AI Security, Privacy and Compliance

Does the EU AI Act Apply to a Business Using ChatGPT or Claude?

Last updated 22 July 2026 · 8 min read

Direct Answer

For an Australian business, the EU AI Act itself only applies if you have staff, customers, or users in the EU — otherwise it's not the law that governs your AI use at all. Australia doesn't have an equivalent binding AI-specific law: as of 2026, the government relies on existing laws (Privacy Act, Australian Consumer Law, Fair Work Act, and sector regulators like APRA, ASIC, and AHPRA) applied to AI use, supported by the National AI Centre's Guidance for AI Adoption and its six essential practices, rather than a standalone AI Act with binding risk tiers. Mandatory guardrails for high-risk AI were proposed in 2024 but the government did not proceed with a dedicated AI Act at the time of the December 2025 National AI Plan. If your business does have EU staff, customers, or users, the EU AI Act applies to you as a 'deployer' of AI systems even though you didn't build the tool — using ChatGPT, Claude, or Copilot doesn't exempt you, and what it requires depends on the risk tier the specific use falls into, from minimal-risk everyday drafting through to high-risk uses like AI-assisted hiring decisions.

Detailed Explanation

Australia's approach is different from the EU's, and it's the one that actually governs an Australian business by default. Rather than a single standalone AI-specific law with binding risk tiers, Australia currently relies on existing laws — the Privacy Act and APPs, the Australian Consumer Law, the Fair Work Act, and sector regulators like APRA, ASIC, and AHPRA — applied to AI use, supported by the National AI Centre's Guidance for AI Adoption (six essential practices covering accountability, risk management, transparency, and human oversight, which replaced the original Voluntary AI Safety Standard's 10 guardrails in October 2025). Mandatory guardrails for high-risk AI were proposed in 2024, but as of the government's December 2025 National AI Plan, Australia hadn't proceeded with a dedicated, binding AI Act — the practical baseline for most Australian businesses is voluntary best-practice guidance plus whatever existing sector law already applies to the specific use (hiring, credit, health, and so on), not a risk-tier compliance regime like the EU's.

The EU AI Act only becomes relevant if your business has an EU-facing angle — staff, customers, or users in the EU. If that doesn't describe your business, the rest of this page is background on a foreign framework rather than something that applies to you directly; the Guidance for AI Adoption's six essential practices are a reasonable practical substitute for thinking through the same governance questions (risk management, human oversight, transparency) without the EU's binding legal force.

For a business that does have EU staff, customers, or users, here's how the EU AI Act actually works. It's a risk-based regulation: it doesn't treat "using AI" as one single thing requiring one single set of obligations. Instead, it sorts AI use into tiers, and what you're required to do depends on which tier a specific use falls into — not on whether AI is involved at all.

Your business is a "deployer," not a "provider." The Act distinguishes between the company that builds and supplies an AI system (the "provider" — Anthropic, OpenAI, Microsoft, and so on) and the business that uses it in the course of its own operations (the "deployer" — most businesses reading this). Deployers have real, but generally lighter, obligations compared to providers, and those obligations scale with the risk tier of the specific use.

The risk tiers, in practice:

  • Unacceptable risk — a small set of practices the Act bans outright (certain forms of biometric categorisation, social scoring, manipulative techniques). Very few ordinary business uses fall here.
  • High-risk — specific, listed use cases carrying real obligations for both providers and deployers: risk management, human oversight, and record-keeping among them. The most relevant example for most businesses is using AI in employment decisions — CV screening, candidate ranking, or performance evaluation. Certain uses in credit scoring, insurance, and a handful of other regulated areas are also named.
  • Limited risk — use cases with a transparency obligation rather than heavy compliance machinery: the main example is a chatbot or AI system that interacts with people, where those people generally need to be told they're interacting with AI rather than a human, unless it's obvious from context. See do you have to tell customers they're talking to an AI chatbot, not a human for what that disclosure actually requires in practice, across chat, voice, and written channels, and how it compares to Australian consumer-law expectations.
  • Minimal risk — the large majority of everyday business AI use (drafting, summarising, internal research, coding assistance) — no specific obligations under the Act beyond general good practice.

Most of what's covered elsewhere on this site — using Claude for business tasks, internal drafting, research, document summarisation — sits in the minimal-risk tier. The obligations that actually bite are concentrated in a narrower set of higher-stakes use cases, most notably anything touching employment decisions.

How to Check Where Your Use Falls

  1. List what you're actually using AI for, specifically enough to categorise — "drafting customer emails" and "screening job applicants with AI" are very different from a risk-classification standpoint even if both technically "use AI."
  2. Check each use against the Act's high-risk list first. If nothing matches, you're very likely in the limited- or minimal-risk tier for that use.
  3. For a customer-facing chatbot or AI system that interacts with people directly, plan for the transparency requirement — disclosing that people are talking to AI, in the situations where that isn't already obvious.
  4. Flag anything touching hiring, performance management, or similar employment decisions for closer review — this is the highest-likelihood way an ordinary business ends up with real obligations under the Act, and is worth a specific conversation with legal counsel rather than a general policy. See how do you reduce bias and discrimination risk in AI-automated decisions about people for the practical mitigation techniques behind that closer review.
  5. Re-check periodically, and specifically around 2 August 2026. That date is when most of the remaining Act — including the bulk of the high-risk obligations most relevant to an ordinary business — becomes applicable, so it's a natural checkpoint to confirm your classification still holds rather than relying on an assessment done months earlier. The Act's provisions apply on a phased timeline extending through 2027, and guidance continues to develop — treat a risk classification done today as needing a revisit, not a permanent answer.

