AI Act compliance checklist for SMEs
A practical guide to navigating the European AI Act: map the systems you use, classify the risks, meet the deadlines already in force and prepare what you'll need for 2027. Designed to be printed and used as an internal working tool.
1. Map your AI systems
Before you can classify risk, you need to know what you have. Many businesses use AI without realising it: from spam filters to chatbots, from recruiting tools to predictive analytics platforms. Start with an inventory.
For every AI system in use or in development, note down:
- What it does, in one clear sentence (e.g. "answers customer questions on the website", "suggests candidates based on the CVs received").
- Who uses it: internal staff only, end customers, external partners, or a combination?
- Origin: developed in-house, bought from a supplier, or built on the API of a foundation model (ChatGPT, Gemini, Claude, etc.)?
- Data processed: personal data, sensitive data, images, voices, confidential documents?
- Impact on decisions: does the system decide autonomously, provide suggestions to staff, or produce only informational output with no direct consequences?
Complete this exercise for every system before moving on to the next section. The inventory is the starting point of any compliance journey.
2. Classify the risk
The AI Act divides AI systems into four risk levels. The level determines which obligations apply and when they come into force.
| Level | What it means | Concrete examples for SMEs | Deadline |
|---|---|---|---|
| Prohibited | Prohibited practices with no exceptions. No possibility of derogation. | Social scoring of employees or customers, covert manipulation of decisions, mass scraping of faces from the internet, emotion recognition of employees or students in work or education settings. | Since 2 Feb 2025 |
| High risk | Heavy obligations: technical documentation, activity logs, human oversight, risk analysis and management, data quality. | CV screening and candidate selection, creditworthiness assessment, systems for education and exams, medical devices with AI components, critical infrastructure, systems for migration or border control. | From 2 Dec 2027 |
| Limited risk | Transparency obligations: informing the user that they are interacting with an artificial intelligence, or that content is AI-generated. | Website chatbots, voice assistants, tools that generate text, images, audio or video intended for publication. | From 2 Aug 2026 |
| Minimal risk | No specific obligation set out in the law. Good practices on privacy and security remain recommended in any case. | Spam filters, product recommendations on e-commerce sites, spell checkers, predictive analytics tools on internal data with no impact on natural persons. | No deadline |
How to tell if you're "high risk". A system is high-risk not because of the technology it uses, but because of its intended purpose and its impact on people. The same model can be minimal-risk if it provides generic suggestions, and high-risk if those responses determine access to an essential service or a hiring decision.
Simplified SME threshold (Digital Omnibus 2026). Companies with up to 750 employees and €150 million in turnover benefit from simplified guidance, standardised documentation and reduced penalties. Compliance remains mandatory, but the administrative burden is calibrated to the actual size of the business.
3. Transparency obligations already in force (from 2 August 2026)
This is the nearest deadline, and it has not been extended. If your system falls into the categories below, the obligations take effect on 2 August 2026.
- Chatbots and virtual assistants. Any system that responds to users in natural language (text or voice) must explicitly state that it is an artificial intelligence, not a human being. The statement must be given at first contact, clearly and visibly, not hidden at the bottom of the page or in a legal notices section.
- AI-generated content intended for publication. Text, images, audio and video produced with generative artificial intelligence tools must be flagged as such to users. Exception under the law: text that has been fully reviewed and published under full human editorial responsibility does not require mandatory labelling.
- Deepfakes and realistic synthetic content. Images, audio or video that depict real people or events in a plausible but artificial way must be explicitly declared as artificial content.
- Emotion recognition or biometric categorisation (in the cases permitted by law): people exposed to the system must be informed in advance.
- Technical watermarking, from 2 December 2026. AI-generated content will also need to carry a machine-readable marker. This technical requirement is deferred by four months relative to the text-disclosure obligation, but it should be planned for now.
Cost of non-compliance. Penalties for failing to meet transparency obligations can reach €15 million or 3% of worldwide annual turnover. SMEs benefit from the lower threshold, but reputational risk adds to the financial one.
4. What to prepare for high-risk systems (by 2 December 2027)
If one or more of your systems fall into the "high risk" category, you have until 2 December 2027. Use the time well: building documentation retroactively, on a system already in production, costs far more than building it in from the start of the project.
- Technical documentation. A complete description of the system: what it does, what data was used to train it, its architecture, expected performance metrics, known limitations and residual risks. It must be updated whenever the system changes significantly.
