AI Act Compliance Guide for SMEs

AI Act SMEs guide to roles, risk classification, high-risk systems, AI literacy, vendor due diligence, GDPR, and practical compliance steps.

AI Act Compliance Guide for SMEs

The EU AI Act is not limited to technology companies or businesses developing complex AI models. It may also apply to SMEs that purchase third-party AI software, use AI in recruitment or employee management, deploy chatbots, create AI-assisted content, or integrate automated tools into routine business processes.

AI Act compliance for SMEs begins with understanding which AI systems the business uses, what role it performs, and how each system is classified under the EU’s risk-based framework. An SME may be regulated as a provider, deployer, importer, distributor, or product manufacturer. It may also assume additional responsibilities by modifying, rebranding, or placing another provider’s AI system on the market under its own name.

Company size does not create a general exemption. The applicable obligations depend primarily on the organization's regulatory role, the system’s intended purpose, and the risks associated with its use.

This guide explains how SMEs can identify their role, build an AI inventory, classify systems, stop prohibited practices, assess high-risk AI, implement transparency controls, strengthen AI literacy, review suppliers, and maintain evidence of compliance.

What Is the EU AI Act?

Regulation (EU) 2024/1689, commonly known as the EU AI Act, establishes harmonised rules for the development, placement on the market, deployment, and use of artificial intelligence across the European Union. It creates a common legal framework for organisations that build, supply, import, distribute, or use covered AI systems.

The purpose of the regulation

The regulation aims to promote safe and trustworthy AI while protecting health, safety, and fundamental rights. It also seeks to establish consistent rules across EU Member States, support responsible innovation, and create clearer accountability throughout the AI value chain.

For SMEs, this means compliance responsibilities may arise at different stages, from product development and procurement to deployment, monitoring, and customer communication.

The AI Act uses a risk-based framework

The AI Act does not impose identical requirements on every AI tool. Instead, obligations depend on the system’s characteristics, intended purpose, and potential impact.

The main categories are

  1. Prohibited AI practices that create unacceptable risks

  2. High-risk AI systems subject to extensive controls

  3. AI systems covered by specific transparency requirements

  4. Minimal or limited-risk systems that generally face fewer mandatory obligations

An SME must therefore classify each AI use correctly before deciding which compliance measures are required.

Does the AI Act Apply to SMEs?

Yes. The AI Act can apply to micro, small and medium-sized businesses. SME status may influence how certain requirements are implemented, but it does not create a general exemption from EU AI regulation.

The key question is not simply how many people the company employs. An SME must determine whether it provides or deploys an AI system, imports or distributes one, or integrates AI into a product sold under its own name. Regulatory responsibilities may also change when the business rebrands a third-party system, substantially modifies it or changes its intended purpose.

Territorial scope

The AI Act may apply to:

  • Providers placing AI systems or general-purpose AI models on the EU market

  • EU-based organisations deploying AI in their business activities

  • Importers and distributors making AI systems available in the EU

  • Providers and deployers established outside the EU when the system’s output is used within the EU

This means a non-EU supplier or business may still fall within scope when its AI products, services or outputs reach the European market.

SME support and proportionality

The European Commission’s AI Act regulatory framework overview explains that the framework includes measures intended to support innovation and proportionate implementation. These include regulatory sandboxes, targeted guidance, dedicated communication channels and simplified compliance pathways for specified obligations. SMEs may also receive priority access to certain sandbox arrangements, while relevant conformity-assessment fees should take account of their size and interests.

These measures can reduce unnecessary administrative burdens, but SMEs must still identify their role, classify their AI systems and meet every obligation that applies to their activities.

Identify Your Role Under the AI Act

An SME’s obligations depend heavily on the regulatory role it performs. The same AI system can create different responsibilities for the organisation that develops it, the business that deploys it and the companies that place it on the EU market.

Provider

An SME may be a provider when it develops an AI system or general-purpose AI model, has one developed on its behalf, or places the system on the market under its own name or trademark.

Examples include a software company selling an AI recruitment tool, a health-technology business developing diagnostic software or an organisation rebranding a third-party AI product as its own.

Deployer

A deployer uses an AI system under its authority in a professional or organisational context. Most SMEs using commercial AI tools are more likely to be deployers than providers.

