Home · Resources

AI Act & Compliance

AI Act compliance checklist for SMEs

A practical guide to navigating the European AI Act: map the systems you use, classify the risks, meet the deadlines already in force and prepare what you'll need for 2027. Designed to be printed and used as an internal working tool.

Important note. This checklist is general informational guidance, based on the text of Regulation (EU) 2024/1689 (the AI Act) and the Digital Omnibus package of 7 May 2026. It does not constitute legal advice. For a binding assessment of your company's specific situation, consult a qualified professional.
Print this page or save it as a PDF with Ctrl+P (Windows) or Cmd+P (Mac).

1. Map your AI systems

Before you can classify risk, you need to know what you have. Many businesses use AI without realising it: from spam filters to chatbots, from recruiting tools to predictive analytics platforms. Start with an inventory.

For every AI system in use or in development, note down:

Complete this exercise for every system before moving on to the next section. The inventory is the starting point of any compliance journey.

2. Classify the risk

The AI Act divides AI systems into four risk levels. The level determines which obligations apply and when they come into force.

Level What it means Concrete examples for SMEs Deadline
Prohibited Prohibited practices with no exceptions. No possibility of derogation. Social scoring of employees or customers, covert manipulation of decisions, mass scraping of faces from the internet, emotion recognition of employees or students in work or education settings. Since 2 Feb 2025
High risk Heavy obligations: technical documentation, activity logs, human oversight, risk analysis and management, data quality. CV screening and candidate selection, creditworthiness assessment, systems for education and exams, medical devices with AI components, critical infrastructure, systems for migration or border control. From 2 Dec 2027
Limited risk Transparency obligations: informing the user that they are interacting with an artificial intelligence, or that content is AI-generated. Website chatbots, voice assistants, tools that generate text, images, audio or video intended for publication. From 2 Aug 2026
Minimal risk No specific obligation set out in the law. Good practices on privacy and security remain recommended in any case. Spam filters, product recommendations on e-commerce sites, spell checkers, predictive analytics tools on internal data with no impact on natural persons. No deadline

How to tell if you're "high risk". A system is high-risk not because of the technology it uses, but because of its intended purpose and its impact on people. The same model can be minimal-risk if it provides generic suggestions, and high-risk if those responses determine access to an essential service or a hiring decision.

Simplified SME threshold (Digital Omnibus 2026). Companies with up to 750 employees and €150 million in turnover benefit from simplified guidance, standardised documentation and reduced penalties. Compliance remains mandatory, but the administrative burden is calibrated to the actual size of the business.

3. Transparency obligations already in force (from 2 August 2026)

This is the nearest deadline, and it has not been extended. If your system falls into the categories below, the obligations take effect on 2 August 2026.

Cost of non-compliance. Penalties for failing to meet transparency obligations can reach €15 million or 3% of worldwide annual turnover. SMEs benefit from the lower threshold, but reputational risk adds to the financial one.

4. What to prepare for high-risk systems (by 2 December 2027)

If one or more of your systems fall into the "high risk" category, you have until 2 December 2027. Use the time well: building documentation retroactively, on a system already in production, costs far more than building it in from the start of the project.

5. AI literacy (Art. 4, already in force)

Article 4 of the AI Act requires providers and deployers of AI systems to ensure that their staff have sufficient competence in artificial intelligence: what it does, how it works, and what its limitations and risks are. In force since 2 February 2025. You don't need huge training programmes, but you do need to be able to show that you've done something concrete and documented.

6. Working checklist: tick off completed items

Use this list as a practical working tool. Print it, tick off items as you complete them, and come back to it whenever you introduce a new AI system in your company or update an existing one.

Not sure whether your AI project is compliant?

We offer a bespoke AI Act compliance audit for your business: we classify your systems, identify the obligations that apply and set out a concrete action plan. Response within 24 hours.

Request the compliance audit

← Back to home