Questions and answers on AI rules
The questions companies ask most — answered briefly, with the rule behind each answer.
Basics · ChatGPT, Copilot and other tools at work · AI literacy and training · Personal data and GDPR · Customers, chatbots and content · Employees and decisions about people · Developers and AI products · Supervision in Slovenia
Basics
Does the AI Act apply to my small company?
Yes, if you use AI at work — but for most small companies only a few rules matter: AI literacy of staff, no prohibited practices and, if you have a chatbot or publish AI content, transparency. SMEs get lower fine caps and simpler documentation.
What is an “AI system” — is our Excel macro AI?
An AI system infers from inputs how to generate outputs (predictions, content, recommendations, decisions) with some autonomy. Software that only follows rules written by people — a macro, a formula, a classic if-then program — is generally not AI. The Commission’s guidelines of 6 Feb 2025 give examples.
What already applies and what comes later?
Already: bans and AI literacy (Feb 2025), general-purpose model rules (Aug 2025), transparency for chatbots and deepfakes (Aug 2026). Coming: new bans on nudify apps (Dec 2026), high-risk rules (Dec 2027 and Aug 2028). See our master timeline.
Was the AI Act postponed?
Only partly. The Digital Omnibus (Regulation (EU) 2026/1744, in force 27 Jul 2026) postponed high-risk rules to Dec 2027 and Aug 2028. Bans, AI literacy, transparency and the general-purpose model rules were not postponed.
Are we a provider or a deployer?
If you use an AI tool in your work, you are a deployer. If you develop AI or sell it under your name — including rebranding someone else’s high-risk AI or changing its purpose into a high-risk one — you are a provider, with many more duties.
Does the AI Act apply to companies outside the EU?
Yes, if they place AI on the EU market or its output is used in the EU. Non-EU providers of high-risk AI and general-purpose models need an authorised representative in the EU.
ChatGPT, Copilot and other tools at work
May employees use the free version of ChatGPT?
For general tasks without personal or confidential data, yes. For client, employee or business data, use a business plan with a data processing agreement where your data is not used for training — or remove personal data first. Set this in your AI policy.
Is Microsoft 365 Copilot GDPR-compliant?
Copilot for business runs under Microsoft’s data processing terms and the EU Data Boundary, and does not train on your data. Compliance still depends on you: permissions in SharePoint (Copilot sees what the user sees), a legal basis and staff rules. See our comparison of business plans.
Do we need a written AI policy?
It is not explicitly required by law, but it is the simplest way to show AI literacy measures, GDPR accountability and to protect trade secrets. One page is enough for most companies — use our generator.
What is “shadow AI”?
AI tools employees use for work on their own, without approval — often free personal accounts. It is the most common source of data leaks. A register of approved tools and a clear policy reduce it.
Who is liable if AI makes a mistake in our work?
Your company, towards your clients — as for any tool. AI providers usually limit their liability in their terms. That is why a person should check AI output before it reaches customers.
AI literacy and training
Is AI literacy training mandatory?
The AI Act requires measures that support AI literacy of staff who use AI (Art. 4, an obligation of effort since the 2026 Omnibus). Training is the most common measure; the form is up to you.
Do we need certificates?
No. The Commission says an internal record is enough. Our free course produces a one-page certificate you can keep in the record.
Who must be trained?
Staff and others acting on your behalf (e.g. contractors) who operate or use AI systems. The depth depends on the risk: more for people using AI in HR or customer decisions.
Is there a fine for missing AI literacy?
The AI Act does not set a specific fine for Art. 4, but authorities supervise it from 3 Aug 2026 and missing literacy counts when other breaches or damage occur.
Personal data and GDPR
May we put customers’ personal data into AI?
Only with a legal basis, for a compatible purpose, with a data processing agreement and appropriate security — and ideally only as much as needed. Pseudonymising first (e.g. with Clean before AI) often solves the problem.
Do we need a DPIA for AI?
When AI processing is likely to result in high risk — systematic evaluation or profiling of people, monitoring of employees, large-scale sensitive data, new technology with people’s data. The Information Commissioner expects a documented DPIA for such uses.
Are the GDPR changes from the Digital Omnibus already in force?
No. Only the AI part of the Omnibus is law. The GDPR, cookie and Data Act changes are still a proposal under negotiation (September 2026).
Is it allowed to use US AI providers?
Yes, with the EU–US Data Privacy Framework (if the provider is certified) or standard contractual clauses, and ideally EU data residency. Check this in the DPA.