Examples include an employer using an AI recruitment platform, a retailer operating a customer-service chatbot, a business deploying productivity-monitoring software or a financial company using AI-assisted fraud detection.

Importer and distributor

An importer introduces an AI system from a third country into the EU market. A distributor makes an AI system available within the supply chain without necessarily developing or importing it.

Product manufacturer

An SME may have additional responsibilities when an AI system is integrated into a regulated product sold under its name. This is especially relevant where the AI performs a safety-related function.

Why contracts do not determine regulatory status

A supplier agreement can allocate commercial duties, but it cannot override the role the company actually performs under the AI Act. Regulators will look at the business’s real activities, not only the labels used in the contract.

SMEs should record their regulatory role for every system in the AI inventory and reassess it whenever the product, branding, intended purpose or level of control changes.

★ Free Certificate of Completion Included

Build Practical AI Act & Governance Expertise

Understand the EU AI Act, AI governance responsibilities, privacy risks, high-risk AI controls, human oversight and risk management. Build practical knowledge for responsible AI governance and receive a free Certificate of Completion when you successfully complete the course.

Explore AI Act Training →

Start with an AI Systems Inventory

SMEs cannot assess AI Act compliance until they know where and how artificial intelligence is being used across the organisation. An AI systems inventory creates that visibility and provides the foundation for role assessment, risk classification, vendor review, transparency controls and staff training.

What the inventory should cover

For each system, record the product name, supplier, business owner, department, intended purpose and authorised users. The inventory should also identify affected individuals, the data processed, the type of output produced and the level of human involvement.

Compliance fields should include the company’s regulatory role, the system’s risk classification, applicable transparency obligations, contract status and next review date. Recording the intended purpose is particularly important because changing how a system is used can alter its legal classification or the company’s responsibilities.

Include informal and unsanctioned AI use

The inventory should capture more than centrally purchased software. Common examples include employees using public generative AI tools, AI-assisted email drafting, automated meeting transcription, embedded office-software features, candidate screening, customer sentiment analysis, AI image or video generation, fraud or credit tools and employee productivity analytics.

These uses may otherwise remain invisible to legal, compliance, security and procurement teams.

Create an AI intake process

Require employees to notify a designated owner before purchasing a tool, activating an AI feature, uploading business data, running a pilot, integrating an API or using AI to support employment or customer decisions.

The inventory should be treated as a living governance record. Update it when systems, suppliers, features, data sources, intended purposes or business owners change.

Classify AI Systems by Risk

AI Act SMEs infographic comparing provider and deployer duties, from building and testing AI to monitoring outputs and reporting risks.

AI risk classification should follow a documented decision sequence. SMEs should assess the system’s legal definition, intended purpose and real-world use rather than relying solely on vendor descriptions or the perceived sophistication of the technology.

Step 1: Is the technology an AI system?

Not every automated rule, calculator, spreadsheet formula or conventional software application qualifies as an AI system. The assessment should examine how the technology operates, whether it infers how to generate outputs from inputs and the extent to which those outputs influence physical or virtual environments.

The European Commission’s guidelines on the definition of an AI system provide practical, non-binding guidance for applying the legal definition.

Step 2: Is the use prohibited?

Check the intended and actual use against the prohibited-practices rules. A system that involves harmful manipulation, certain forms of social scoring, prohibited emotion recognition or restricted biometric practices may require immediate suspension and legal assessment.

Step 3: Is the system high-risk?

Determine whether the system:

  • Is a safety component of a regulated product

  • Falls within a listed high-risk use case

  • Meets the conditions for an exception or exclusion

The classification depends primarily on intended purpose and impact, not simply technical complexity.

Step 4: Do transparency requirements apply?

Check whether the system interacts directly with individuals or generates synthetic audio, images, video or text. Additional requirements may apply to deepfakes, emotion-recognition systems and biometric-categorisation tools.

Step 5: Does the SME provide a general-purpose AI model?

An SME purchasing access to a general-purpose model will not ordinarily become the model provider. However, developing, placing on the market or substantially modifying such a model may create broader provider obligations.

Step 6: Do other laws apply?

AI Act classification is only one part of the assessment. SMEs should also consider the GDPR, employment law, consumer protection, product safety, intellectual property, cybersecurity and sector-specific regulation.

Record the reasoning, evidence, reviewer and review date for every classification decision.

