The EU AI Act is often discussed in the context of large technology companies and AI developers. But the Regulation applies to any organisation — including small and medium-sized enterprises — that uses, deploys, or places on the market AI systems affecting people in the EU. If you use AI in your hiring process, customer service, credit decisions, or content production, you are likely in scope.
The good news: the EU AI Act is proportionate. The obligations scale with the risk level of your AI. A chatbot carrying a disclosure label is very different from a medical diagnosis tool requiring a conformity assessment. This checklist helps SMEs identify where they stand and what to prioritise.
Your two key dates: 2 August 2026 — transparency obligations (Article 50) for chatbots, AI-generated content, and emotion recognition. 2 December 2027 — full obligations for high-risk AI systems (Annex III). Both deadlines apply to deployers, not just developers.
The 7-Step EU AI Act Checklist for SMEs
1. Build Your AI Inventory
You cannot manage what you have not mapped. Start by listing every AI-powered tool your organisation uses — including SaaS products and third-party services where AI is a feature, not the headline.
- CRM tools with AI lead scoring
- Recruitment platforms with CV screening or interview analysis
- Customer service chatbots
- AI writing assistants used for external content
- Analytics tools that make automated recommendations
- Any tool that processes biometric data (photos, voice, video)
For each tool, record: the vendor, what the AI does, who it affects, and whether the AI makes or informs decisions about people.
2. Classify Each System by Risk Level
The EU AI Act defines four risk tiers. Apply them to each system in your inventory:
- Unacceptable risk — banned outright (social scoring, real-time biometric surveillance in public, subliminal manipulation). If you use any of these, stop immediately.
- High risk — Annex III systems (recruitment, credit, education, law enforcement, critical infrastructure, biometrics, border control, justice). Full compliance programme required by December 2027.
- Limited risk — chatbots, deepfakes, emotion recognition. Transparency disclosure required by August 2026.
- Minimal risk — everything else (spam filters, AI recommendations, most productivity tools). No specific obligations, but best practice documentation is advisable.
3. Act on August 2026 Transparency Obligations Now
If any of your systems fall under "limited risk", you need to add disclosures before August 2026. This is the quick win — and the most immediate legal exposure for most SMEs.
- Add "You are talking to an AI" notices at the start of chatbot interactions
- Label AI-generated images, videos, and audio content
- Inform users when emotion recognition or biometric categorisation is in use
- Review your SaaS vendor contracts: who is responsible for disclosures when using a third-party AI tool?
4. Review Your Vendor Contracts
Most SMEs do not build AI — they buy it. This does not remove your compliance obligations. As a deployer, you are responsible for ensuring the systems you use meet the AI Act's requirements.
- Ask vendors for their EU AI Act compliance roadmap
- Check whether high-risk AI tools have technical documentation and conformity assessments
- Ensure contracts clearly allocate responsibility for disclosures and incident reporting
- Be wary of vendors who cannot answer basic questions about their AI Act compliance status
5. Set Up a Basic Documentation System
Even for low-risk systems, documentation is good practice and demonstrates good faith to regulators. For high-risk systems, it is mandatory. Start simple:
- A register of AI systems (your inventory from Step 1, formalised)
- The purpose, inputs, and outputs of each system
- Who is responsible for each system internally
- How and when each system was reviewed
- Any incidents, errors, or unexpected outputs
6. Designate an AI Compliance Owner
The EU AI Act does not require a dedicated AI officer for most SMEs, but someone needs to own compliance. In practice, this is often the DPO (if you have one), a legal or compliance function, or a senior manager with oversight of technology decisions.
Their responsibilities should include: maintaining the AI inventory, monitoring regulatory updates (the AI Act is still evolving through delegated acts and guidelines), and liaising with vendors and external advisors.
7. Plan for High-Risk Compliance (if applicable)
If any of your systems qualify as high-risk, you need a structured compliance programme. Do not wait until 2027. The main workstreams are:
- Risk management system — identify and document risks across the AI lifecycle
- Data governance — audit training data for bias, gaps, and relevance
- Technical documentation — record how the system works and was validated
- Human oversight design — ensure humans can monitor and override the system
- Conformity assessment — internal self-assessment or third-party audit depending on the system type
- EU registration — register the system in the EU AI Act database before deployment
Each workstream typically takes 2–4 months. Start with a gap assessment to understand where you are versus where you need to be.
Your Compliance Timeline at a Glance
| Date | What you need | Who it affects |
|---|---|---|
| Now | AI inventory + risk classification | All organisations using AI |
| 2 Aug 2026 | Transparency disclosures in place | Chatbots, AI content, emotion recognition |
| 2 Dec 2026 | Synthetic content labelling + nudifier ban | Media, marketing, AI content platforms |
| 2 Dec 2027 | Full high-risk AI compliance | Recruitment, credit, education, law enforcement… |
| 2 Aug 2028 | High-risk AI in regulated products | Medical devices, machinery, vehicles… |
SME-Specific Provisions in the AI Act
The AI Act includes several provisions designed to reduce the burden on smaller organisations:
- Regulatory sandboxes — national authorities must establish sandboxes allowing SMEs to develop and test AI under regulatory supervision before full deployment.
- Proportionate fees — conformity assessment fees for SMEs must be proportionate to their size and market share.
- Priority access — SMEs get priority access to sandboxes and guidance from national competent authorities.
- Simplified documentation — for some systems, SMEs can use simplified technical documentation templates.
These provisions exist, but they do not reduce the substantive compliance obligations for high-risk AI. They reduce cost and friction, not requirements.
A note on GDPR overlap: Many EU AI Act obligations — particularly around data governance, documentation, and individual rights — overlap with GDPR. If you have a functioning GDPR compliance programme, you have a head start. Your DPO and existing data processing records are a valuable foundation for AI Act compliance.
Not sure where you stand?
Our free assessment tool maps your AI systems to the relevant EU AI Act obligations in minutes.
Start free assessment