- Risk analysis and management. A formal procedure to identify, assess and mitigate the system's risks across its entire lifecycle, not just before launch. It must be repeated at every relevant update.
- Data quality. Training, validation and testing datasets must be relevant, representative of the real population of use, free of significant errors and documented. A process is needed to monitor and update them over time.
- Human oversight. There must be mechanisms allowing a person to monitor the system's operation in real time, to intervene to correct anomalous behaviour and, if necessary, to stop it. Whoever exercises oversight must have adequate technical competence.
- Activity logging. The system must automatically generate logs of relevant operations, so as to ensure traceability of critical events, errors and any incidents. Logs must be retained for the period set out in the law.
- Robustness, accuracy and cybersecurity. The system must be tested for resilience against errors, malfunctions and manipulation attempts (including adversarial attacks). Security must be assessed periodically, not just at launch.
- EU declaration of conformity and registration (where required). For some categories of high-risk systems, registration in a public European database is mandatory. Check in advance whether your system falls into a category that requires it.
- Clarity on roles: provider and deployer. Put in writing, in contracts or in an internal policy, who developed the system (provider) and who uses it in their own operations (deployer). The two roles carry distinct obligations: failing to define them creates disputes and unclear liability.
5. AI literacy (Art. 4, already in force)
Article 4 of the AI Act requires providers and deployers of AI systems to ensure that their staff have sufficient competence in artificial intelligence: what it does, how it works, and what its limitations and risks are. In force since 2 February 2025. You don't need huge training programmes, but you do need to be able to show that you've done something concrete and documented.
- Train those who use AI day to day. Every employee who interacts with AI tools (even just ChatGPT for routine work) must understand what the tool does, its limitations, and how to check its results before using them in a professional context.
- Train those who oversee high-risk systems. People responsible for the human oversight of high-risk AI systems must have technical competence proportionate to their role, not just a generic understanding of AI.
- Document the training provided. Keep a record of who received which training and when. Even a spreadsheet or a summary email with attendance confirmations can be enough to demonstrate compliance with Art. 4 in an SME.
- Update the training periodically. AI evolves quickly: plan updates at least annually, and whenever you introduce a significantly new AI tool or system.
- Include AI literacy in onboarding. Anyone joining the company who will use AI tools should receive basic training as part of onboarding. Don't treat it as a separate, optional activity.
6. Working checklist: tick off completed items
Use this list as a practical working tool. Print it, tick off items as you complete them, and come back to it whenever you introduce a new AI system in your company or update an existing one.
- ☐ I have compiled an inventory of all AI systems in use in the company, including those provided by third parties and foundation-model APIs.
- ☐ For every system I have noted the intended purpose, data processed, users involved and impact on decisions.
- ☐ I have classified each system as prohibited, high risk, limited risk or minimal risk.
- ☐ No system in use or in development falls under the practices prohibited by the AI Act.
- ☐ Chatbots and virtual assistants clearly state that they are an artificial intelligence at the user's first contact (deadline: 2 August 2026).
- ☐ AI-generated content intended for publication is labelled as such, or I have verified that the human editorial responsibility exception applies.
- ☐ I have started planning the technical documentation for high-risk systems.
- ☐ I have defined who exercises human oversight over the systems that require it, and verified that they have the necessary competence.
- ☐ High-risk systems generate logs of relevant activities and retain them for the required period.
- ☐ I have started (or planned) a formal risk assessment for high-risk systems.
- ☐ The data used to train or feed the AI systems is documented, checked and kept up to date.
- ☐ I have set out in writing the roles of provider and deployer for each system, in contracts or in an internal policy.
- ☐ Staff who use AI tools have received basic training (Art. 4, already in force).
- ☐ A record exists of the AI training provided to staff, with dates and attendees.
- ☐ I have planned the technical watermarking of generated output, ahead of the 2 December 2026 deadline.
- ☐ I have scheduled a review of this checklist within the next 12 months, or at the next introduction of an AI system.
- ☐ For high-risk systems, I have consulted (or planned to consult) an AI compliance expert.
Not sure whether your AI project is compliant?
We offer a bespoke AI Act compliance audit for your business: we classify your systems, identify the obligations that apply and set out a concrete action plan. Response within 24 hours.
Request the compliance audit