Prohibited AI Practices SMEs Must Avoid

Some AI uses are prohibited because they create unacceptable risks to individuals, fundamental rights or society. Article 5 of the AI Act covers practices such as harmful manipulation or deception, exploitation of vulnerabilities, certain forms of social scoring and specified individual criminal-risk predictions. It also restricts untargeted facial-image scraping, certain biometric categorisation based on sensitive characteristics, emotion recognition in workplaces and schools, and specific real-time remote biometric identification uses by law-enforcement authorities.

The European Commission’s guidelines on prohibited AI practices provide legal explanations and practical examples to help organisations assess whether a planned or existing use falls within these categories. The guidelines are intended to support interpretation, but the facts and context of each deployment still require careful assessment.

SME workplace example

An employer should not assume that a tool is lawful because a supplier markets it as an employee-engagement, wellbeing or productivity solution. If the system attempts to infer employees’ emotions from facial expressions, voice, behaviour or biometric signals, its use may fall within the workplace emotion-recognition prohibition.

Procurement control

Procurement, HR and compliance teams should screen proposed systems for:

  • Biometric functions

  • Emotion analysis

  • Behavioural or social scoring

  • Manipulative personalisation

  • Vulnerability targeting

  • Facial-image collection or scraping

Supplier descriptions should be tested against the system’s actual functionality, intended purpose and possible configurations.

Where a tool may involve a prohibited practice, the SME should stop procurement, testing or deployment and obtain a documented legal assessment before proceeding. Disabling the relevant function may be necessary, but employers should verify that it cannot be reactivated or used indirectly.

What Counts as High-Risk AI?

High-risk AI is not defined by how advanced, expensive or technically complex a system appears. Classification depends on the system’s intended purpose, the product or activity in which it is used and its potential effect on health, safety or fundamental rights. Under the AI Act, high-risk systems generally fall into two routes: AI connected to certain regulated products and AI used for specified purposes listed in Annex III.

High-risk AI linked to regulated products

An AI system may be classified as high-risk when it serves as a safety component of a product covered by specified EU product legislation, or when the AI-enabled product itself must undergo a third-party conformity assessment before being placed on the market.

This route may be relevant to SMEs developing or selling regulated machinery, medical devices, safety equipment or other products covered by the legislation referenced in the AI Act.

Listed high-risk use cases

The Annex III categories most relevant to SMEs can include AI used for:

  • Recruitment and candidate selection

  • Employment decisions and worker management

  • Task allocation and performance monitoring

  • Access to vocational education or training

  • Creditworthiness assessment

  • Risk assessment and pricing in certain life and health insurance contexts

  • Access to essential private or public services

  • Certain biometric applications

  • Specified safety, law-enforcement, migration and justice purposes

Recruitment and HR tools

Employment-related systems require particularly close assessment. Examples include CV-screening and candidate-ranking tools, automated interview analysis, promotion recommendations, disciplinary or dismissal decision support, employee task-allocation software and performance-monitoring systems.

An SME should assess what the system actually influences. A tool described as administrative support may still be high-risk when its output materially shapes who is recruited, promoted, monitored or dismissed.

Classification exceptions

Some Annex III systems may fall outside high-risk classification when they perform a narrow procedural or preparatory task, improve the result of a completed human activity, detect patterns without replacing human assessment, or do not materially influence the relevant decision. Systems that profile individuals remain subject to stricter treatment.

Employers should not rely on an exception without recording the intended purpose, decision impact, human involvement and supporting evidence. The European Commission’s guidelines for providers and deployers of high-risk AI systems provide practical classification examples, but each SME remains responsible for assessing its own system and use case.

Provider Obligations for High-Risk AI

This section is primarily relevant to SMEs that develop, brand or substantially modify high-risk AI systems. Providers carry broader responsibilities than businesses that simply use an AI tool because they must demonstrate that the system meets the AI Act’s requirements before and after it reaches the market.

Core provider controls include:

  • A continuous risk-management system

  • Appropriate data and data-governance controls

  • Technical documentation

  • Automatic record-keeping and logging capabilities

  • Clear instructions and transparency information for deployers

  • Effective human-oversight design

  • Appropriate accuracy, robustness and cybersecurity

  • A documented quality-management system

  • Conformity assessment before market placement or use

  • Registration where required

  • Post-market monitoring

  • Serious-incident reporting

  • Corrective action when non-compliance or risk is identified

These controls should operate across the system’s lifecycle rather than being completed only at product launch.

