Client data stays in-house
Dictations, emails and documents are processed on your computer, which takes the client data in chatbots problem out of everyday work.
The EU AI Act regulates how AI systems may be offered and used, and it applies to offices, law firms and practices that use ChatGPT, Copilot or a dictation assistant, not just to AI developers. This summary covers the timeline, the risk levels, AI literacy, deployer duties, fines and whether the EU AI Act applies to UK businesses. Last reviewed: September 2026.

In short: If your business uses AI, it is a “deployer”. Since 2 February 2025, deployers must support AI literacy among their staff and must not use prohibited practices. Since 2 August 2026, transparency duties apply too. Strict high-risk duties, for example for AI used in recruitment, only apply from 2 December 2027. The GDPR applies on top.
The EU AI Act is Regulation (EU) 2024/1689 of 13 June 2024. As an EU regulation, it applies directly in every member state. It sorts AI systems by risk: the greater the danger to health, safety and fundamental rights, the stricter the rules.
Most duties fall on providers, the companies that develop AI systems and place them on the market. Businesses that only use AI are deployers. Their duties are fewer but concrete, and they are the focus of this guide.
In July 2026 the EU amended the Act for the first time: Regulation (EU) 2026/1744, the Digital Omnibus on AI, has been in force since 27 July 2026. It postpones the high-risk rules and rewords the AI literacy duty, so many older summaries are out of date.
The EU AI Act entered into force on 1 August 2024 and applies in stages (Art. 113, as amended by Regulation (EU) 2026/1744):
The AI Act enters into force 20 days after publication in the Official Journal (Art. 113). Its obligations apply in stages.
The prohibited practices in Art. 5 and the AI literacy duty in Art. 4 apply, including to deployers.
Obligations for providers of models such as those behind ChatGPT or Gemini (Chapter V), the governance structure and the penalty rules (Art. 99).
Amending Regulation (EU) 2026/1744 postpones the high-risk rules and rewords Art. 4.
The transparency obligations in Art. 50 apply. According to the European Commission, national authorities enforce AI literacy from this date.
According to the Commission, the two new prohibitions added by the Omnibus take effect (see section 07). For AI systems already on the market before 2 August 2026, the four-month period for machine-readable marking under Art. 50(2) ends.
Models placed on the market before 2 August 2025 must comply (Art. 111(3)).
For example recruitment, promotion, creditworthiness, education. Originally 2 August 2026.
AI as a safety component in products such as lifts, toys or medical devices. Originally 2 August 2027.
Only the high-risk rules were postponed. AI literacy, the prohibitions and the transparency duties were not. Whether high-risk duties matter for you is covered in section 07.
It can. The UK has left the EU, but the AI Act reaches beyond EU borders. Under Art. 2(1) it applies to:
So a UK firm that sells AI-based software to EU customers, or uses AI whose results are used in the EU, for example to assess applicants for a role in Dublin, needs to look at the Act. A UK office that only uses AI for its own work in the UK is generally not covered.
The UK’s own approach: as of September 2026, the UK has no AI Act and no government AI bill before Parliament. Since the 2023 white paper “A pro-innovation approach to AI regulation”, existing regulators apply existing law to AI within their remits. For personal data that means the UK GDPR and the Data Protection Act 2018, enforced by the ICO, which publishes guidance on AI and data protection. The rules on automated decision-making were changed by the Data (Use and Access) Act 2025.
The European Commission describes four levels of risk:
| Level | Examples | Consequence |
|---|---|---|
| Unacceptable risk | Social scoring, emotion recognition in the workplace, exploiting vulnerabilities | Prohibited (Art. 5) |
| High risk | Recruitment, evaluating employees, creditworthiness, access to education (Annex III), AI in regulated products (Annex I) | Strict duties for providers, Art. 26 for deployers |
| Transparency risk | Chatbots, AI-generated images, deepfakes, emotion recognition outside the ban | Label and inform (Art. 50) |
| Minimal risk | Spell checkers, spam filters, dictation, writing assistants in the office | No specific duties, but AI literacy (Art. 4) |
Separately, the Act regulates general-purpose AI models (Art. 51 onwards), the large language models. Those duties fall on their providers, not on you as a user. Most office tools are minimal or transparency risk, but the classification depends on the use, not the tool. The same chatbot that drafts emails becomes high risk if it is used to shortlist job applicants.
Under Art. 3(4), a deployer is any natural or legal person, public authority, agency or other body using an AI system under its authority, except for personal, non-professional activity.
Be careful with your own changes: if you market a high-risk system under your own name, modify it substantially or change the purpose of an ordinary AI system so that it becomes high risk, Art. 25(1) makes you a provider with all the duties that come with it. An example is a general chatbot deliberately used to pre-screen job applications.
Article 4 is the duty that affects almost every business, because it applies to all deployers regardless of risk. Since the Omnibus, providers and deployers must “take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”, taking into account their knowledge, experience, education and the context.
Before, Article 4 required a “sufficient level” of AI literacy. It is now a duty to act rather than a guaranteed result, but it has not been removed. The European Commission’s questions and answers say:
Art. 99 sets no specific fine for Article 4, but authorities can enforce it. Useful AI literacy training for an office covers what AI can and cannot do, which tools are allowed, which data must not go in, how to check results and who to ask.
Some transparency duties fall on providers: chatbots must be recognisable as AI (para. 1) and generated content must be marked in a machine-readable way (para. 2). Deployers must act themselves when they:
The information must be clear at the latest at the first interaction (para. 5). An email you drafted with AI and read yourself does not need a label.
If you use a high-risk system, such as software that filters applications or evaluates staff, you must among other things:
Public bodies and some businesses, for example in credit scoring and life and health insurance, must also carry out a fundamental rights impact assessment (Art. 27).
