EU AI Act compliance checklist for SMEs
A practical, source-referenced compliance checklist for European startups and SMEs that use or build AI systems. Written for product and operations teams, not lawyers.
The EU AI Act applies to almost every company that uses or builds AI in the European Union, even if you only run a chatbot on your marketing site. This guide is the working checklist we’d hand a founder or product lead who just realised the regulation applies to them and has roughly two weekends to get oriented before talking to a lawyer.
It covers what to inventory, what to classify, what to write down, and what to ship by which deadline. It is not legal advice. It is the practical first pass.
Coming under the Digital Omnibus (pending adoption): the AI Act’s SME reliefs — simplified documentation templates, proportionate quality-management expectations, priority sandbox access, and lower penalty caps — are set to be extended to a new “small mid-cap” tier: companies that aren’t SMEs but employ fewer than 750 people with annual turnover ≤ €150M (or balance sheet ≤ €129M). This is part of the 7 May 2026 political agreement and takes effect once the Omnibus is formally adopted.
Step 1 — Inventory every AI system you use or build
The Act regulates AI systems, defined broadly in Article 3(1). For most SMEs, that means anything that uses a foundation model (ChatGPT, Claude, Mistral, Llama), any ML model trained in-house, any vendor product whose value proposition includes “AI,” and any embedded system that produces predictions, recommendations, or decisions.
For each system, capture:
- A short plain-language description of what it does
- The business purpose
- Who built it (your team, a named vendor, a foundation-model provider)
- The data inputs (biometric, health, financial, behavioural, geolocation)
- The affected persons (employees, candidates, customers, the public)
- Your role: deployer (you use it), provider (you build it and put it on the EU market), or both
Inventory first, classify later. Most teams skip the inventory and end up with a 200-page document that misses three systems running in HR.
Step 2 — Screen for prohibited practices (Article 5)
Article 5 lists eight practices that are banned outright as of 2 February 2025. Penalties hit €35 million or 7% of global turnover, whichever is higher (Article 99). The most likely traps for SMEs:
- Subliminal manipulation or exploitation of vulnerable users (age, disability, economic situation)
- Social-scoring systems that produce unjustified differential treatment
- Real-time remote biometric identification in publicly accessible spaces
- Emotion recognition in the workplace or educational settings
If you’re a normal B2B SaaS this list usually doesn’t apply, but check every system once. The cost of getting this one wrong is catastrophic.
Step 3 — Classify each system by risk tier
Every system that isn’t prohibited falls into one of three tiers:
| Tier | What it means | Source | |---|---|---| | High risk | Falls under Annex III (HR, credit scoring, essential services, biometric ID, etc.) or is a safety component of a regulated product (Annex I). | Article 6 | | Limited risk | Transparency obligations only — typically chatbots and generative content. | Article 50 | | Minimal risk | No specific obligations beyond AI literacy. | — |
Read Annex III carefully. The Annex III categories that catch unsuspecting SMEs most often: employment (CV screening, interview scoring), creditworthiness, education (exam grading), and access to essential services.
For a definitive walkthrough, see our Is my AI system high-risk? guide.
Step 4 — If high-risk, plan the full provider obligations
For providers of high-risk systems (Articles 9–17), the obligations include:
- A documented risk-management system across the lifecycle
- Data governance (training, validation, test data quality)
- Technical documentation per Annex IV
- Logging and record-keeping
- Transparency and instructions for use for deployers
- Human-oversight measures designed into the system
- Accuracy, robustness, and cybersecurity (Article 15)
- Conformity assessment and CE marking
- Registration in the EU database (Article 49)
- Post-market monitoring and serious-incident reporting (Articles 72, 73)
For deployers of high-risk systems (Article 26), the lighter set includes:
- Use the system per the provider’s instructions
- Ensure meaningful human oversight over outputs
- Inform affected persons that AI is involved
- Keep logs the provider supplies
- Run a fundamental-rights impact assessment if you’re in the categories listed in Article 27
Step 5 — Mandatory across every tier: AI literacy (Article 4)
Article 4 — in force since 2 February 2025 — requires providers and deployers to ensure their staff have a sufficient level of AI literacy in the context of the systems they work with. There’s no certification scheme yet, but expect supervisory authorities to ask “how do you train your team?” Document your AI literacy programme. See AI literacy under Article 4.
Step 6 — Transparency for limited-risk systems (Article 50)
If your AI system interacts with humans (chatbot), generates synthetic media (deepfake, GPT-generated content), or recognises emotions, you must disclose this in plain language. The disclosure must be unmistakable — a footnote in your privacy policy does not count. It should be visible at the point of interaction.
Step 7 — Document the human acceptance step
Whatever your system does, the legally relevant moment under the Act is when a named human in your organisation accepts a consequential AI output. Build this into the product if you’re a provider, and into your operations if you’re a deployer. Capture: who, when, on what evidence, with what reviewer notes. This becomes the spine of your audit trail.
Step 8 — Track the deadlines
| Date | What applies | |---|---| | 2 Feb 2025 | Prohibited practices (Article 5) + AI literacy (Article 4) | | 2 Aug 2025 | GPAI model obligations + governance bodies | | 2 Aug 2026 | Article 50 transparency applies (chatbots, deepfakes, AI-interaction & synthetic-content disclosure). Machine-readable marking of synthetic content already on the market before 2 Aug 2026 has a grace period to 2 Dec 2026. | | 2 Dec 2027 | Most provisions — including high-risk AI registration, post-market monitoring, fines for most offences — expected, postponed from 2 August 2026 under the Digital Omnibus | | 2 Aug 2028 | High-risk AI under Annex II (regulated products) — expected, postponed from 2 August 2027 under the Digital Omnibus |
The 2 December 2027 date is the one to plan around. Backwards-plan your conformity assessment, technical documentation, and EU database registration from 2 December 2027 (postponed from 2 August 2026 under the Digital Omnibus, agreed May 2026 and pending formal adoption).
What software does for you
You will not navigate this checklist by remembering it. You’ll work through it system by system in something that keeps your AI inventory, your risk classifications, your evidence, and your reviewer notes in one place — and produces the dossier when a regulator asks. That’s what Maditon is for.