Substantial modification risk

A deployer, distributor or other business may become the provider when it places an AI system on the market under its own name or trademark, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk. A change that affects regulatory compliance may also require the system to undergo a new conformity assessment.

Documentation proportionality

SMEs should avoid creating a paperwork-heavy compliance structure that is disconnected from product development. Evidence should instead be integrated into existing operational records, including:

  • Product requirements

  • Testing and validation records

  • Change-management processes

  • Security reviews

  • Supplier documentation

  • Release and approval decisions

This approach makes compliance evidence easier to maintain, audit and update while supporting effective product governance.

Deployer Obligations for High-Risk AI

This section is particularly relevant to SMEs that purchase and use high-risk AI rather than develop it. A deployer must operate the system within its intended purpose and take appropriate technical and organisational measures to follow the provider’s instructions.

Depending on the system and context, the SME may need to:

  • Assign competent personnel to provide human oversight

  • Ensure input data is relevant and sufficiently representative where it controls that data

  • Monitor the system’s operation and identify unexpected risks

  • Retain automatically generated logs under its control

  • Suspend use when the system may create unacceptable risks

  • Report serious incidents or malfunctions through the required channels

  • Inform workers and employee representatives before certain workplace deployments

  • Cooperate with competent authorities

  • Complete a fundamental-rights impact assessment where the legal conditions apply

The Commission’s official Navigating the AI Act questions and answers provides practical guidance on deployer responsibilities, including input-data quality, affected-person notices and fundamental-rights assessments.

Human oversight

Human review must be meaningful, not a routine approval of the AI output. The designated reviewer should understand the system’s purpose, limitations and expected performance. They must be able to recognise automation bias, interpret outputs critically, reject or override recommendations, escalate concerns and stop use where necessary.

The SME should give reviewers sufficient authority, time, information and training to intervene effectively.

Do not rely solely on vendor assurances

Before deployment, request and review:

  • Instructions for use

  • The intended-purpose statement

  • Risk-classification information

  • Performance limitations

  • Human-oversight requirements

  • Logging capabilities

  • Incident procedures

  • Cybersecurity information

  • Relevant compliance documentation

Vendor claims do not remove the deployer’s responsibility to configure, monitor and use the system lawfully. The SME should record its review, operational controls and any unresolved limitations in the AI inventory.

AI Transparency Requirements

Some AI systems are subject to transparency requirements even when they are not classified as high-risk. Article 50 of the AI Act applies to specified interactive, generative and content-manipulation systems, with the relevant obligations applying from 2 August 2026. SMEs should assess whether they act as the provider of the system, the deployer using it or both.

AI interaction notices

Where required, individuals must be informed that they are interacting with an AI system unless this is already obvious to a reasonably informed and attentive person.

Relevant SME examples may include:

  • Customer-service chatbots

  • AI reception systems

  • Automated support assistants

  • Voice bots

The notice should be clear, timely and visible before or during the interaction, rather than hidden in lengthy terms and conditions.

AI-generated and manipulated content

Providers of certain systems that generate synthetic audio, images, video or text may need to enable machine-readable marking so the content can be detected as artificially generated or manipulated. Deployers may also need to label deepfakes and disclose specified AI-generated text published to inform the public on matters of public interest, subject to relevant exceptions and editorial safeguards.

Marketing and communications risks

SMEs should establish approval rules for synthetic spokespersons, AI-generated testimonials, manipulated product demonstrations, news-style content, voice cloning, deepfake video and undisclosed automated conversations. Human editorial review should verify accuracy, context, permissions and the risk of misleading customers.

Keep evidence of transparency controls

Document:

  • Where interaction notices appear

  • Which content is labelled

  • Who performs editorial review

  • Which machine-readable marking features are enabled

  • Which legal exceptions are relied upon

The European Commission’s official guidelines on transparency obligations for AI systems provide practical guidance for applying Article 50 consistently and proportionately.

AI Literacy and Staff Training Requirements

Effective AI training should be proportionate to the SME’s systems, workforce and risk exposure. Article 4 requires providers and deployers to take measures that support the development of AI literacy among staff and other people who operate or use AI systems on their behalf. The approach should reflect the organisation’s regulatory role, employees’ technical knowledge and experience, the context in which AI is used, the decisions it affects and the people who may be harmed. The current framework does not prescribe one identical course or a specific level of literacy for every employee.

