Why “we only use ChatGPT” is not a compliance strategy
21 May 2026 · 6 min read

There is a sentence I hear a lot from small teams when the EU AI Act comes up. It goes something like this: "We don't really need to worry about that. We only use ChatGPT." Sometimes it is Copilot, or Gemini, or a translation tool baked into an app they already pay for. The reassurance underneath is always the same: our stack is small, our tools are famous, and famous tools are surely someone else's problem to worry about.
I understand the instinct. When a regulation lands, the natural hope is that you fall outside it. But "we only use ChatGPT" is a description of your tooling, not a compliance position. It answers a question the AI Act never actually asks. Let me explain why, and then, because this is the good news, let me show you how little work it usually takes to put the matter to rest for a low-risk team.
The EU AI Act, formally Regulation (EU) 2024/1689, is built around roles and risk, not brand names. It does not keep a list of approved or exempt products. It asks two questions instead. First, what is your role: are you a provider who builds an AI system and puts it on the market, or a deployer who uses one under your own authority in a professional setting? Almost every small studio, agency or SaaS team is a deployer. Second, what is the risk of the way you are using the system: prohibited, high-risk, limited or minimal?
Notice that neither question has anything to do with how many tools you run or how well known they are. A two-person agency using one chatbot and a fifty-person company running a dozen models are judged by the same framework. The size of your stack changes how much work you have to do. It does not change whether the Act applies to you at all.
Here is the part that catches people out. The AI literacy duty in Article 4 has applied since 2 February 2025. It says that providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and anyone operating or using AI on their behalf.
Read that again and look for the escape hatch. There is a threshold for company size: there is none. There is a carve-out for minimal-risk tools: there is none. Article 4 applies regardless of how big you are and regardless of which risk tier your tools sit in. If your team uses AI in its work, the literacy duty is live for you today.
The duty is proportionate, which is genuinely reassuring, and I will come back to that. But proportionate is not the same as absent. A duty that scales down to something small is still a duty you have to meet.
The most common version of the argument is subtler than "the Act doesn't apply." It is: "our people already know how to use ChatGPT, so surely we are literate enough." And they probably are competent users. But Article 4 is not satisfied by competence that exists only in people's heads. The idea behind it is that your team understands enough to use AI responsibly and to spot its risks, and that you can show a reasonable, role-appropriate effort to get them there.
"We use common tools" tells a regulator, a client or an insurer nothing about whether your staff know that a model can be confidently wrong, that customer data pasted into a prompt may leave your control, or that AI output going to the public sometimes has to be labelled. Familiarity with a product is not the same as understanding its risks. And crucially, none of it is legible from the outside. Literacy you cannot point to is, for practical purposes, literacy you cannot rely on when someone asks.
The quiet reframe: Article 4 is less about how skilled your team is and more about whether you can show a deliberate, sensible effort to make them AI-aware. Skill lives in people's heads. Evidence lives in a record. The Act rewards the second one.
The other flaw in "we only use ChatGPT" is that it treats the tool as the source of risk. It is not. The use is. The same chatbot can sit in three different risk tiers depending on what you point it at, and a minimal-risk tool can quietly slide into duties the moment the task changes.
A few everyday examples of how a friendly general-purpose assistant stops being minimal-risk:
None of this means ChatGPT is dangerous or that you should stop using it. It means the risk tier is not a property of the logo on the tab. It is a property of what your team decides to do with it on a Tuesday afternoon, which is exactly why literacy, and a policy that draws a few lines, matters even for a modest stack.
It helps to see where we are. The Act entered into force on 1 August 2024 and applies in phases. The prohibited practices and the Article 4 literacy duty have applied since 2 February 2025. The rules for general-purpose AI models, the governance framework and the penalty provisions applied from 2 August 2025. The transparency duties in Article 50, such as telling people they are talking to a chatbot and labelling AI-generated or synthetic content, apply from 2 August 2026, which is the date most small businesses should have in mind. The heavier high-risk obligations in Annex III, for both deployers and providers, were pushed back from that date to 2 December 2027 by the 2026 Digital Omnibus, so they land later than the original timeline suggested.
Enforcement is national. In the Netherlands the Autoriteit Persoonsgegevens has taken a coordinating role for algorithm and AI supervision, alongside the RDI, and has signalled a focus on transparency and prohibited uses. In Germany there is not yet a single federal AI authority, though the Bundesnetzagentur is widely expected to take a central coordinating role, with data-protection authorities involved in the meantime. The point is not to alarm you with any specific action, there is no need to invent one. The point is that the duties are live, the authorities exist, and "we only use ChatGPT" is not the answer you want to be giving when someone reasonable asks how you handle AI.
Here is the reassuring turn, and I mean it. If your stack really is low-risk, a few everyday assistants and nothing that screens people or makes automated decisions about them, the work in front of you is small and finite. It is not a legal project. It is an afternoon of tidying, done once and kept current. Concretely:
That is the whole shape of it for a genuinely low-risk team. Not a compliance department, four modest artefacts kept honest. This is the model Klaar is built around, turning a small, sensible effort into a dated bundle you can hand to a client, an insurer or a regulator without scrambling. But the tools are secondary. The mindset is the thing: the size of your stack was never the question, and "we only use ChatGPT" was never going to be the answer.
Use whatever tools serve you. Use one if one is all you need. Just do not mistake a short toolset for a finished obligation. The literacy duty is here now, it is proportionate, and for a low-risk team it asks for a course, a policy, an inventory and a date. That is a good afternoon's work, and it is a far better sentence to be able to say than the one we started with.
Klaar walks you through inventory, training, policy and the dated evidence.