Home › Blog › SME Guide
SME Guide

EU AI Act Compliance Checklist for SMEs: 7 Steps to Get Ready

By PROGEAT · 7 min read

The EU AI Act is often discussed in the context of large technology companies and AI developers. But the Regulation applies to any organisation — including small and medium-sized enterprises — that uses, deploys, or places on the market AI systems affecting people in the EU. If you use AI in your hiring process, customer service, credit decisions, or content production, you are likely in scope.

The good news: the EU AI Act is proportionate. The obligations scale with the risk level of your AI. A chatbot carrying a disclosure label is very different from a medical diagnosis tool requiring a conformity assessment. This checklist helps SMEs identify where they stand and what to prioritise.

Your two key dates: 2 August 2026 — transparency obligations (Article 50) for chatbots, AI-generated content, and emotion recognition. 2 December 2027 — full obligations for high-risk AI systems (Annex III). Both deadlines apply to deployers, not just developers.

The 7-Step EU AI Act Checklist for SMEs

1. Build Your AI Inventory

You cannot manage what you have not mapped. Start by listing every AI-powered tool your organisation uses — including SaaS products and third-party services where AI is a feature, not the headline.

For each tool, record: the vendor, what the AI does, who it affects, and whether the AI makes or informs decisions about people.

2. Classify Each System by Risk Level

The EU AI Act defines four risk tiers. Apply them to each system in your inventory:

3. Act on August 2026 Transparency Obligations Now

If any of your systems fall under "limited risk", you need to add disclosures before August 2026. This is the quick win — and the most immediate legal exposure for most SMEs.

4. Review Your Vendor Contracts

Most SMEs do not build AI — they buy it. This does not remove your compliance obligations. As a deployer, you are responsible for ensuring the systems you use meet the AI Act's requirements.

5. Set Up a Basic Documentation System

Even for low-risk systems, documentation is good practice and demonstrates good faith to regulators. For high-risk systems, it is mandatory. Start simple:

6. Designate an AI Compliance Owner

The EU AI Act does not require a dedicated AI officer for most SMEs, but someone needs to own compliance. In practice, this is often the DPO (if you have one), a legal or compliance function, or a senior manager with oversight of technology decisions.

Their responsibilities should include: maintaining the AI inventory, monitoring regulatory updates (the AI Act is still evolving through delegated acts and guidelines), and liaising with vendors and external advisors.

7. Plan for High-Risk Compliance (if applicable)

If any of your systems qualify as high-risk, you need a structured compliance programme. Do not wait until 2027. The main workstreams are:

Each workstream typically takes 2–4 months. Start with a gap assessment to understand where you are versus where you need to be.

Your Compliance Timeline at a Glance

DateWhat you needWho it affects
NowAI inventory + risk classificationAll organisations using AI
2 Aug 2026Transparency disclosures in placeChatbots, AI content, emotion recognition
2 Dec 2026Synthetic content labelling + nudifier banMedia, marketing, AI content platforms
2 Dec 2027Full high-risk AI complianceRecruitment, credit, education, law enforcement…
2 Aug 2028High-risk AI in regulated productsMedical devices, machinery, vehicles…

SME-Specific Provisions in the AI Act

The AI Act includes several provisions designed to reduce the burden on smaller organisations:

These provisions exist, but they do not reduce the substantive compliance obligations for high-risk AI. They reduce cost and friction, not requirements.

A note on GDPR overlap: Many EU AI Act obligations — particularly around data governance, documentation, and individual rights — overlap with GDPR. If you have a functioning GDPR compliance programme, you have a head start. Your DPO and existing data processing records are a valuable foundation for AI Act compliance.

Not sure where you stand?

Our free assessment tool maps your AI systems to the relevant EU AI Act obligations in minutes.

Start free assessment
← Back to all articles