Banned are, among others, AI systems that manipulate people subliminally or exploit vulnerabilities due to age, disability or social situation, social scoring, untargeted scraping of facial images from the internet or CCTV for facial recognition databases, and biometric categorisation by traits such as religion or sexual orientation.
For employers, Art. 5(1)(f) matters most: emotion recognition in the workplace and in education is banned, except for medical or safety reasons. Software that reads staff mood from voice or face during customer calls falls under it. The Omnibus adds two bans: AI that creates realistic intimate images of people without consent, and AI that creates child sexual abuse material.
The Act sets maximum amounts; member states lay down the details. The penalty rules have applied since 2 August 2025.
| Infringement | Maximum fine |
|---|---|
| Prohibited practices (Art. 5) | €35 million or 7% of total worldwide annual turnover for the preceding year, whichever is higher (Art. 99(3)) |
| Deployer duties (Art. 26), transparency (Art. 50) and other operator duties | €15 million or 3% of worldwide annual turnover (Art. 99(4)) |
| Incorrect, incomplete or misleading information to authorities | €7.5 million or 1% of worldwide annual turnover (Art. 99(5)) |
For small and medium-sized enterprises, including start-ups, the lower of the two amounts applies (Art. 99(6)). Authorities consider, among other things, the nature, gravity and duration of the infringement, intent or negligence and the size of the business. GDPR fines can come on top.
The AI Act does not replace data protection law. Art. 2(7) makes clear that the GDPR is unaffected. As soon as personal data goes into an AI tool, you still need:
Put simply: the AI Act asks whether and how an AI system may be used, the GDPR asks what happens to the data in it. In the UK, the UK GDPR plays that role. What to look for in a tool is explained in our guides on GDPR-compliant AI and whether ChatGPT is GDPR compliant.
In small businesses, compliance rarely fails on the legal text, but on everyday work:
These steps cover the duties that apply to most offices today:
SpeechToWork is an AI assistant that runs entirely on your own Windows computer: speech recognition and the language model work there, and dictations, emails, documents and recordings do not go to any provider. That mainly simplifies the data protection side: for your content there is no processor, no transfer to the US and no training on your data. The model does not change overnight, because it sits on your computer as a file. More in our guide to local AI.
To be honest: a local program does not take the AI Act off your hands. If your business in the EU uses SpeechToWork, it is still a deployer of an AI system. The AI literacy duty under Art. 4 applies all the same, the program belongs on your tool list, and if you used it for a high-risk task, that purpose would count. For everyday office work such as dictating, drafting, summarising and taking minutes, no further duties arise.
All statements were checked against these sources in September 2026:
Last reviewed: September 2026. This guide is not legal advice. Further Commission guidelines and the practice of national authorities may still change how the Act is interpreted.
Dictations, emails and documents are processed on your computer, which takes the client data in chatbots problem out of everyday work.
One program, a fixed model, no provider terms that change overnight. That makes classification and records easier.
Art. 4 applies to SpeechToWork too: your staff should know what the AI can do and when to check its results.
Speech recognition and the language model are installed on your PC and run there. What you dictate ends up in your program and nowhere else. How the data flow works.
Audio and text stay on your computer. There is no server listening in and no AI provider in the background.
No third party processes your dictations. So there is no data processing agreement to sign and no international transfer to assess.
Once installed, SpeechToWork works offline. Only the licence check needs a connection.
The EU AI Act is Regulation (EU) 2024/1689. It regulates AI systems in the EU according to risk: some practices are banned, high-risk AI faces strict duties, and chatbots and deepfakes must be transparent. It entered into force on 1 August 2024 and applies directly in every member state, in stages until 2028.
It can. Under Art. 2, it applies to providers placing AI on the EU market wherever they are based, and to providers and deployers outside the EU where the AI output is used in the EU. A UK business using AI only for its own work in the UK is generally not covered.
In force since 1 August 2024. Bans and AI literacy since 2 February 2025, rules for general-purpose AI models since 2 August 2025, transparency duties since 2 August 2026. After the Digital Omnibus, high-risk rules under Annex III apply from 2 December 2027 and for AI in regulated products from 2 August 2028.
Yes, if your business is covered. Article 4 requires deployers to take measures to support the AI literacy of their staff, since 2 February 2025. According to the European Commission, no certificate is needed and an internal record is enough. Training should fit the role and tools: capabilities, limits, allowed data and checking results.
Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for breaches of deployer or transparency duties, and up to €7.5 million or 1% for misleading information to authorities (Art. 99). For small and medium-sized enterprises, the lower of the two amounts applies.
Partly. Regulation (EU) 2026/1744, the Digital Omnibus, moved the high-risk rules under Annex III from 2 August 2026 to 2 December 2027, and those for AI in products to 2 August 2028. AI literacy, the bans and the transparency duties were not delayed. The AI literacy duty was reworded, not removed.
No. A business in the EU that uses a local assistant such as SpeechToWork for work is still a deployer and must support AI literacy. What gets simpler is data protection: content stays on your computer, with no processor and no international transfer. For everyday office work, no further AI Act duties arise.
SpeechToWork is about to launch. As soon as the first version is ready, you can download it here: one click, one file, no form.
Coming soonFor Windows 10/11 (64-bit). The download will be available here as soon as it is ready.
One installer for Windows, straight from our server.
A double click is all it takes. No administrator rights needed.
On first start: enter your name and business email, no payment method.
On first start, SpeechToWork downloads the language models once (4 to 6 GB). Already have a licence key? Enter it on first start. What is transferred in the process is explained in our privacy policy.