When your staff use ChatGPT, Gemini or Claude at work, your organisation is the deployer under the AI Act, not them. A free plan changes nothing about that. The actual obligations are narrower than most articles suggest, but they do not sit where people expect.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
When your staff use ChatGPT, Gemini or Claude at work, your organisation is the deployer under the AI Act, not them. A free plan changes nothing about that. The actual obligations are narrower than most articles suggest, but they do not sit where people expect.
Article 50 of Regulation EU 2024/1689 has applied since 2 August 2026. It reaches more European organisations than any other provision, because it does not depend on the system's risk level: a six-person charity drafting meeting notes with a chat assistant falls under the same scope as an industrial group. If you need the wider picture first, the AI Act compliance guide for SMEs and non-profits covers it end to end. This article handles one narrow case: employees using consumer generative AI tools.
The organisation, always, and never the individual employee. The European Commission's FAQ on Article 50 is unambiguous: where a legal person is the deployer of an AI system, the individual employees acting under its instructions and control, whether copywriters, designers or sales staff, are not separate deployers. The legal person stays the deployer even when contractors or freelancers operate the system on its behalf.
France's data protection authority, the CNIL, reaches the same conclusion from another direction. In its Q&A on the use of generative AI systems, it states that the using organisation is the one incurring legal liability when its staff misuse AI.
Two practical consequences follow. First, banning AI on paper while tolerating it in practice offers no protection: de facto deployment is enough to make you a deployer. Second, a penalty will not land on the employee who pasted a client contract into a prompt, but on the organisation that had no written rule, no training and no oversight.
One exception: strictly personal use, outside any professional activity, falls outside the regulation. As soon as there is regular economic benefit or professional activity, freelance included, deployer status returns.
Of four transparency obligations, only one usually bites on organisations that merely use AI, and two fall solely on providers. Confusing them generates a great deal of pointless over-compliance.
| Obligation | Article | Who is bound | Relevant to an SME user? |
|---|---|---|---|
| Inform people they are interacting with an AI (chatbot, voice agent, avatar) | 50(1) | The system provider | Only if you run a public-facing conversational agent |
| Mark outputs in a machine-readable format | 50(2) | The provider | No, unless you build or resell a system |
| Inform people exposed to emotion recognition or biometric categorisation | 50(3) | The deployer | Rare in an SME |
| Label deepfakes and public-interest text published without human review | 50(4) | The deployer | Yes, as soon as you publish |
Put plainly: if your teams use generative AI to draft emails, prepare meeting notes, sort applications internally or produce a first pass at a commercial note, Article 50 asks almost nothing of you. Nothing requires an "AI-generated" stamp on a quote, a product sheet or a marketing newsletter. The customer-facing side is covered in detail in AI Act and customer information.
The timeline holds one useful nuance: the Commission confirms that content generated before 2 August 2026 does not need retroactive labelling, and that systems already on the market before that date get until 2 December 2026 for the machine-readable marking obligation alone. Full dates are in the AI Act timeline.
Three false needs come up in nearly every compliance pitch.
The first is blanket marking of anything produced with AI. The Commission explicitly carves out short sequences of numbers, symbols or letters, source code, outputs communicated machine-to-machine only, and outputs used in closed-loop industrial or product development environments. It also states that the obligation does not apply where the AI performs an assistive function for standard editing. Correcting a photo's exposure or rephrasing a paragraph is not synthetic generation within the meaning of the text.
The second is labelling every published text. Article 50(4) requires three cumulative criteria: the text must be published, must inform the public, and must concern a matter of public interest, a notion covering politics, public administration, justice, fundamental rights, public security and health, the environment, consumer safety, and economic, financial, scientific or cultural developments open to public debate. A technical blog post or a spec sheet does not tick those boxes. And even when it does, genuine human review or editorial control exempts it. One caveat: the Commission excludes superficial, purely formal or procedural checks. Running a spellchecker is not review.