Things to Consider

  • This is a compliance question, not a technology question. The AI Act's obligations attach to what you're using AI to do, not to which vendor or model you've chosen — switching from ChatGPT to Claude or Copilot doesn't change your risk tier for the same use case.
  • The Act's provisions are phased in over time. Prohibitions and staff AI-literacy obligations started February 2025, general-purpose AI model rules started August 2025, and most of the rest — including the high-risk system obligations that matter most to an ordinary business — becomes applicable 2 August 2026 (safety-component high-risk systems embedded in regulated products get until August 2027). Practical guidance around several provisions is still developing as of mid-2026 — verify your specific obligations against the current official timeline rather than a static summary, including this one.
  • For a business with EU exposure, this sits alongside, not instead of, GDPR. The AI Act governs AI-specific risk categories and obligations; GDPR continues to govern the personal-data-processing side of using an AI tool, independently. See does GDPR apply to a business using AI tools for that separate set of obligations, and how it compares to the Privacy Act and APPs that apply to an Australian business regardless of EU exposure.
  • For a business with no EU exposure, the Guidance for AI Adoption is the closer Australian equivalent to think through. Its six essential practices cover much of the same ground as the EU AI Act's risk-tier thinking — governance, risk management, human oversight, transparency — without the binding legal force or the compliance deadlines.
  • A vendor's own AI Act compliance doesn't cover your deployer obligations. Anthropic, OpenAI, and Microsoft each carry their own provider-side obligations, but using a compliant tool doesn't automatically discharge your separate obligations as the business deploying it for a specific use — particularly for anything in the high-risk tier.
  • The Act also imposes an "AI literacy" obligation on staff who operate AI systems. Separately from risk-tier obligations, deployers must take measures ensuring their staff have a sufficient level of AI literacy — see how do you train employees to use AI tools safely for building that into an actual training program.

Common Mistakes

  • Assuming "we just use off-the-shelf AI tools, this doesn't apply to us." Deployer obligations attach to businesses using AI, not only to the companies building it — the size of your business or the fact that you didn't build the model doesn't exempt you.
  • Assuming the opposite — that any AI use triggers heavy compliance. This leads businesses to either avoid legitimate low-risk AI use out of unnecessary caution, or to spend compliance effort uniformly across all AI use instead of concentrating it where the actual risk (and actual obligation) sits.
  • Not specifically checking AI-assisted hiring or performance-review tools against the high-risk list. This is the single most common real exposure for an ordinary business — treat any AI involved in decisions about individual employees or candidates as needing a dedicated compliance check, not a general policy covering "AI use" broadly.
  • Treating a general AI usage policy as sufficient for a high-risk use case. See what should an employee AI usage policy include for the baseline everyday-use policy — a use case that falls into the Act's high-risk tier needs a specific compliance review beyond that general policy, not a substitute for one.

Frequently Asked Questions

Does the EU AI Act ever apply to an Australian business?
Yes, but only in a specific circumstance. The Act applies based on where the AI system's output is used, not where your business is headquartered — an Australian business that deploys AI systems affecting people located in the EU (customers, employees, applicants) can fall within scope alongside its Australian obligations. An Australian business with no EU staff, customers, or users generally isn't affected by the EU AI Act at all — its AI governance obligations come from existing Australian law and the Guidance for AI Adoption instead.
Is using ChatGPT or Claude for internal drafting and research high-risk?
No, in the large majority of cases. Drafting emails, summarising documents, researching a topic, or getting a first-pass answer to an internal question are not among the use cases the Act classifies as high-risk. High-risk classification is tied to specific, listed use cases (such as employment decisions, credit scoring, and certain safety-critical systems), not to which underlying model you're using.
What's the single most common way a small business ends up in a higher-risk category without realizing it?
Using AI to screen, rank, or make decisions about job applicants or employees — CV screening, automated shortlisting, or performance-evaluation scoring are explicitly named among the Act's high-risk use cases, which surprises businesses that think of this as 'just using AI to save time on hiring admin.'
What changes for a small business on 2 August 2026?
2 August 2026 is when most of the remaining Act becomes applicable, including the bulk of the high-risk system obligations (Annex III use cases such as employment decisions) and the transparency requirement for AI that interacts with people. If your business already checked its uses against the risk tiers above, nothing new is required on that date itself — but it's a reasonable prompt to re-run that check, since guidance and enforcement expectations tend to firm up around a major applicability date. Businesses embedding high-risk AI as a safety component in a regulated product (Annex I) get a longer runway, to 2 August 2027; that later date doesn't apply to the deployer scenarios most readers of this page are in.

References

Related Questions