What the AI Act is and why it matters even if you're a freelancer
Imagine this: you have a chatbot on WhatsApp that handles customers and books appointments. It's saved you hours of work. One day an inspection shows up, and it turns out you've been violating a European regulation for 6 months that you'd never even heard of. Sounds exaggerated, but it's the scenario thousands of SMBs are facing since February this year.
The AI Act (Regulation EU 2024/1689) is the world's first law regulating artificial intelligence at continental level. It's not a voluntary guideline or a recommendation: it's mandatory throughout the EU, including Spain. And it doesn't distinguish between 10-person and 10,000-person companies. If you use AI in your business, this law applies to you. If you need to automate processes with AI in your SMB, we have solutions ready to comply.
Now, take a breath. That it applies to you doesn't mean you're doing something wrong. It means there are things you need to document and be transparent about. According to National AI Observatory data, 68% of Spanish companies using AI haven't started preparing yet. So if you're reading this, you're ahead of the curve.
The 4 risk levels (and where you fit in)
The AI Act divides AI systems into four categories. Knowing which one you're in tells you exactly what you need to do. I'll sum it up because nobody understands articles 6-7 of the regulation on first read:
| Level | What it includes | Probably you | What you need to do |
|---|---|---|---|
| Unacceptable | Social scoring, mass surveillance, manipulation | No | Don't even think about it. Banned since Feb 2025. |
| High risk | HR selection, credit scoring, justice, education | Only if you use AI to filter CVs or evaluate people | Technical documentation, impact assessment, mandatory human oversight |
| Limited risk | Chatbots, virtual assistants, generative AI, deepfakes | Most fall here | Inform the user they're talking to AI. That's it. |
| Minimal | Spam filter, productivity without people decisions | Maybe some tools | Nothing specific |
Most SMBs using WhatsApp chatbots, automation with n8n or Make, or just having their team use ChatGPT daily, are in "limited risk." Your main obligation: the user knows they're talking to a machine. A welcome message like "Hi, I'm the virtual assistant for [your company]" works as a baseline.
But watch: if your chatbot also filters job candidates, evaluates credit applications or makes decisions affecting people's rights, you jump to "high risk." And then you really need advice.
Spain was the first EU country to create its supervisory agency: AESIA (Spanish Artificial Intelligence Supervision Agency), based in A Coruña. By March 2026 they had opened 23 preliminary investigations. This is serious.
What you need to do (no lawyer, no stress)
Let's get down to it. These are the real obligations based on your case. Not regulation summary: what you need to do tomorrow morning.
If you have chatbots or virtual assistants (limited risk)
- Tell the user they're talking to AI. A clear initial message. You don't need a legal notice: "I'm X's virtual assistant, how can I help?" works.
- Mark AI-generated content. If you publish text, images or audio made by AI, say so. This has applied since February 2025.
- Don't upload sensitive data to external APIs. If your chatbot sends customer conversations to ChatGPT or Claude, you have a GDPR problem on top of AI Act issues.
If you use AI for HR, scoring or decisions about people (high risk)
- Technical system documentation
- Fundamental rights impact assessment (FRIA)
- A person reviewing critical decisions
- Activity log (logs)
For this case seriously: seek advice. It's not optional.
For everyone, even if you just use ChatGPT to write emails
Article 4 of the AI Act requires your team to receive AI training. Since February 2025. Yes, this is asking you to do a training. In practice, one documented internal session is enough: what is AI, what it can do, what it can't, what data never gets uploaded. Renew yearly. Put the date in an Excel and you've covered that point.
Fines: how much you're really risking
This is the scary part, but read it with a clear head. The AI Act has three penalty tiers:
| Breach | Standard fine | Fine for SMBs |
|---|---|---|
| Prohibited practices (unacceptable AI) | Up to €35M or 7% revenue | Whichever is lower |
| Non-compliance with obligations (transparency, documentation) | Up to €15M or 3% revenue | Whichever is lower |
| Incorrect information to authorities | Up to €7.5M or 1% revenue | Whichever is lower |
The nuance that changes everything for SMBs: the lower amount applies, not the higher. If you invoice €2 million a year, the second tier cap comes to €60,000, not €15 million. For a €200,000 revenue company, it would be €6,000.
Does it still sting? Absolutely. €6,000 for not putting "I'm a virtual assistant" in your WhatsApp bot hurts. But it's not the apocalyptic LinkedIn headline you read. The €35 million maximum fine is aimed at big tech companies that systematically breach the rules, not at the freelancer who forgot to put a bot disclaimer on their WhatsApp.
Penalties for high risk take effect August 2, 2026. Prohibited practices have been sanctionable since February 2025.
To understand the real cost of inaction, check our article on how much it costs not to automate, where we analyze the financial impact of doing nothing on SMBs.
Your real case: scenarios we see every month
Real examples of what lands at BigLobster monthly. Pinpointing your risk is easier than it sounds.
