EU AI Act in Practice: What Should Your SMB Actually Do About Risks?
The EU AI Act is now in force, and many business owners in the Netherlands feel uncertain. The regulations sound complicated, but for companies deploying an AI system to take recurring work off their plate, it's far less daunting than it appears. This article walks you through the practical steps your SMB needs to stay compliant without getting lost in legal mazes.
What Is the EU AI Act and Why Does It Affect Your SMB?
The EU AI Act is a regulatory framework that categorizes AI applications based on risk. For most SMBs deploying an AI system for internal automation, the risk level is low. This means you won't fall into the heavier compliance categories (prohibited AI, high risk), but you do need to meet some basic requirements.
The core of the regulation: you must be able to demonstrate that you understand what risks your AI system carries, how you manage them, and that you're transparent with your customers and employees. This applies especially if your AI system directly influences customer decisions or processes personal data.
An AI operating system (AIOS) that automatically answers emails, sorts customer data, or manages quote follow-ups typically falls under low risk. But a system that automatically rejects customers or evaluates employees could be higher risk. The question is: how do you know for sure where you stand?
Step 1: Conduct a Risk Analysis for Your AI System
Start by establishing exactly what your AI system does and what risks it carries. This doesn't need to be 50 pages. For an SMB, a two to four page document answering questions like these will do:
What are the inputs to your AI system (what data goes in)? Who depends on the output (customers, employees, both)? What happens if the system makes wrong decisions? How big is the impact of those errors?
Imagine your AIOS automatically categorizes and routes customer requests to the right department. The risks are relatively low: if the system gets it wrong, an employee can correct it. But imagine the same system automatically approves or denies credit without human review. Then the risk rises significantly.
This analysis document is your first proof of governance. You don't need to send it to the authorities, but you must be able to show it if ever asked.
Step 2: Define Your Role as a User, Not a Developer
This is crucial. If you deploy an AI system built by an external party (a software vendor, an AI agency, or even a combination of Claude and n8n through an implementation partner), you are the user. The vendor bears responsibility for technical compliance, but you're responsible for how you deploy it.
This means you don't need to train or validate the AI models yourself. OpenAI does that for GPT-5, Anthropic for Claude, and Google for Gemini. You do need to ensure you use the system responsibly in your business context.
In practice: if you work with an implementation partner building your AIOS based on Claude or GPT-5, explicitly ask for documentation on how they've structured compliance. A serious partner will give you a compliance statement. That saves you work and risk.
Step 3: Set Up the Right Governance Within Your Company
Compliance starts with internal agreements. You don't need to create a separate compliance department, but you do need to be clear about:
Who is responsible for the AI system? This could be the owner, the operations director, or a designated employee. This person oversees how the system works and acts if problems arise.
How do you test whether the system is still working well? For many AIOS applications, monthly checks are enough: reviewing a sample of generated emails, routed tickets, or analyzed data. Simply document this in a checklist.
What do you do if the system makes mistakes? Set up a simple escalation process. Example: if your AIOS miscategorizes a customer three times in a row, you pause the system and call your implementation partner.
Record these agreements in an AI governance document. It's no more than a page, but it shows you're aware of your responsibilities.
Step 4: Ensure Transparency With Customers and Employees
The EU AI Act requires you to be transparent about AI use. This doesn't mean posting a legal document on your website, but it does mean communicating clearly.
For customers: if your AIOS automatically sends emails or processes customer requests, you can't hide that. You don't need to say "this was made with Claude," but you do need to say "this response was partly generated using AI technology." Many companies add this to their email signature or FAQ.
For employees: if your AIOS changes their work (for example, by automatically generating status updates), they need to know it's happening. This is also a change management issue: employees feel safer when they understand what the system does and doesn't do.
Step 5: Decide What You Outsource and What You Keep In-House
This is where many SMB owners stumble. You don't need to do everything yourself.
Outsource: the technical build of your AIOS, AI model training and validation, hosting and security of your system. Do this through a specialized partner like an AI agency or implementation firm that integrates n8n and Claude.
Keep in-house: the risk analysis for your business context, governance and oversight, communication with customers and employees, final responsibility for how the system works.
A concrete check: if your partner can't explain how they've structured compliance, that's a warning sign. A trustworthy partner gives you a compliance roadmap and helps you set up governance.
Step 6: Document and Keep Your Records
Compliance is easier when you document it. Keep:
- Your risk analysis
- Your AI governance document
- Test logs or control checklists
- Communication with customers about AI use
- Correspondence with your implementation partner
This doesn't need to be in an elaborate binder, but a simple folder in Google Drive or OneDrive with these files is enough. If questions ever come up, you have proof that you've handled AI responsibly in your business.
The Practical Reality for Your SMB
For most SMBs, the EU AI Act is no reason to panic. If you deploy an AI system that makes your business faster without directly making critical decisions, you're probably in the low-risk segment. That means you're compliant with a few simple steps: a risk analysis, internal governance, transparency, and good oversight.
The difference from hiring extra staff is clear: an AIOS is operational in weeks, while recruiting and onboarding a new employee takes months. At the same time, you need to know your AI system works responsibly. These six steps help you get there.
Want to know how your specific situation relates to the EU AI Act, or need help setting up governance for your AIOS? Contact us for a discovery call at 5cagency.nl. We'll help you fill in the compliance steps concretely, so you can grow with confidence.
Ready to serve more clients with the same team?
Book a discovery call. We look at your business together and show you which recurring work an AI system can take off your plate.
Book a discovery call →