The rules are coming either way, and they ask simple things
You have seen the headlines: the EU has passed its AI Act, and US states are passing their own laws one by one. It is easy to conclude this is a problem for companies with legal departments. It is not, for two reasons.
First, you are probably already using AI, whether or not you chose to. Second, the ideas underneath almost every AI rule are ones a small business can act on this month: know what you use, protect the data you feed it, be honest with the people it affects, and keep a human accountable for decisions about people.
The details of who falls under which law are set out in who the EU AI Act applies to and the patchwork of US state AI laws. If you work in a regulated sector such as health, finance or insurance, or you use AI to make significant decisions about people, take specific legal advice. For everyone else, the steps below are where to start, and they will put you on the right side of most rules as they arrive.
Step one: find out where AI is already in use
You cannot manage what you have not listed. Start with the obvious tools: the chatbot subscription, the image generator used for social posts. Then look for the hidden ones, because they are usually the larger exposure.
- AI features inside software you already pay for. Office suites, customer-relationship systems, accounting tools and help desks are adding AI features, sometimes switched on by default.
- Meeting note-takers that join calls, record them and write summaries.
- Browser extensions that summarise pages or rewrite emails, with access to whatever is on screen.
- Personal accounts. Staff using their own free AI accounts for work tasks is common, and it is the hardest use to see.
Keep the list simple: the tool, what it is used for, who uses it, and what data it touches. That single page is the foundation for everything else.
Step two: control what goes in
Most of the real risk is in what staff paste into a prompt. Set a short list of things that never go into a public AI tool:
- customer personal data, such as names with order histories, addresses or account details;
- health, financial or other sensitive information about anyone;
- passwords, keys and access codes;
- contracts and documents covered by confidentiality agreements.
Then make the safe path the easy one. Use business accounts for the tools you approve, and check that they let you turn off use of your data for training. A blanket ban rarely works; it pushes staff onto personal accounts where you can see nothing and control nothing. An approved tool with clear rules is safer than a forbidden one used in secret. This fits naturally alongside the first steps in small business security: accounts you control, protected with strong sign-in.
Step three: tell customers when they are dealing with AI
Transparency is the most common thread in AI rules, and the cheapest to get right.
- A chatbot says it is a chatbot. It should never let a customer believe they are talking to a person.
- Recorded calls and meetings should be disclosed, including when AI will transcribe or analyse them. Consent is the weak point of most note-taking tools, as AI meeting note-takers and consent explains.
- Synthetic images and media in marketing should not show people or events that never existed as if they were real.
Picture a customer who discovers, after a long complaint, that the sympathetic "agent" was a bot. The problem is not the bot. It is that they were allowed to think otherwise.
Step four: keep a person responsible for decisions about people
AI can sort, score and suggest. It should not have the final word on decisions that materially affect someone: hiring, firing, credit, pricing for an individual, or access to a service.
For each place where AI informs such a decision, name the person responsible. That person reviews the output, can overrule it, and records the decision and the reason. This is good management in any case, and it is the core of how most rules treat high-risk uses. Hiring is the area where this matters most often for small firms, and your rights when an algorithm screens you shows the decision from the candidate's side, which is a useful test of whether your process is fair.
Step five: ask vendors four questions, and write the policy
Before adopting an AI tool, ask the vendor:
- Where is our data stored and processed?
- Is our data used to train your models, and can we turn that off?
- How do we delete our data completely if we leave?
- How and when will you tell us about a breach?
Get the answers in writing. Vague answers are an answer.
Then write a policy of one page. It should say which tools are approved, what data never goes into AI tools, when customers must be told, which decisions need a named human, and who to ask when unsure. A long policy goes unread. A page that fits on a noticeboard gets followed.
This month: make the list of tools; publish the never-paste list; switch approved tools to business accounts with training turned off; add a bot disclosure to any chatbot; name the person responsible for each decision about people; send the four questions to your main vendors.
Questions people ask
What if we only use free AI tools?
Then read their terms carefully, because free consumer tiers often allow the provider to use what you type to improve its models, and they rarely give you business controls. For anything involving customer or confidential information, a business plan with training switched off is the safer default.
Do we need to follow these steps if we are not in the EU?
The specific obligations depend on where you operate and whom you serve, and some rules reach businesses outside their home jurisdiction. The habits here are worth having anywhere, because they are what most rules converge on.
How do we stop staff using AI on their phones?
You mostly cannot, and trying usually drives use out of sight. Give staff an approved tool that is easier to use, a clear never-paste list, and a person to ask. That reduces risk far more than a ban.
Is a one-page policy really enough?
For most small businesses, yes, if it covers approved tools, forbidden data, customer disclosure and human review. What matters is that people read it and follow it, which a short page achieves and a long one does not.
Close
AI rules sound like a legal project. For a small business they are mostly a management one: list what you use, keep sensitive data out of the wrong tools, tell people when they are dealing with a machine, and keep a named person responsible for decisions about people. Do those four things and write them on one page, and you will be ready for most of what the rules ask, wherever you are.