Skip to content
Products
Platform
PricingSecurityServicesBlog
Start freeSign inBook a demo

The EU AI Act for SMBs: what a limited-risk AI workspace actually has to do

Most business AI tools are limited-risk under the EU AI Act. That means Article 50 transparency duties, not a compliance mountain. What applies to you as a deployer.

The EU AI Act for SMBs: what a limited-risk AI workspace actually has to do
In short
  • A chat-and-drafting workspace sits in the limited-risk tier. Article 50 transparency duties apply, not conformity assessments.
  • If you use FlowSentric for your business you are a deployer; the general-purpose-model duties sit with the model providers.
  • Write a one-page note: approved tools, tasks, who reviews output, where the logs live. Our AI Act statement, DPA and subprocessor list attach to it.

If you run a small or mid-sized company, the AI Act headlines probably sound like they're about someone else. They mostly are. Regulation (EU) 2024/1689 sorts AI systems into four risk tiers, and the drama sits in the top two: prohibited practices such as social scoring, and high-risk uses such as credit scoring, hiring decisions, biometrics and critical infrastructure. Almost nobody in an SMB is building those. What most SMBs actually use is a tool that chats, drafts and summarises. That lands in the limited-risk tier.

What limited risk means, in practice

Limited-risk systems carry the transparency obligations of Article 50. Boiled down:

  • People must be told when they are dealing with an AI system rather than a human.
  • AI-generated or manipulated content should be identifiable as such.
  • Where AI drafts something consequential, a human should be able to review it.

Those are design decisions, not a compliance department. The heavy duties, risk management systems, conformity assessments, CE marking, apply to high-risk systems and to providers of general-purpose models. Not to a firm that uses a chat workspace to answer client emails.

Provider or deployer?

The Act separates providers, who build a system or model, from deployers, who use it under their own authority. If you use FlowSentric to run an agent for your business, you're a deployer. We don't train or offer foundation models. We integrate third-party models (OpenAI, Anthropic, Google, Mistral and others) as a downstream deployer ourselves, and the general-purpose-model obligations sit with those providers.

Could your use case be high-risk anyway? Only if it falls into an Annex III category, for example screening job applicants with AI or deciding on someone's creditworthiness. If that's you, the safeguards you need go beyond any tool. Document them, and talk to us; we'll help you set up the approval steps and logs.

How FlowSentric handles Article 50

  1. AI is disclosed. Chats, agents, AI Sessions and embedded widgets make clear that a person is talking to an AI system.
  2. The model is named. The picker shows exactly which model answers, and models routed through the EU gateway carry an "(EU)" label.
  3. A human can sit in the loop. Workflows have an approval step; the run pauses until a person approves or rejects. Agents can hand off by email or Slack instead of acting on their own.
  4. There are logs. Every agent run keeps a trace of its tool calls, and the audit log records who did what and when. Both export as CSV.
  5. Less personal data goes in. Privacy Guard strips personal data out of prompts, which serves the data-governance spirit of the GDPR and the AI Act at the same time.

What to write down as a deployer

Even for limited-risk use, a short internal note pays off: which AI tools are approved, for which tasks, who reviews output before it reaches a client, and where the logs live. One page is plenty. Our EU AI Act statement, DPA and subprocessor list are written so you can attach them to that note.

The usual caveat applies: this is information, not legal advice. The Act's obligations phase in over 2025 to 2027, and the implementing guidance keeps moving, so check the current state for your case.

All articles
Aneel Ahmed · Co-founder, FlowSentricAneel co-founded FlowSentric in Hamburg and writes about putting AI to work on real business data without handing that data away. Questions? hello​[at]​flowsentric.com
Try it on your own documentsStart free