Checklist
EU AI Act compliance checklist for small and medium businesses
Ten steps, in the order they actually make sense. Most SMEs finish steps one to four in an afternoon and discover their exposure is smaller than feared — but rarely zero.
Last reviewed: August 2026
1. Confirm whether the Act reaches you at all
The test is territorial reach, not company address. If you place an AI system on the EU market, put one into service there, or the output of your AI system is used in the EU, you are in scope. Write down the answer and the reasoning — that note is the first piece of evidence in your file.
2. Build a register of every AI tool in use
- Tool name, vendor, and who owns it internally.
- What it is used for, in one sentence a non-technical colleague would recognise.
- Whether it touches personal data, and whose.
- Whether it influences a decision about a person, and how much.
- Whether any affected person is in the EU.
Shadow AI is the usual gap
3. Classify each tool by risk tier
Check the prohibited list first — those uses must stop immediately, regardless of timeline. Then check Annex III: employment and worker management, credit and insurance scoring, education assessment, essential services, biometrics. Everything left over is usually limited or minimal risk.
4. Fix your role for each tool
Provider or deployer, tool by tool. If you white-label, resell, or materially modify a system, you are a provider for that system and the obligation set is far heavier.
5. Assign human oversight in writing
- Name the person who reviews AI output for each high-risk or borderline use.
- State what authority they have to override, pause or escalate.
- State how often the tool's output is spot-checked, and where the record lives.
6. Deliver AI literacy training and record it
The literacy obligation has applied since February 2025 and applies to every organisation using AI, not only high-risk ones. A short internal session covering what the tools do, what may not be pasted into them, and who to ask is enough for most SMEs — provided you keep an attendance record and refresh it.
7. Meet the transparency duties
- Chatbots and AI agents facing customers must be identifiable as AI.
- Synthetic images, audio and video must be labelled as artificially generated.
- Staff subject to a high-risk system at work must be told before it is used.
8. Align with UK GDPR at the same time
Nearly every AI use in scope of the Act is also processing personal data. Lawful basis, transparency notices, DPIAs for high-risk processing, and international transfer checks for overseas AI vendors all need to line up with what you have just written down.
9. Read the vendor documentation, and keep it
Providers must publish instructions for use and an intended purpose. Operating a tool outside that intended purpose can move liability onto you. Save the version you relied on, with the date.
10. Set a review rhythm
A register goes stale in weeks. Review quarterly, and re-check whenever a new tool is adopted, a vendor changes its model, or a use case moves closer to hiring, credit or access to services.
See where your own AI use actually stands
Register the AI tools your team uses and get a risk rating for each one, in plain English. Free, and it takes about ten minutes.
Not legal advice. This guide explains how the rules are generally understood and is here to help you get organised. It isn't a substitute for advice from a qualified solicitor or your own compliance team.