General AI awareness training

Employees who use or encounter AI should understand:

  • What AI is and which systems the company permits

  • Common limitations, including hallucinations and unreliable outputs

  • Confidentiality and personal-data risks

  • Intellectual-property concerns

  • Bias and discrimination risks

  • Human-review expectations

  • Incident-reporting procedures

  • Prohibited or unauthorised uses

Training should use examples drawn from the organisation’s actual workflows, such as drafting emails, analysing customer information or generating marketing content.

Role-based training

Enhanced instruction may be required for HR teams using recruitment AI, marketers publishing AI-generated content, developers creating AI products, procurement teams assessing vendors, managers relying on automated recommendations and compliance personnel overseeing AI governance.

High-risk AI training

Employees responsible for high-risk AI should understand the system’s intended purpose, performance limitations, input-data requirements and warning signals. They should also know how to interpret outputs, resist automation bias, override recommendations, preserve logs and escalate incidents or fundamental-rights concerns. Deployers of high-risk systems retain specific obligations to ensure that personnel responsible for human oversight are appropriately trained.

Document training

Maintain records of training content, target audiences, attendance, completion dates, knowledge checks, role-specific modules, refresher schedules and material updates.

The Commission’s AI literacy questions and answers confirms that AI literacy measures should be risk-based and adapted to staff knowledge, organisational roles and actual use contexts. Buying a generic AI course alone does not complete compliance. Training must connect directly to the SME’s systems, responsibilities and identified risks.

How the AI Act Interacts with the GDPR

AI Act compliance does not replace data-protection compliance. When an AI system processes personal data, the EU AI Act and the GDPR may apply at the same time. The AI Act focuses on system risks, regulatory roles and AI-specific controls, while the GDPR governs how personal data is collected, used, stored and shared. The CNIL confirms that organisations using personal data through AI systems must continue to respect the GDPR and individuals’ rights.

Key GDPR questions

For each AI use, SMEs should assess:

  • What personal data is processed?

  • What is the lawful basis?

  • Does the system use sensitive data?

  • Have affected individuals received clear information?

  • Is the processing necessary and proportionate?

  • Does it involve automated decision-making?

  • Is a data protection impact assessment required?

  • How long will the data be retained?

  • Is data transferred outside the EEA?

  • Can individuals exercise access, correction, objection and deletion rights?

Generative AI risks

Generative AI creates additional risks when employees enter customer, applicant or employee information into prompts. SMEs should examine whether providers retain prompts, reuse data for model training or transfer information internationally.

Other issues include model memorisation, unclear training-data sources, inaccurate outputs and the practical ability to respond to data-subject requests. The CNIL notes that some AI models may remain subject to the GDPR when they memorise personal data from training.

Combine AI and privacy assessments where practical

SMEs can coordinate AI risk classification, data protection impact assessments, legitimate-interest assessments, security reviews, vendor due diligence and fundamental-rights analysis. This reduces duplication and helps teams identify connected risks.

However, one assessment does not automatically replace another. Each must address its own legal requirements and decision criteria. The CNIL’s official AI compliance guidance for professionals provides a practical starting point for aligning AI use with GDPR obligations.

AI Vendor and Procurement Due Diligence

Most SMEs rely on third-party AI rather than building systems internally. That does not remove compliance responsibility. Vendor-provided AI should be reviewed before purchase, controlled through contract terms and monitored throughout its use.

Questions to ask suppliers

Before approval, request clear information on:

  • The system’s intended purpose

  • The supplier’s AI Act role

  • Risk classification

  • Prohibited-use restrictions

  • Technical and performance limitations

  • Training-data information where relevant

  • Data-processing terms

  • Security controls

  • Human-oversight requirements

  • Logging functions

  • Incident-notification procedures

  • Subcontractors and hosting locations

  • Audit or assurance evidence

  • Exit and data-deletion procedures

  • Commitments to notify material changes

Supplier claims should be compared with the system’s actual configuration and proposed business use.

Contract controls

Contracts should address regulatory cooperation, access to compliance documentation, incident notification, cybersecurity, model or system changes, subcontracting, data use, intellectual property, liability, termination and transition assistance.

