The EU AI Act for small businesses in Croatia: what to do before 2027
What the EU AI Act means for a small business in Croatia: risk tiers, deadlines to 2028, duties for chatbots, CV screening and generated content, a checklist.

I work from Zagreb, and the AI Act comes up at almost every first meeting with a small business. The question usually sounds like this: "We have a chatbot on the website and we use ChatGPT for copy, should we be worried?" Short answer: for most small companies the obligations are manageable, but they are not zero, and the first deadline has already passed.
Up front: I am not a lawyer and this article is not legal advice. I write as an engineer who puts AI into business processes and needs to know where the lines are. A lawyer should confirm the obligations for your specific product.
What the AI Act is, in plain words
The AI Act is an EU regulation that applies directly in Croatia, with no separate national law needed. It does not ban AI and does not require a permit for every tool. Instead it sorts uses of AI into four risk tiers, and the obligations grow with the tier.
- Prohibited. Practices the EU considers unacceptable, such as manipulating people or social scoring. In practice this does not touch a small business.
- High risk. Systems that make decisions about people in sensitive areas: hiring, access to credit, education, public services. The heavy obligations sit here: documentation, human oversight, logs, data quality.
- Limited risk with transparency duties. Chatbots, generated content, deepfakes. The duty is mostly one thing: people must know they are dealing with AI or looking at generated content.
- Minimal risk. Spam filters, product recommendations in a web shop, spell checkers. No specific obligations.
Almost everything a small business uses lands in the third and fourth tiers. The problem is that a few popular uses that look harmless belong in the second.
The deadlines
A 2026 analysis of the EU labour market, which I return to below, cites three dates that matter.
- 012 August 2026: transparency obligations under Article 50. These are the rules for chatbots and generated content. That date has passed, so if your chatbot still does not say it is a chatbot, that is the first thing to fix.
- 02December 2027: obligations for high-risk systems. This covers CV screening tools, customer scoring and similar decisions about people.
- 03August 2028: AI embedded in products that already have their own regulation, for example medical devices or machinery.
For a small company in Zagreb or Split this means a year to sort out everything that touches decisions about people, and zero days for the chatbot.
What small businesses actually use, and which uses carry duties
When I build an inventory with a client, it almost always looks the same.
A chatbot on the website or in a messaging app. Duty: tell the user plainly that they are talking to AI. One sentence at the start of the conversation, not a paragraph buried in the terms of service. If a human can join the conversation, it should be clear when that happens.
Content generation: text, images, video. For ordinary marketing copy the duty is small. For content that shows real people or events that did not happen, in other words deepfakes, labelling is required. If you publish AI generated news or texts of public interest without human review, that needs a label too.
CV screening. This is the surprise for many. A tool that ranks candidates or rejects part of the applications falls into the high-risk category, even when it is used by an accounting firm with five employees. That is not a ban, but it does mean documentation, human oversight and a record of decisions by December 2027.
Customer scoring, creditworthiness assessment, insurance pricing decisions. Same category, high risk.
Internal tools: meeting summaries, translation, drafting proposals. Minimal risk, carry on.
Why you will not hire a compliance officer
In a 2026 analysis of 3,519 EU AI job postings, only 446 were governance and compliance roles. The other 3,004 were "builders": engineers and related roles. The ratio is roughly seven to one.
More telling: under 30% of those governance postings mention the AI Act at all. About half come from companies with 5,000 or more staff, and two thirds from financial services and IT consulting. Day rates for AI governance consultants run from 800 to 2,000 USD.
In other words, banks and large consultancies are building compliance teams. A ten-person company in Zagreb will not hire anyone with that title, and it does not need to. It needs a short list the owner or office manager can work through in an afternoon, plus a few hours of a lawyer's time for the doubtful items. I covered the wider picture in my review of the AI jobs market in 2026.
The five-point checklist
- 01Make an inventory of where you use AI. All of it: the chatbot, ChatGPT for copy, the CV screening tool, features inside your CRM and accounting software that decide something "on their own". Write down who uses it, for what, and which vendor is behind it.
- 02Classify each item by risk. Most will be minimal or limited. Anything that decides about people (employees, candidates, customers who get approved or rejected for something) gets flagged as high risk and goes to a lawyer.
- 03Add a disclosure to the chatbot. Now. One sentence at the start of the conversation and a clear way to reach a human.
- 04For decisions about people, keep logs and a human review step. Who saw the system's recommendation, who made the final decision, on what basis. Without this you will not be able to prove anything in December 2027.
- 05Document data sources and vendor terms. What the tool was trained on, where your data goes, what the vendor guarantees about compliance. For most SaaS tools this is in the contract nobody has read.
The first two points take the most time and cause the most mistakes, because AI hides in tools nobody calls AI.
Where an AI readiness audit fits
The AI readiness audit I offer, from 450 EUR, covers exactly steps one and two: an inventory of every place the company uses or plans to use AI, classification by risk and by usefulness, and a recommendation on what to adopt, what to fix and what to switch off. The output is a document you can hand to a lawyer, instead of paying a lawyer's hourly rate for the inventory. The services are described on the home page.
I will say it again because it matters: the audit is not a legal opinion. It tells you what you have and which category it most likely falls into. The final confirmation of obligations for a specific product comes from a lawyer.
FAQ about the AI Act for small businesses
Does the AI Act apply to a company with five employees?
Yes. The regulation makes no exception by company size, only by how AI is used. A small company with a chatbot has a transparency duty, and a small company using a CV screening tool has the obligations of a high-risk system. Check the specific obligations with a lawyer.
What do I need to do with my chatbot right now?
Add a clear notice that the user is talking to AI and offer a way to reach a human. The transparency obligations under Article 50 apply from 2 August 2026, so they are already in force.
We use ChatGPT for marketing copy. Is that a problem?
For ordinary copy, product descriptions and social media posts, no. Labelling is required for deepfake content and for AI generated texts of public interest published without human review.
Is automated CV screening banned?
It is not banned, but it falls into the high-risk category. That means documentation, human oversight and a record of decisions, with a December 2027 deadline. A company using it should check with a lawyer before that date.
Do I need to hire someone for AI Act compliance?
For a small business, very likely not. Of 3,519 EU AI postings, only 446 were governance roles, mostly at banks and large consultancies. An inventory, a classification and a few hours of a lawyer's time are enough.
If you want to know where your company stands, send me a short brief: what you use, what for, and who runs it. I will reply with a proposed audit scope and a price.
Keep reading
All articlesA RAG chatbot on your company knowledge base: what it is and when it pays off
RAG in plain language: which businesses benefit from a bot that answers from their documents, what to prepare, where projects fail, why a pilot takes two weeks.
ReadPrompt engineer is not a job anymore: which AI skills the market actually buys
Why the prompt engineer title dropped out of hiring plans, what it pays in the US and Russia, which skills the market buys instead and who to hire.
ReadWhat a Forward Deployed Engineer is and why a small business should care
Where the Forward Deployed Engineer role comes from, why postings grew 1,000%, what an FDE does on site and how a small business gets that work without hiring.
Read