Regulation of AI is arriving, and most coverage of it is pitched at multinationals. If you run a dental practice in Norwalk or a contracting firm in Stamford, the practical question is narrower: does any of this apply to me, and if so what do I need to do about it? For most small local businesses the honest answer is that the direct obligations are modest, but the indirect ones are real and worth getting ahead of.
The European Union's AI Act is the most developed framework and is influencing legislation elsewhere, which is why it matters even to businesses with no European customers. Its central idea is sensible and worth borrowing regardless of whether it binds you: obligations scale with risk.
Systems that pose unacceptable risk are prohibited outright. High-risk systems, which broadly means those making consequential decisions about people such as in employment, credit or education, carry substantial documentation, oversight and testing requirements. Limited-risk systems, chiefly those that interact with people or generate content, mainly carry transparency duties. Everything else sits largely outside the framework.
The overwhelming majority of small business uses fall into the last two categories. Drafting social posts, summarising notes and answering routine customer questions are not high-risk activities.
The exception worth knowing about is hiring. Using AI to screen applications, rank candidates or evaluate employees is treated as high-risk in the EU framework and is also the area attracting the most attention from regulators in the United States, including at state and city level. New York City already requires bias auditing and candidate notification for automated employment decision tools, and other jurisdictions are following.
If you are using any tool that filters or scores job applicants, that is the one area where you should check your obligations properly rather than assuming you are too small to be caught. The rules generally attach to the activity, not the size of the company.
The practical requirement for ordinary business use is disclosure. People should know when they are interacting with an automated system rather than a person, and in many cases when content has been synthetically generated. This is not onerous:
Most of this is what a straightforward business would do anyway. Doing it now costs almost nothing and removes any future scramble.
For many small businesses the binding constraint will not be legislation at all. It will be a larger customer's procurement questionnaire. Enterprises and public bodies are increasingly asking suppliers what AI they use, where data goes, and what controls exist. That question arrives well before any regulator does.
Being able to answer it is a competitive advantage rather than a compliance burden. A supplier who can produce a clear, one-page answer looks considerably more capable than one who cannot.
Keep a simple written inventory: which AI tools you use, for what, what data goes into them, and who is responsible. A single page is enough. Review your vendor terms for whether your data is used in training, and prefer business tiers where it is not. Add a short paragraph to your privacy policy. Never put customer personal data, health information or financial details into a free consumer chat tool.
Then check the fundamentals of your own site, because data handling and basic web hygiene tend to be neglected together. Our audit of 622 local business websites found 2.4% still serving pages without HTTPS, which is both a trust problem and, where forms collect personal information, a genuine one. A free website audit will confirm where you stand.
None of this is a reason to avoid the technology. The regulatory direction is toward transparency and accountability rather than prohibition, and a business that documents what it uses and tells customers the truth will find compliance largely incidental. The businesses that will struggle are the ones that cannot say what they are running or where their customer data went.
Generally not directly. It applies to systems placed on the EU market or whose output is used there. However, it is shaping law elsewhere and shaping how vendors build products, so its requirements reach you through the tools you buy. Treating its transparency principles as good practice is sensible even where the Act does not bind you.
No general rule currently requires disclosing AI assistance in written correspondence, as distinct from disclosing an automated system a customer is conversing with. The line worth holding is honesty: never imply personal attention that was not given. If a message claims you reviewed something personally, review it personally.
Data handling, not the AI itself. Pasting customer records, medical details or financial information into a consumer tool with unfavourable terms creates exposure under privacy laws that already exist and are already enforced. That risk is present today, independent of any new AI legislation, and it is entirely avoidable.
Waiting carries its own cost, and the areas most small businesses want to use, drafting, summarising and scheduling, are not where the regulatory attention sits. Adopt in the low-risk areas now, keep the written inventory, and be more careful in hiring and any decision affecting someone's access to work, credit or services.
Want this handled for you?
Get a free audit of your website, Google reviews, and local SEO — we’ll show you exactly where you’re losing customers. Delivered in 24 hours, no sales call.
Get my free audit → or book a 15-min callWe help local businesses in Stamford, Greenwich, Norwalk, and Fairfield County implement AI marketing that generates real results.
Get Your Free AI Marketing Audit →