EU AI Act Approved: What It Means for AI in Sales and Support
On 13 March 2024 the European Parliament approved the Artificial Intelligence Act. If you run a small firm that uses AI writing assistants and chatbots in sales and support, here is what it means in practice: transparency and good housekeeping. Not a ban. That is the short version of the EU AI Act for small business owners who saw the headlines and wondered whether their team has to change anything. And one caveat straight away: the law has passed Parliament but still awaits final checks and Council endorsement, so it is not yet in force. What follows is a plain-language explainer with a checklist, not legal advice.
Table of Contents
AI Act explained: what did Parliament actually approve?
A binding EU law. It sets rules for artificial intelligence according to how much harm a system can cause. In Parliament’s announcement of the vote, the co-rapporteurs describe its goals as reducing risks, combating discrimination, bringing transparency and keeping human beings in control of the technology. They also call it a starting point. The real work, they say, is now putting the text into practice.
One detail in that release is worth a second look if you run a company. An AI Office will be set up to support businesses in complying with the rules before they enter into force. So help with interpretation is planned. It just does not exist yet.
AI Act timeline: what is the status in March 2024?
Approved by Parliament, pending final checks and formal Council endorsement. Not published, not in force. Until those steps are done, nothing in it binds your company.
And once it does take effect? Obligations will apply in stages instead of all at once, so there is time to prepare. I would still start early. An inventory of the tools your staff use takes little effort today. Try reconstructing it later, after people have changed roles and subscriptions have multiplied, and it gets much harder.
How does the risk-based approach work in plain words?
Simple rule: the higher the potential harm to people, the stricter the rules. The law sorts AI into tiers:
- Unacceptable practices - uses considered so harmful that they are banned outright.
- High-risk systems - AI that can seriously affect people’s lives or rights, allowed only under strict requirements.
- Limited-risk systems - tools that mainly carry transparency duties, such as telling people they are dealing with AI.
- Minimal-risk tools - everyday software that faces no new obligations.
Who carries the weight? Mainly those who build AI systems and place them on the market. Companies that only use such products have lighter duties. Most small firms are in exactly that position.
EU AI Act for small business: where do writing assistants, chatbots and lead scoring fall?
Typical sales and support uses are likely to sit in the minimal or limited-risk tiers. The text is still being finalised, though, so treat the list below as orientation and run anything unusual past an adviser:
- AI writing help for emails and replies - likely minimal risk, since a person reads, edits and owns the message before it goes out.
- Customer-facing chatbots - likely limited risk, with a duty to disclose that the customer is talking to a machine.
- Lead scoring - likely low risk when it simply ranks B2B prospects for follow-up, but worth a closer look if a score affects access to essential services or drives decisions about individuals.
So what is the honest answer to “is my chatbot high-risk under the AI Act”? Probably no, as long as it answers questions and does not decide anything important about a person. Forecasting follows the same logic: using predictive analytics in CRM to prioritise deals is one thing. Letting software decide who gets a contract or credit is a very different one.
AI chatbots and the AI Act: what do the transparency obligations mean for customer service?
People should know when they are talking to a machine and not a person. That is the heart of the AI transparency obligations, and it boils down to a few simple AI in customer service rules:
- Label the chatbot clearly at the start of every conversation.
- Offer an easy route to a human agent.
- Do not present AI-drafted replies as personally written when that would mislead the recipient.
Then there is the problem of wrong or invented answers. Human review of customer-facing output remains the simplest safeguard against them. Language models can sound confident while being mistaken about prices, terms or deadlines (and they rarely flag it themselves). Your company answers for the result, not the tool. Teams already relying on AI in customer interactions should make that check a fixed step. Not an optional one.
What should a small company do now? A practical checklist
Start with an inventory of AI tools and the data fed into them. Then set simple rules for review and disclosure. None of the steps below needs a lawyer or a budget:
- List every AI tool used in sales and support, including free ones staff signed up for themselves.
- Note who uses each one and on what data.
- Decide which customer data must never be pasted into external tools.
- Require human review of anything sent to customers.
- Tell customers when a chatbot is answering.
- Ask vendors how they plan to meet the new rules.
- Check edge cases with a legal adviser.
The second step gets a lot easier when you know where customer information lives. If contact and ticket history is kept in one system, for example a CRM such as EpicCRM hosted on EU servers with roles and permissions, you can see who has access to what and spot where data might leak into outside tools. While you are at it, review your CRM security best practices too. That closes the most common gaps.
So for now, the EU AI Act for small business comes down to three habits: be transparent with customers, keep a human responsible for what goes out, and maintain a written list of the tools in use. Pick them up early and there will be little left to fix when the obligations begin to apply.
FAQ
Is the EU AI Act already in force?
No. In March 2024 it has been approved by Parliament and still awaits final checks and formal endorsement by the Council. Only after publication will it enter into force, and even then its obligations will apply in stages.
Does a small business have to stop using AI chatbots?
No. The expected duty is to make clear that the customer is talking to AI and to keep a human reachable. A visible label at the start of the chat plus a simple handover option covers the core of it.
Do AI writing assistants used by sales staff count as high-risk?
Unlikely, at least for ordinary drafting of emails and replies. A person should still review the output before sending, and sensitive customer data should stay out of prompts. But if a tool begins making decisions about individuals instead of suggesting wording, ask an adviser to look at it.