May we train our own AI on customer data?
Possibly on legitimate interest, if you pass the three-step test, inform customers and allow objections (EDPB Opinion 28/2024). Anonymised data is safest. Sensitive data needs an explicit exception.
Customers, chatbots and content
What must a chatbot say?
That the person is interacting with AI, at the latest at the first interaction, unless obvious. A short sentence is enough; offering a human contact is good practice. Use our notice generator.
Must every AI image be labelled?
Under the AI Act, deployers must label deepfakes — realistic content resembling real people, places or events. Obviously artistic or fictional images need only a light disclosure. Slovenian media must label all AI content (ZMed-1).
What about AI-written blog posts and newsletters?
Marketing texts need no AI Act label. Texts informing the public on matters of public interest must be labelled unless a person reviewed them editorially. Media under ZMed-1 must label AI content.
Are we bound by what our chatbot says?
Generally yes — it speaks for your company. A Canadian tribunal held Air Canada bound by its chatbot’s wrong refund information (2024). Limit the bot to verified content and test it.
Can we use AI voices or faces of real people?
Only with their consent (personality rights, GDPR) and with a deepfake label. Creating intimate images of real people without consent will be prohibited from 2 Dec 2026 and is already a crime in many cases.
Employees and decisions about people
May we use AI in recruitment?
Yes, but screening and ranking candidates is high-risk (from 2 Dec 2027), GDPR Art. 22 applies now, and emotion analysis in interviews is prohibited. Let a person decide and tell candidates.
May we monitor employees with AI?
Only proportionately, for a legitimate purpose, announced in advance, after consulting workers’ representatives and usually with a DPIA. Emotion recognition is prohibited; performance evaluation with AI is high-risk.
Must we tell the works council about AI?
Yes when introducing technology that affects work organisation or monitoring (ZSDU, ZDR-1); the AI Act additionally requires informing workers before high-risk AI is used at the workplace.
What is a fundamental rights impact assessment?
An assessment of how a high-risk AI system may affect people’s rights (discrimination, privacy, access to services), who is affected and what safeguards exist. Required for public bodies, providers of public services, credit scoring and life/health insurance pricing — from Dec 2027. It can build on a GDPR DPIA.
Developers and AI products
We build an app on top of the OpenAI or Anthropic API — what are we?
You are the provider of your AI system; they are providers of the general-purpose model. Your duties depend on your system’s risk: transparency for chatbots and generated content, full requirements if your use is high-risk.
Does the Cyber Resilience Act apply to our software?
If you sell software or devices with digital elements on the EU market, yes: vulnerability reporting since 11 Sep 2026, all requirements from 11 Dec 2027. Pure SaaS is mostly covered by NIS2 instead; free open source outside commercial activity is exempt.
Are we liable for damage caused by our AI?
Under the new Product Liability Directive (products placed on the market after 9 Dec 2026) software and AI are products: manufacturers can be liable without fault for injury, property damage and data loss. The separate AI Liability Directive was withdrawn.
Who owns content created with AI?
Copyright protects human creativity. Purely AI-generated content is generally not protected; content with substantial human creative input can be. Check the AI tool’s terms for commercial use.
Supervision in Slovenia
Who supervises AI in Slovenia?
Under ZIUDHPUI: AKOS (single point of contact and market surveillance), the Information Commissioner (prohibited practices, biometrics and several high-risk areas, plus GDPR), the Bank of Slovenia (credit), the Insurance Supervision Agency and the Market Inspectorate.
Where can we ask for advice?
AKOS as the single point of contact, the Information Commissioner for data protection, the EU AI Act Service Desk, and for practical support the digital innovation hubs (DIH Slovenia, EDIH) and the Chamber of Commerce.
What is the AI regulatory sandbox?
A controlled environment where companies develop and test AI with guidance from the regulator. AKOS is setting up the Slovenian sandbox; the EU deadline is now 2 Aug 2027. Access is free for SMEs and start-ups.
How high are the fines?
AI Act: up to €35 million or 7% of turnover for prohibited practices, €15 million or 3% for other breaches, €7.5 million or 1% for false information; SMEs and small mid-caps pay the lower amount. GDPR: up to €20 million or 4%. Authorities can also issue warnings and non-monetary measures.
Is there public funding for AI projects?
Yes — calls for digitalisation and AI adoption (Slovenian Enterprise Fund, ministries, EU programmes), free EDIH services for SMEs, and access to computing and expertise through the Slovenian AI Factory (SLAIF). Check the Business Portal for current calls.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.