The 4 AI Documents Every Small Business Needed Before August 2026 (EU AI Act, FTC, and Your Clients)
The EU AI Act’s first enforcement deadline passed in February. The August 2026 deadline is here. If your business uses AI tools and you work with EU clients — or any clients — here is what you actually need.
If you use AI tools in your business — ChatGPT for client deliverables, an AI scheduler, AI-written copy you publish under your name — you likely have compliance obligations you haven’t thought through. Most small business owners haven’t, because the guidance is fragmented, often written for enterprise legal teams, and the consequences feel abstract.
They’re becoming less abstract. The EU AI Act’s general-purpose AI obligations kicked in for all businesses touching EU users on August 2, 2026. The FTC has been active on AI deception claims. Client contracts are increasingly asking suppliers to disclose AI use. The gap between “I use ChatGPT sometimes” and “I have documented how we use AI” is closing — and the consequences for the gap are real.
Here are the four documents that address this honestly for a small business.
Document 1: Employee (and contractor) AI Acceptable Use Policy
If anyone on your team uses AI tools — including you and any contractors — you need a written policy that defines what is and isn’t acceptable. This serves two purposes: it protects your business from misuse (a contractor who feeds confidential client data into a public AI tool is a real liability risk), and it demonstrates operational maturity to enterprise clients who ask “do you have an AI policy?”
What the policy needs to cover: which AI tools are approved for use, what data can and cannot be entered into AI systems (confidential client data, PII, proprietary information should be explicitly prohibited in public AI tools), disclosure requirements (when does AI use need to be disclosed to clients?), and review requirements (when must human review happen before AI output reaches a client or goes public?).
What to avoid: the policy that says “we don’t use AI” when you do. This creates legal exposure if clients ever audit. The honest policy — we use these specific tools, for these purposes, with these guardrails — is both safer and more credible.
Document 2: Client AI Disclosure Statement
Your clients are increasingly asking. Even when they don’t ask, disclosure protects you: if you deliver AI-assisted work without disclosure and a client later discovers it, the trust damage is far worse than the upfront disclosure would have been.
The disclosure statement doesn’t need to say “this was written by a robot.” It can say what’s true: “We use AI tools to assist with drafting, research, and analysis. All output is reviewed and approved by [your name/team] before delivery. Final responsibility for all work rests with us.” That statement is accurate, protects you legally, and most clients find it unremarkable.
The statement also helps with FTC compliance. The FTC’s 2023 AI guidance and ongoing enforcement actions focus on deception — making AI-generated content appear to be something it isn’t. A proactive disclosure policy makes deception claims much harder to sustain.
Document 3: AI Vendor Register
This is the document most small businesses don’t have and most enterprise procurement teams now require: a list of the AI tools you use, what data they access, where that data is processed, and what the vendor’s data retention and deletion policies are.
If you work with healthcare clients, legal clients, financial services clients, or any EU-based company, they may ask for this during onboarding or audit. Not having it is a disqualifier. Having a one-page register is not.
The register should include: tool name, vendor, primary use, what data types it processes, where data is stored (EU/US/other), the vendor’s data processing agreement (DPA) status, and your data retention setting (most tools allow you to opt out of training data use — verify this and document it).
Document 4: EU AI Act Compliance Statement (for businesses with EU exposure)
The EU AI Act distinguishes between AI system providers, AI system deployers, and end users. Most small businesses that use AI tools are deployers — they use AI systems built by others to perform tasks. Deployers have obligations under the Act that vary by risk category of the AI system.
For most small businesses using general-purpose AI (ChatGPT, Claude, Gemini for writing, research, customer service), the obligations are manageable: transparency to users when they interact with AI, basic fundamental rights impact consideration, and maintaining records of high-risk AI use. But the compliance statement — documenting which AI systems you use, for what purpose, and how you’ve assessed risk — is what demonstrates you took the obligations seriously.
The August 2, 2026 deadline specifically covers the transparency and governance obligations for GPAI (General-Purpose AI) model providers and deployers. If you’re providing a service to EU users using GPAI, the documentation requirements apply to you.
The practical approach: do this once, review annually
None of these documents needs to be a legal masterpiece. A clear, honest two-page document that describes what you actually do is better than a 20-page policy that nobody reads and your practices don’t match.
The sequence: start with the Employee Use Policy (even if it’s just you), add the Client Disclosure Statement (adapt it to your specific service type), build the Vendor Register (takes about an hour with your tools list), and write the EU AI Act Compliance Statement if you have EU exposure. Review annually or when you add significant new AI tools.
The purpose isn’t to protect yourself from regulators who are targeting small businesses — they’re not, yet. The purpose is to be a credible supplier to clients who are already asking, to have a documented position if anything goes wrong, and to think clearly about what AI tools touch what data in your business. That clarity is valuable independent of any regulation.
Want all 4 documents done — right — with editable templates?
The Small Business AI Policy & Disclosure Toolkit includes the 8-chapter guide plus all 4 editable documents (Employee Policy, Client Disclosure, Vendor Register, EU AI Act statement) written for the 2026 compliance landscape — instant PDF + editable download.
Get the AI Policy Toolkit →
Leave a Reply