Since 2 August 2026 most of the European AI Act applies. Almost everything written about it addresses companies that build AI. This article is for the much larger group that only uses it — for example by connecting an AI assistant to its accounting. What changes, and what do you need to arrange?
This article is an overview, not legal advice. If you are unsure about your own situation, put it to a lawyer.
Does the AI Act apply to my business?
Yes, but in a lighter role than you might expect. The regulation distinguishes providers (who develop an AI system and place it on the market) from deployers (who use it under their own authority). If you buy an AI assistant and connect it to your administration, you are a deployer. The heaviest obligations — technical documentation, conformity assessment, quality management system — sit with the provider.
That is not a free pass. A set of obligations does land on you, and one of them has applied since early 2025.
The timeline
| Date | What starts to apply | What it means for a user |
|---|---|---|
| 1 August 2024 | The regulation enters into force | Starting point; no obligations yet |
| 2 February 2025 | Prohibited practices and AI literacy | Affects you directly: staff must understand what they are working with |
| 2 August 2025 | Rules for general-purpose AI models | Mainly for the provider of your assistant |
| 2 August 2026 | The bulk, including Annex III high-risk systems | Relevant if your use case falls in that category |
| 2 August 2027 | High-risk systems embedded in products | Rarely relevant for administrative use |
Four risk classes, and where an accounting assistant sits
The regulation classifies by use, not by technology. The same assistant can therefore fall into two categories depending on what you point it at.
- Unacceptable risk — prohibited. Social scoring, manipulation. Not in play for administrative use.
- High risk — allowed under strict conditions. Annex III includes assessing the creditworthiness of natural persons and decisions about recruitment and employment. If you let an assistant decide whether a private customer may buy on account, you are here.
- Limited risk — transparency obligations. People must know they are dealing with AI, or that content was AI-generated.
- Minimal risk — no specific obligations. This covers the vast majority of use: asking questions about your own administration, pulling overviews, summarising figures.
The practical rule of thumb: looking up and summarising is minimal risk; deciding about people is not. It is about what you do with the output, not which assistant you use.
What you need to arrange as a user
- AI literacy. Make sure whoever works with it understands what the system does, where it goes wrong and how to verify an answer. This has applied since February 2025 and is the obligation most often overlooked.
- Human oversight. Record who may do what. An assistant that can only read cannot post an entry; that is oversight you do not have to enforce because it is already technically true.
- Transparency towards staff. Say which systems you use and for what. If the assistant contributes to anything that affects employees, that is not an optional notice.
- Know who your provider is. You depend on the documentation and the terms of the model you use. Keep a record of which assistant you used when.
- Keep track of what happens. If you can show afterwards which questions were asked and which actions followed, the rest of this list becomes far easier to evidence.
Where the AI Act and the GDPR meet
The two are often conflated. Briefly: the GDPR is about personal data — which data you process, on what basis and under which agreements. The AI Act is about the system — what you use it for, what risk that creates and what oversight belongs with it.
They overlap on one point: the moment you point AI at data about customers or staff, both apply. For the GDPR side you can generate a data processing agreement; how we handle data is set out on the security page.
What Ledger Botje already covers
Part of the oversight does not have to be built by you:
- Read-only as the starting point — on Basic the assistant cannot change anything. Writing is a deliberate choice, not a default.
- Tool permissions per connection and per colleague — you decide which parts of your administration a shared agent may see. That is human oversight enforced technically.
- Audit logging — every call is recorded, so afterwards you can see what was asked and done.
- Servers in the Netherlands — our own processing does not leave the EEA.
What we do not cover: what your AI assistant does with the conversation falls under that provider terms. Assess that separately, per assistant.
How to start
First determine what you use AI for and whether that stays within minimal risk. Then record who has access and why, inform your staff, and make sure you can show afterwards what happened. For most smaller businesses, that is the whole list.
Further reading: Exact Online and AI: GDPR, privacy and data processing, or the glossary for the terms that keep appearing in these texts. The full text of the regulation is on EUR-Lex.