All articles
COMPLIANCE

EU AI Act compliance for growing teams

5 minutes read

EU AI Act compliance for growing teams
Summary

The EU AI Act isn't just a large-enterprise problem. Here's what it actually means for a growing team, in practical terms, not legal theory.

The EU AI Act gets talked about like it's a large-enterprise problem: something for banks and hospitals with compliance departments to worry about. For a growing agency or consultancy, that read is comfortable and wrong. If your team uses AI on client work and any of that work touches the EU, the Act's practical obligations apply to you too, just in a lighter form than they apply to a bank.

This is not a substitute for legal advice specific to your business. It is a plain description of what actually changes in practice, so you know what to ask your lawyer instead of guessing.

The shape of the law: risk, not size

The Act doesn't regulate companies by size. It regulates AI systems by risk. A system used for something low-stakes, like drafting marketing copy, carries far fewer obligations than one used for something high-stakes, like screening job candidates or making credit decisions.

Most of what a growing agency or consultancy uses AI for sits in the lower-risk bands: drafting, research, summarising, internal analysis. That doesn't mean zero obligations. It means the obligations are about being able to show what you did, not about pre-approval or certification.

What "being able to show what you did" means in practice

Three things, in plain terms:

Know what you're using it for. You should be able to state, per team or per use case, what AI is being used for and on what kind of data. If you can't answer that today, that's the first gap to close, independent of the Act.

Keep a record. Which model handled which piece of work, when, and on whose behalf. This is the same audit trail that makes client trust possible, not an extra burden layered on top of it.

Know where the data goes. Processing location matters both for the Act and for client contracts that specify data residency directly. If a client asks where their data was processed and the honest answer is "we don't know," that's a bigger problem than any single regulation.

Where EU residency and audit logs actually fit

These aren't abstract compliance checkboxes. They're the concrete answer to the three points above.

RequirementWhat it looks like in practice
Know what you're using AI forA short, current list of AI use cases by team
Keep a recordAn audit log: who, what model, when, on whose behalf
Know where data is processedEU data residency, stated plainly, not buried in a vendor's terms

If your current AI tools can't answer any row of that table, that's the practical gap, regardless of how the Act is eventually enforced in detail.

"We're too small for this to apply"

This is the most common reason teams delay looking at it, and it doesn't hold up on inspection. The Act's obligations are tied to what an AI system is used for and, for general-purpose models, to how the model itself is provided, not to the size of the company using it. A 40-person consultancy running client analysis through a general-purpose model isn't automatically exempt because it isn't a large enterprise. It may well sit in a lighter-obligation band than a bank's credit-scoring system, but "lighter" is not "none."

The practical risk of assuming you're too small isn't a fine. It's a client who asks a direct question about how their data was handled and gets an answer that reveals nobody had looked at it.

Transparency: telling people AI was involved

One obligation is easy to overlook because it's simple: certain uses require disclosing that AI was involved, particularly where the output could otherwise be mistaken for something a person made without assistance. For a growing team this mostly means being straightforward with clients about where AI sits in your process, rather than treating it as something to obscure. Teams that are already transparent about this as a matter of trust tend to find this requirement is already met in practice.

What this doesn't mean

It doesn't mean you need a compliance officer, a certification process, or a six-month audit before your team can use AI. For most growing teams, the obligations here are closer to good practice you should have anyway: know what you're using, log it, and know where it lives. The Act raises the cost of not doing that. It doesn't invent a new burden out of nothing.

Questions to ask any AI vendor

  • Where is our data processed, specifically, not just "in a compliant region"?
  • Is there an audit log we can see, not just one that exists internally?
  • Is any of our data used to train your models?
  • Can we get a straight answer to all three without a sales call?

Where Hebno fits

Every request through Hebno is processed inside the EU, none of it trains any model, and every use is logged, by team, by person, and by client. That's the practical version of the three requirements above, already in place rather than something to build separately. See our DPA for the specifics.

See where your AI spend is going.

Most teams find the number surprising. Book a 20-minute demo and we will show you yours.