Quite possibly — but usually only the light-touch transparency duties, not the heavy “high-risk” regime. Being small doesn’t exempt you; what matters is your role and whether your users are in the EU.
The rules follow what you do. A provider builds an AI system and puts it out under their own name; a deployer simply uses one. Most small businesses are deployers, which brings at most the limited Article 50 transparency duties — not the heavy high-risk regime.
Using an off-the-shelf tool to write copy generally makes you a deployer — often with no duty at all, unless you’re running a customer-facing bot or publishing public-interest content. It does not pull you into the high-risk rules.
It can still apply. If your AI or its outputs reach people in the EU, you’re in scope — the same long-arm logic as the GDPR. (A business based in Portugal serving EU customers is squarely in.)
Building on a free or open model doesn’t switch off the Article 50 transparency duties.
Startups face the same duties. The concessions are lighter paperwork and proportionate enforcement — not exemption. If you build or rebrand AI as your own product, you may tip into being a provider, with heavier duties.
Not sure where you stand? The free checker tells you in two minutes which duties apply to you — no signup, no data collected.
Run the free 2-minute check →Other common questions