← Back to blog

The EU AI Act for small businesses: what to arrange

TL;DR If you use AI without building it, you are a deployer and not a provider - which removes most of the obligations. What remains: AI literacy among your staff, human oversight and transparency. An assistant that queries your administration is normally not high-risk; using it to assess the creditworthiness of individuals or to decide on job applicants is. This article is not legal advice.

Since 2 August 2026 most of the European AI Act applies. Almost everything written about it addresses companies that build AI. This article is for the much larger group that only uses it — for example by connecting an AI assistant to its accounting. What changes, and what do you need to arrange?

This article is an overview, not legal advice. If you are unsure about your own situation, put it to a lawyer.

Does the AI Act apply to my business?

Yes, but in a lighter role than you might expect. The regulation distinguishes providers (who develop an AI system and place it on the market) from deployers (who use it under their own authority). If you buy an AI assistant and connect it to your administration, you are a deployer. The heaviest obligations — technical documentation, conformity assessment, quality management system — sit with the provider.

That is not a free pass. A set of obligations does land on you, and one of them has applied since early 2025.

The timeline

DateWhat starts to applyWhat it means for a user
1 August 2024The regulation enters into forceStarting point; no obligations yet
2 February 2025Prohibited practices and AI literacyAffects you directly: staff must understand what they are working with
2 August 2025Rules for general-purpose AI modelsMainly for the provider of your assistant
2 August 2026The bulk, including Annex III high-risk systemsRelevant if your use case falls in that category
2 August 2027High-risk systems embedded in productsRarely relevant for administrative use

Four risk classes, and where an accounting assistant sits

The regulation classifies by use, not by technology. The same assistant can therefore fall into two categories depending on what you point it at.

  • Unacceptable risk — prohibited. Social scoring, manipulation. Not in play for administrative use.
  • High risk — allowed under strict conditions. Annex III includes assessing the creditworthiness of natural persons and decisions about recruitment and employment. If you let an assistant decide whether a private customer may buy on account, you are here.
  • Limited risk — transparency obligations. People must know they are dealing with AI, or that content was AI-generated.
  • Minimal risk — no specific obligations. This covers the vast majority of use: asking questions about your own administration, pulling overviews, summarising figures.

The practical rule of thumb: looking up and summarising is minimal risk; deciding about people is not. It is about what you do with the output, not which assistant you use.

What you need to arrange as a user

  1. AI literacy. Make sure whoever works with it understands what the system does, where it goes wrong and how to verify an answer. This has applied since February 2025 and is the obligation most often overlooked.
  2. Human oversight. Record who may do what. An assistant that can only read cannot post an entry; that is oversight you do not have to enforce because it is already technically true.
  3. Transparency towards staff. Say which systems you use and for what. If the assistant contributes to anything that affects employees, that is not an optional notice.
  4. Know who your provider is. You depend on the documentation and the terms of the model you use. Keep a record of which assistant you used when.
  5. Keep track of what happens. If you can show afterwards which questions were asked and which actions followed, the rest of this list becomes far easier to evidence.

Where the AI Act and the GDPR meet

The two are often conflated. Briefly: the GDPR is about personal data — which data you process, on what basis and under which agreements. The AI Act is about the system — what you use it for, what risk that creates and what oversight belongs with it.

They overlap on one point: the moment you point AI at data about customers or staff, both apply. For the GDPR side you can generate a data processing agreement; how we handle data is set out on the security page.

What Ledger Botje already covers

Part of the oversight does not have to be built by you:

  • Read-only as the starting point — on Basic the assistant cannot change anything. Writing is a deliberate choice, not a default.
  • Tool permissions per connection and per colleague — you decide which parts of your administration a shared agent may see. That is human oversight enforced technically.
  • Audit logging — every call is recorded, so afterwards you can see what was asked and done.
  • Servers in the Netherlands — our own processing does not leave the EEA.

What we do not cover: what your AI assistant does with the conversation falls under that provider terms. Assess that separately, per assistant.

How to start

First determine what you use AI for and whether that stays within minimal risk. Then record who has access and why, inform your staff, and make sure you can show afterwards what happened. For most smaller businesses, that is the whole list.

Further reading: Exact Online and AI: GDPR, privacy and data processing, or the glossary for the terms that keep appearing in these texts. The full text of the regulation is on EUR-Lex.

Frequently asked questions

Does the EU AI Act apply to a small business?

Yes, but in a lighter role. Anyone who buys and uses AI is a deployer, not a provider. The heaviest part of the regulation targets providers who develop and place AI systems on the market. For users, what remains is mainly AI literacy, human oversight and transparency.

Is an AI assistant on my accounting a high-risk system?

Normally not. Querying and summarising administrative data does not fall under the high-risk categories in Annex III. That changes if you use the system to assess the creditworthiness of natural persons or to make decisions about applicants or employees; those uses are listed explicitly.

What is AI literacy and do I need to do something about it?

AI literacy means the people working with the system understand what it can and cannot do, and how to weigh its output. That obligation has applied since 2 February 2025 and covers users as well. In practice it comes down to explaining, recording the arrangements, and being able to show them.

What is the difference between the AI Act and the GDPR?

The GDPR is about personal data: which data you process and on what legal basis. The AI Act is about the system: what you use it for, what risk that carries and what oversight belongs with it. They sit alongside each other and you have to satisfy both.

What does Ledger Botje already cover?

The connector runs on servers in the Netherlands, authorises through OAuth 2.1 with PKCE, starts read-only and records every tool call in an audit log. Tool permissions per connection and per colleague make human oversight practical. What your AI assistant does with the conversation itself falls under that provider terms and needs to be assessed separately.

FW
Frank Woutersen is the founder of Ledger Botje and writes about AI, MCP and Exact Online. He helps businesses manage their administration smarter with AI assistants.

Ready to use AI with Exact Online?

Try Ledger Botje for free and discover how AI simplifies your daily work.

Try free