✦  Is your business ready for AI? Find out with the test  → ✦  What does your business need? Take the free check-up  →
AI & Governance

the ai act: what a business really needs to know.

The obligations that matter for anyone communicating and selling online, explained without alarmism and without needless jargon.

by Paola Mirone · 3 July 2026 · 6 min read
In this article

What the AI Act is, in one sentence

The AI Act is the European regulation that governs the use of artificial intelligence according to its level of risk: the more a system can affect people's rights and safety, the more obligations it carries. It doesn't ban AI for businesses: it asks them to use it consciously.

Does it apply to my company too?

It may well do: it depends on your organisation's role, the systems you use and the level of risk — third-party tools are enough, such as an AI assistant for copy or a system that screens applications. Most business uses fall into the low or limited risk bands, with manageable obligations (transparency, training); some uses — recruitment, credit, surveillance — move up a band and demand far more. The point isn't panic: it's knowing which band you're in.

The three obligations that touch almost everyone

First: literacy — anyone using AI in the company must be trained to use it properly. Second: transparencygenerated content and chatbots must be declared as such where the rules require it. Third: control — knowing which tools are in use, with which data, under what human supervision. An inventory of the AI tools in use is the first document to produce, and it costs one meeting.

Where to start without losing your mind

Three steps, in order: take stock of the AI tools already in use (there are more than you think); write a lightweight AI Policy — what can be done, what can't, with which data; train your people. Whoever takes these three steps has already turned a regulatory risk into an advantage: clients and partners are starting to ask for it.

minimal risk — most uses limited — transparency obligations high — strict requirements unacceptable
Illustration — the AI Act risk pyramid: the higher you climb, the heavier the obligations. Most business uses sit at the bottom.
In short
  • The AI Act regulates by risk band: first, know yours.
  • It applies to almost every business that uses AI tools.
  • Training, transparency, control: the cross-cutting obligations.
  • Inventory + policy + training = the right start.

Last updated: 30 July 2026 · Official sources: European Commission — AI Act · ISO/IEC 42001. Informational content: it does not constitute legal advice.

quick answers.

Does the AI Act apply to small and medium-sized businesses too?

Yes: it applies to anyone using AI systems, even just third-party tools. For most SMEs the obligations are light, but they need to be known.

What are the AI Act risk classes?

Four: minimal risk (most business uses), limited (transparency obligations), high (strict requirements) and unacceptable (banned practices).

Where do you start with AI Act compliance?

With an inventory of the AI tools in use, followed by a policy written in plain language and basic staff training.

Paola Mirone
Paola MironeFounder & CEO, Webbidu Digital Minds. Twenty years in marketing and communications, now AI governance too.
✦ Newsletter

one useful idea a month.

Strategy, AI and marketing for decision-makers. One email a month, zero spam — unsubscribe in one click.

Recent topics: getting cited by AI engines · the three KPIs leadership should ask for · the AI Act, explained role by role.

Strategic check-up