The agreement should also clarify who is responsible for maintaining logs, configuring transparency notices, supporting human oversight and notifying the SME when changes may affect risk classification or legal obligations.

Monitor vendors after purchase

Vendor due diligence is not complete at signing. Require reassessment when the supplier changes the model, adds functionality, alters the intended purpose, appoints new subprocessors, modifies data-use terms, experiences a security incident or changes its risk-classification position.

SMEs should record reviews, unresolved issues and required corrective actions in the AI inventory. A vendor relationship should be suspended or escalated where essential documentation, security assurances or legal controls remain unavailable.

Create a Proportionate SME AI Governance Framework

Effective AI governance for SMEs does not require a large committee or a complex corporate structure. A smaller organisation can manage AI risk effectively by assigning clear responsibilities, applying proportionate controls and documenting how important decisions are made.

Assign ownership

Responsibility should be distributed across the people who understand the business, legal and technical risks. Relevant roles may include:

  • An executive sponsor

  • An AI compliance owner

  • A business-system owner

  • The data protection officer

  • An information-security lead

  • An HR or legal representative

  • A procurement owner

In a smaller company, one person may perform several roles. However, accountability should remain clear for system approval, risk classification, monitoring, incidents and regulatory escalation.

Establish core controls

At minimum, the governance framework should include:

  1. An AI usage policy

  2. An AI systems inventory

  3. A risk-classification process

  4. Procurement and vendor review

  5. An approved-tools list

  6. Prohibited-use rules

  7. Human-oversight requirements

  8. An AI incident procedure

  9. A role-based training programme

  10. A periodic review process

These controls should connect to existing privacy, cybersecurity, employment and procurement procedures wherever possible.

Introduce proportionate approval levels

Approval requirements should reflect the potential risk:

  • Low-risk productivity tool: business-owner approval

  • Tool processing personal data: privacy and security review

  • Employment or customer decision system: legal and compliance review

  • Potential high-risk system: formal risk assessment and executive approval

  • Potential prohibited practice: stop use and escalate immediately

Use recognised frameworks appropriately

ISO/IEC 42001 can help organisations structure an AI management system around leadership, risk, controls, monitoring and continual improvement.

However, ISO certification is not a universal AI Act requirement, and the standard does not replace legal classification or role-specific compliance. SMEs can adopt selected principles to strengthen governance without immediately pursuing formal certification.

AI Incident Management and Monitoring

AI compliance continues after deployment. SMEs should monitor how systems perform in practice, whether users follow approved procedures and whether changes affect the original risk assessment.

Define an AI incident

An AI incident may involve:

  • Discriminatory or unsafe output

  • An incorrect decision affecting an individual

  • Loss of meaningful human control

  • Personal-data exposure

  • A security compromise

  • Unexpected system behaviour

  • Missing transparency information

  • Use outside the intended purpose

  • Repeated hallucinations causing material harm

  • Employee use of an unapproved AI tool

Incidents should be assessed according to their actual impact, not only their technical severity.

Create an escalation procedure

The response process should cover:

  1. Immediate containment

  2. Preservation of logs and evidence

  3. Assessment of affected individuals

  4. Internal notification

  5. Vendor notification

  6. Legal and regulatory assessment

  7. Corrective action

  8. Documentation

  9. Follow-up monitoring

Clear ownership is essential so employees know when and how to escalate concerns.

Monitor system changes

Compliance should be reviewed when models are updated, new features are activated, business use changes, new data sources are introduced or vendor terms are revised. Reassessment may also be necessary after performance declines, incidents, security events or changes to regulation and official guidance.

Each material change should trigger an update to the AI inventory, risk classification and applicable controls.

AI Act Penalties and Business Consequences

AI Act penalties depend on the nature, severity and duration of the infringement, the organisation’s role and the circumstances of the case. Enforcement exposure may arise from prohibited AI practices, failure to meet system-specific or operator obligations, providing incorrect or misleading information, refusing to cooperate with competent authorities or breaching general-purpose AI requirements where applicable. Member States must provide penalties and enforcement measures that are effective, proportionate and dissuasive.

The AI Act requires authorities to consider proportionality, including the interests and economic viability of SMEs. However, smaller businesses are not immune from enforcement. A company that cannot demonstrate its risk classification, human oversight, supplier controls, training or incident response may face greater difficulty defending its compliance position.