The third is the idea that technical marking is enough. It is not. For a deepfake, the Commission says the deployer cannot rely on the machine-readable marking embedded by the provider; disclosure has to be perceivable by a person, with no special technical tools required.
Across a year of actual usage, an SME's exposure almost always comes from what goes into a prompt, not from a missing label. A translated client contract, an HR export pasted into a chat window, a board summary run through a consumer tool: GDPR, trade secrets and, in regulated professions, professional secrecy are engaged long before the AI Act is.
The CNIL accepts that a consumer service can be used for non-confidential purposes, but on conditions: access through dedicated work email addresses, no account creation with personal addresses, and opting out of the provider's reuse of usage data where that is possible. As soon as client or employee personal data, or sensitive and strategic documentation, is involved, it points towards on-premise deployment, referring to the French cybersecurity agency ANSSI's security recommendations for generative AI systems.
The overlap between the two regulations deserves its own treatment: see AI Act and employee data and, for the most widely used tool, AI Act and ChatGPT.
Price does not change your deployer status. It changes the data regime. That is the only difference with legal weight.
Three things to check in any provider's terms, whatever the tool:
One practical point that gets overlooked: when a tool is consumed through an API, control over the system sits almost entirely with the provider. Scrutiny of submitted data needs to go up, not down.
The CNIL explicitly recommends framing usage through internal policies or charters that clearly set out permitted and prohibited uses. A policy that merely urges caution is worthless. It has to decide cases.
Six minimum decisions:
A template to adapt is available in AI policy for business, and the question of who owns the topic internally is handled in appointing an AI officer.
Article 4 has required, since February 2025, a sufficient level of AI literacy from people using AI systems on the organisation's behalf. This obligation predates Article 50 and stands independently of it. It does not scale with company size, and a free tool does not exempt you.
The CNIL points the same way, recommending that end users be familiarised with how these systems work and where they fail, with permitted and prohibited uses, and warning about automation bias, the gradual loss of critical judgement in front of a machine that always answers. The precise content of the obligation is covered in AI Act Article 4.
Do we have to ban ChatGPT to comply with the AI Act? No. The AI Act neither bans nor restricts professional use of a general-purpose chat assistant. An outright ban is counterproductive anyway: it pushes usage onto employees' personal accounts, beyond any oversight. Framing works better than forbidding.
Must we write "AI-generated" on everything produced with AI? No. The disclosure duty on deployers covers deepfakes and text published to inform the public on matters of public interest without substantive human review or editorial control. Sales collateral, product sheets and client emails fall outside that scope.
Can an employee be penalised personally under the AI Act? Not as a deployer: the legal person remains the deployer for staff acting under its instructions and control. Consequences of individual misconduct fall under employment law and, where relevant, criminal law, not the regulation.
What are the penalties for breaching Article 50? Fines can reach 15 million euros or 3 % of total worldwide annual turnover, whichever is higher. The Commission notes that proportionality can be taken into account for SMEs and small mid-cap companies. Details in AI Act penalties.
Is a free tool outside the scope of the AI Act? No. The regulation reasons by role and by use, never by price. A free tool used professionally makes the organisation a deployer exactly as a business subscription would.
Who enforces these rules? Enforcement rests mainly with national market surveillance authorities. The EU AI Office has a limited role, reserved in particular for systems built on general-purpose models where the same entity supplies both model and system.
Do we have to redo compliance if we switch tools? The policy and the inventory need updating, but the reasoning holds. That is the argument for organising your rules around uses rather than around tool brands.
We work at the point where most SMEs and non-profits stall: turning a European regulation into rules that non-lawyers can actually apply. In practice, an inventory of the tools genuinely in use, a usage policy that decides cases rather than states principles, and user training that satisfies the Article 4 obligation.
GrowthPerf holds Qualiopi certification, which opens funding through your French OPCO. Our AI for business and operational AI for SMEs programmes build the compliance component in rather than treating it separately.
To find out where you stand, book a free 30-minute AI audit. You leave with the list of your risky uses and the policy to write first.