Dental clinic with WhatsApp chatbot for appointments
A bot books appointments, confirms 24 hours before, and answers typical questions ("Do you take insurance?", "How much is a cleaning?"). Uses n8n and GPT-4o behind the scenes.
Risk: limited. Doesn't make decisions about people's rights, manages logistics. Needs: transparency message, policy against uploading clinical data to the API, and someone reviewing odd conversations.
Accounting firm classifying emails with AI
Automation that reads incoming emails and classifies them into tax, labor, payroll... Uses a language model to understand intent.
Risk: minimal or limited. Needs: system inventory, policy on what data goes to the model (don't send unmasked client names), and article 4 training.
Installation company with voice AI agent
An AI agent takes calls, collects basic info, and books tech visits. Doesn't filter people, just manages the schedule.
Risk: limited. The caller must know they're talking to AI. That's it. Plus document how the system works.
Law firm using AI to screen interns
A system that reads CVs, scores them and auto-rejects based on criteria.
Risk: HIGH. Annex III of the AI Act explicitly includes "employment and worker management." Here you need: technical documentation, fundamental rights impact assessment, human oversight and activity log. If you're serious about this, hire a lawyer.
AI Act and GDPR: different things (though they touch)
If you already complied with GDPR and think that's enough, here's why it's not:
| GDPR | AI Act | |
|---|---|---|
| What it's about | Protecting personal data | Regulating AI system use |
| Applies to you if | You process people's data | You use AI (with or without data) |
| Transparency | Inform about data processing | Inform user they're interacting with AI |
| Impact assessment | DPIA for high-risk processing | FRIA for high-risk AI systems |
If you already have a GDPR DPIA for some data processing, you can expand it with the AI Act part. They're complementary, not substitutes. That OpenAI complies with the AI Act on their end doesn't remove your obligations as the company using the tool.
If you're evaluating implementing AI agents in your business, our guide on how to integrate AI agents without a technical team will help you plan the rollout in a way that's compatible with the AI Act from the start.
What to do this week (3 steps, under 1 hour)
Less than 2 months until August 2. This is what I'd do tomorrow with your business:
- Inventory (30 minutes). Open an Excel and list all the AI you use. WhatsApp chatbot, automation with n8n/Make, ChatGPT, accounting software with AI, CRM with assistant... Put: name, what it does, what data it uses, who uses it. No need to be exhaustive: what matters is the list exists.
- Classify (20 minutes). For each tool: does it make decisions about people? If yes → high risk, get advice. If no → definitely limited or minimal risk. Apply step 3.
- Transparency (10 minutes). If you have a chatbot, check the user knows they're talking to AI. If your team uses ChatGPT, write a one-page document: what can be uploaded, what can't. Schedule a 30-minute internal session explaining what AI is and its limits. Save the date and attendee list.
"68% of Spanish companies haven't started preparing. If you do the inventory, classify and add transparency, you're already ahead of most. AESIA said it would prioritize education the first 6 months. But 'education' doesn't mean 'nothing happens': if someone files a complaint, not having started doesn't excuse you."
Frequently asked questions
Does the AI Act apply to freelancers without employees?
Yes. The AI Act makes no exceptions by size. If you're a freelancer and use a chatbot, automation or generative AI tools, it applies. Obligations are proportional: most freelancers fall into "limited risk" and only need transparency.
Do I have to remove my WhatsApp chatbot?
No. The AI Act doesn't ban chatbots. What it requires is the user knows they're talking to AI. If your chatbot handles inquiries, books appointments or answers FAQs, keep it. Add an informative message and carry on.
When can they fine me?
Penalties for high-risk systems take effect August 2, 2026. Prohibited practices (unacceptable risk) have been sanctionable since February 2025. AESIA announced it would prioritize education over penalties for the first 6 months of full application, but starting February 2027 the tone changes. Don't wait until the last minute.
Do I need a lawyer?
For most SMBs with basic AI use (chatbots, common automation, ChatGPT as a tool), no. This article's checklist covers enough. If you use AI to select staff, evaluate credit or make decisions about people, seek specialized legal advice.
What if I do nothing before August 2?
Technically, breaches will be sanctionable. In practice, there will be an adaptation period. But don't let that be your plan. Doing the inventory and documenting what you have serves as a mitigating factor if something goes wrong. Plus, the AI Act is just one part: if you have a chatbot with customer data, GDPR already applies. Complying isn't optional, it's a question of when, not if.
Do the tools I use already comply with the AI Act on their side?
OpenAI, Anthropic, Google and other providers have obligations starting August 2025. But you, as a company using those tools (the "deployer"), have your own: document what data you send them, have an internal usage policy, and make sure a human reviews what matters. That they comply doesn't excuse you.
Want to comply with the AI Act hassle-free?
At BigLobster we implement AI solutions and make sure they comply with regulation. From auditing what you have to documenting your compliance. Let's talk.
Talk to an expert →