Wider business consequences

Regulatory fines are only one part of the risk. Non-compliance may also lead to:

  • Suspension of an AI project

  • Product withdrawal or restricted deployment

  • Contract and supplier disputes

  • Exclusion from procurement opportunities

  • Loss of customer and investor confidence

  • Employment or discrimination claims

  • Parallel GDPR enforcement

  • Security incidents

  • Reputational damage

  • Costly system replacement or redesign

The most effective response is prevention. SMEs should prioritise accurate system inventories, documented classification decisions, meaningful human oversight, vendor due diligence and timely corrective action rather than focusing only on maximum penalty figures.

Practical AI Act Compliance Roadmap for SMEs

AI Act SMEs roadmap showing five compliance steps: discover, classify, control, prepare and maintain for responsible AI governance.


A proportionate roadmap helps SMEs move from uncertainty to evidence-based compliance without creating unnecessary bureaucracy.

Phase 1: Immediate actions

Appoint an AI compliance owner and create a complete AI systems inventory. Record whether the business acts as a provider, deployer, importer or distributor for each system. Check immediately for prohibited practices, establish an approved-tools list and stop employees from entering confidential or personal data into uncontrolled public AI tools.

Introduce a basic AI usage policy and begin role-based AI literacy measures for employees, managers and specialist teams.

Phase 2: Risk classification

Assess whether each tool falls within the AI Act definition. Identify potential high-risk AI systems and any Article 50 transparency obligations. Document the reasoning behind each classification, escalate uncertain cases and review whether the system also triggers GDPR requirements.

Phase 3: Vendor and process controls

Review AI contracts and request relevant compliance documentation from suppliers. Assess data use, security, intended purpose, logging, incident procedures and system limitations.

Define meaningful human oversight, establish incident-notification requirements and add AI due diligence to procurement and change-management processes.

Phase 4: High-risk readiness

Where relevant, review the provider’s instructions, assign trained oversight personnel and validate operational controls. Configure logging, prepare monitoring and escalation procedures, assess fundamental-rights impacts and confirm any worker or employee-representative notification duties.

Phase 5: Ongoing governance

Refresh the AI inventory regularly and review material system or vendor changes. Monitor regulatory guidance, analyse incidents, repeat staff training and audit high-impact systems.

Policies and controls should be updated after significant changes in functionality, intended use, data sources or legal requirements. Material risks, unresolved weaknesses and corrective actions should be reported to leadership.

AI Act Compliance Checklist for SMEs

Use this checklist to test whether your organisation has the basic controls needed for proportionate, evidence-based AI Act compliance.

Scope and ownership

  • Have we appointed an AI compliance owner?

  • Have we identified all AI systems in use?

  • Have we assigned a business owner to each system?

  • Have we recorded whether we act as provider, deployer, importer or distributor?

Classification

  • Have we checked for prohibited AI practices?

  • Have we assessed whether any system is high-risk?

  • Have we identified applicable transparency obligations?

  • Have we documented the reasoning behind each classification?

People and training

  • Have relevant employees received AI training?

  • Is training tailored to actual roles, systems and risks?

  • Are human reviewers trained to challenge and override outputs?

  • Are completion records and refresher schedules retained?

Data and security

  • Does the system process personal or sensitive data?

  • Have we assessed GDPR obligations?

  • Are confidential inputs restricted?

  • Have cybersecurity risks been reviewed?

  • Are logs retained securely and for an appropriate period?

Vendors

  • Has the supplier disclosed the system’s intended purpose?

  • Have we requested relevant compliance documentation?

  • Does the contract address incidents and system changes?

  • Are subcontractors, hosting locations and data flows understood?

Operations

  • Are users following approved instructions?

  • Is human oversight meaningful?

  • Are required transparency notices active?

  • Is AI-generated content labelled where necessary?

  • Is there a documented incident procedure?

  • Is each system reviewed after material changes and at scheduled intervals?

Common AI Act Compliance Mistakes

Mistake 1: Assuming the AI Act only affects AI developers
Correction: Assess whether the business also acts as a deployer, importer, distributor or product manufacturer.

Mistake 2: Treating every AI tool as high-risk
Correction: Apply the legal classification criteria based on intended purpose, product category and decision impact.

Mistake 3: Assuming all generative AI is low-risk
Correction: Review transparency, data protection, intellectual property, confidentiality and use-case risks.

