EU AI Act answers · ChatGPT at work
We use ChatGPT at work. Does the EU AI Act apply to us?
Yes, in almost every case. Using ChatGPT, Microsoft Copilot, Gemini or a similar tool at work makes your business a deployer under Regulation (EU) 2024/1689, and one duty already applies. Correct as of 3 August 2026, after Regulation (EU) 2026/1744, the Digital Omnibus on AI.
The Act reaches businesses established in the European Union, and businesses in third countries where the output of the AI system is intended for use in the Union. A deployer is a business that uses an AI system under its own authority, outside personal non-professional activity. Paying for a ChatGPT subscription that staff use for work is exactly that. The size of the business does not remove the duty.
ComplianceSME's free EU AI Act checker turns this into your own duty card in one minute, with article citations and dates. No account, no email address.
The duty that already applies
Article 4 has applied since 2 February 2025. It requires providers and deployers to take measures supporting the AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf. In plain words: the people using ChatGPT for your business need training appropriate to how they use it, and you need to be able to show the measures you took.
Article 5 has also applied since 2 February 2025. It prohibits a defined set of practices outright, including AI systems that infer the emotions of a person in the workplace or in education institutions except for medical or safety reasons. Do not point an AI tool at your staff's feelings.
The obligations from 2 August 2026
2 August 2026 is the general date of application under Article 113. For a business that uses AI tools, the practical content is Article 50, the transparency duties. If your AI talks to customers, people must be informed they are interacting with an AI system unless that is obvious, under Article 50(1). If you publish deep fake image, audio or video content, you disclose that it was artificially generated or manipulated, under Article 50(4). If you deploy emotion recognition or biometric categorisation, you inform the people exposed to it, under Article 50(3).
The information is given clearly, at the latest at the first interaction or exposure, under Article 50(5).
Duties that do not apply to ordinary ChatGPT use
Ordinary office use for drafting, research and internal tasks does not sit in the high-risk chapter. The high-risk requirements in Chapter III apply from 2 December 2027 for systems classified under Article 6(2) and Annex III, and from 2 August 2028 for systems classified under Article 6(1) and Annex I. Guidance published before 27 July 2026 often states 2 August 2026 for high-risk duties. That date is no longer correct: Regulation (EU) 2026/1744 rewrote Article 113.
One warning on roles. Article 25(1) turns a deployer into a provider where it puts its own name or trademark on a high-risk system, substantially modifies one, or changes an intended purpose so a system becomes high-risk. Rebranding an AI tool as your own product changes your duties entirely.
Actions for this week
- Run the free checker. One minute, and you hold your duty card with citations.
- List the AI tools in use, including features switched on inside software you already pay for.
- Put the Article 4 training in place and keep the record. The first module of the ComplianceSME EU AI Act system is that training.
- If any tool talks to customers or generates published content, prepare the Article 50 disclosures now.
The whole Act, one system
The EU AI Act compliance system, B-001, carries the whole of Regulation (EU) 2024/1689 in one run, in your own Claude account. It interviews you one question at a time and produces your compliance documentation with article citations. £3,000, one purchase.
See the EU AI Act systemMore answers: The Article 4 AI literacy requirement · The current deadlines · The penalties