.
- My team understands the tool and its limits (AI literacy).
- There is a clear human exit: asking to speak to a person is easy and works.
- I can pause or switch the system off at any time.
- I know where the data is processed and stored.
- There is a record of what the system says on behalf of my business.
- I use it for its intended purpose, not for something else.
- I still comply with the GDPR: the AI Act does not replace it.
5. What to demand from your provider
The law gives you leverage as a customer: whoever builds these tools should be able to explain them. These questions separate a serious provider from one who is improvising.
- What does the system do, and what does it not do?
- Does the client know they are talking to an AI?
- How is a conversation handed over to a person?
- Where is the data processed and stored?
- Can I pause it whenever I want?
- What gets recorded?
- Who do I talk to when something goes wrong?
If you get evasive answers to half of them, you already have your answer.
Found this guide useful? Share it.
It is free to use. If you run an appointment-based business and want to see how an assistant that follows these rules works, take a look at ClaudIA.