Mistake 4: Buying a generic policy without creating an inventory
Correction: Build the compliance programme around the organisation’s actual AI systems, suppliers and workflows.

Mistake 5: Relying entirely on the vendor
Correction: Verify documentation, configure operational controls and monitor how the system performs in practice.

Mistake 6: Providing the same AI training to everyone
Correction: Tailor training to employee roles, systems, decision-making authority and risk exposure.

Mistake 7: Ignoring employee use of public AI tools
Correction: Establish approved tools, input restrictions, escalation routes and clear reporting rules.

Mistake 8: Treating compliance as a one-time project
Correction: Review vendor updates, system changes, incidents, performance issues and new regulatory guidance on an ongoing basis.

Build Practical AI Awareness Across Your Organisation

Help Your Employees Use AI Responsibly

AI Act compliance starts with people understanding how AI works, where its risks arise and when human judgement is required. Employees should know how to use AI tools without exposing confidential information, relying uncritically on inaccurate outputs or creating avoidable legal, privacy and operational risks.

The French Compliance Institute’s AI for Everyone course introduces the practical foundations of artificial intelligence, responsible use and informed decision-making for non-technical professionals.

The course can support broader AI literacy efforts, but it should form part of a wider programme tailored to the organisation’s systems, employee roles and risk exposure.

Conclusion

The AI Act can apply to SMEs acting as providers, deployers, importers, distributors or product manufacturers. Compliance should begin with an AI inventory, a clear role assessment and documented risk classification. Prohibited and high-risk uses require the closest attention, supported by transparency, meaningful human oversight, vendor controls and reliable records.

GDPR and other legal requirements still apply, while AI training should reflect the company’s actual systems, employees and risk exposure. SMEs that understand their AI systems, train their staff and introduce proportionate governance controls will be better prepared to use AI productively while meeting the requirements of EU AI regulation.

Frequently Asked Questions

The analysis depends on the activity involved. The AI Act distinguishes between providers of general-purpose AI models, providers integrating models into AI systems and organisations deploying those systems. ChatGPT is an AI assistant powered by OpenAI models, but an SME must still assess its own use case, data inputs, transparency duties and resulting system responsibilities.

The AI Act does not prescribe one identical AI policy for every business. However, a documented policy is a practical governance control for SMEs using AI. It can define approved tools, prohibited uses, data-input restrictions, human-review requirements, procurement approval, incident reporting and employee responsibilities.

Article 4 requires providers and deployers to take measures supporting AI literacy among relevant staff and other people using AI systems on their behalf. Following the 2026 amendments, the obligation remains, but companies are not required to guarantee a specific level of literacy for every individual. Measures should reflect roles, knowledge, context and risk.

High-risk AI may include systems used for recruitment, candidate evaluation, worker management, vocational training, access to essential services and certain creditworthiness assessments. AI incorporated into regulated products may also qualify. Classification depends on intended purpose and impact, not simply technical complexity.

Not automatically, but many recruitment and employment uses appear in Annex III. Systems used to filter applications, evaluate candidates or influence employment decisions require close assessment. A limited exception may apply where a system performs a narrow task and does not materially influence decision-making, but the reasoning must be documented.

No. Both frameworks may apply when an AI system processes personal data. The AI Act addresses system classification, operator duties and AI-specific risks, while the GDPR governs lawful processing, transparency, individual rights, security, retention and international transfers. Completing an AI risk assessment does not automatically satisfy data-protection obligations.

No. ISO/IEC 42001 certification is not a universal requirement under the AI Act. The standard can help structure responsibilities, risk management, monitoring and continual improvement, but it does not replace legal role assessment, system classification or compliance with binding AI Act obligations.

Appoint an accountable owner, create an AI systems inventory and identify the company’s role for each tool. Then check for prohibited practices, assess high-risk and transparency requirements, review GDPR implications and begin role-based AI literacy measures. These steps create the evidence needed for proportionate AI governance.

Non. La certification ISO/IEC 42001 ne constitue pas une exigence générale imposée par l’AI Act. La norme peut aider à structurer les responsabilités, la gestion des risques, la surveillance et l’amélioration continue, mais elle ne remplace ni l’analyse du rôle juridique de l’organisation, ni la classification des systèmes, ni le respect des obligations contraignantes prévues par l’AI Act.