How to Create a HACCP Plan
Learn how to create a HACCP plan step by step, from hazard analysis and CCPs to critical limits, monitoring, corrective actions, verification, and records.
AI Act SMEs guide to roles, risk classification, high-risk systems, AI literacy, vendor due diligence, GDPR, and practical compliance steps.
The EU AI Act is not limited to technology companies or businesses developing complex AI models. It may also apply to SMEs that purchase third-party AI software, use AI in recruitment or employee management, deploy chatbots, create AI-assisted content, or integrate automated tools into routine business processes.
AI Act compliance for SMEs begins with understanding which AI systems the business uses, what role it performs, and how each system is classified under the EU’s risk-based framework. An SME may be regulated as a provider, deployer, importer, distributor, or product manufacturer. It may also assume additional responsibilities by modifying, rebranding, or placing another provider’s AI system on the market under its own name.
Company size does not create a general exemption. The applicable obligations depend primarily on the organization's regulatory role, the system’s intended purpose, and the risks associated with its use.
This guide explains how SMEs can identify their role, build an AI inventory, classify systems, stop prohibited practices, assess high-risk AI, implement transparency controls, strengthen AI literacy, review suppliers, and maintain evidence of compliance.
Regulation (EU) 2024/1689, commonly known as the EU AI Act, establishes harmonised rules for the development, placement on the market, deployment, and use of artificial intelligence across the European Union. It creates a common legal framework for organisations that build, supply, import, distribute, or use covered AI systems.
The regulation aims to promote safe and trustworthy AI while protecting health, safety, and fundamental rights. It also seeks to establish consistent rules across EU Member States, support responsible innovation, and create clearer accountability throughout the AI value chain.
For SMEs, this means compliance responsibilities may arise at different stages, from product development and procurement to deployment, monitoring, and customer communication.
The AI Act does not impose identical requirements on every AI tool. Instead, obligations depend on the system’s characteristics, intended purpose, and potential impact.
The main categories are
Prohibited AI practices that create unacceptable risks
High-risk AI systems subject to extensive controls
AI systems covered by specific transparency requirements
Minimal or limited-risk systems that generally face fewer mandatory obligations
An SME must therefore classify each AI use correctly before deciding which compliance measures are required.
Yes. The AI Act can apply to micro, small and medium-sized businesses. SME status may influence how certain requirements are implemented, but it does not create a general exemption from EU AI regulation.
The key question is not simply how many people the company employs. An SME must determine whether it provides or deploys an AI system, imports or distributes one, or integrates AI into a product sold under its own name. Regulatory responsibilities may also change when the business rebrands a third-party system, substantially modifies it or changes its intended purpose.
The AI Act may apply to:
Providers placing AI systems or general-purpose AI models on the EU market
EU-based organisations deploying AI in their business activities
Importers and distributors making AI systems available in the EU
Providers and deployers established outside the EU when the system’s output is used within the EU
This means a non-EU supplier or business may still fall within scope when its AI products, services or outputs reach the European market.
The European Commission’s AI Act regulatory framework overview explains that the framework includes measures intended to support innovation and proportionate implementation. These include regulatory sandboxes, targeted guidance, dedicated communication channels and simplified compliance pathways for specified obligations. SMEs may also receive priority access to certain sandbox arrangements, while relevant conformity-assessment fees should take account of their size and interests.
These measures can reduce unnecessary administrative burdens, but SMEs must still identify their role, classify their AI systems and meet every obligation that applies to their activities.
An SME’s obligations depend heavily on the regulatory role it performs. The same AI system can create different responsibilities for the organisation that develops it, the business that deploys it and the companies that place it on the EU market.
An SME may be a provider when it develops an AI system or general-purpose AI model, has one developed on its behalf, or places the system on the market under its own name or trademark.
Examples include a software company selling an AI recruitment tool, a health-technology business developing diagnostic software or an organisation rebranding a third-party AI product as its own.
A deployer uses an AI system under its authority in a professional or organisational context. Most SMEs using commercial AI tools are more likely to be deployers than providers.
Examples include an employer using an AI recruitment platform, a retailer operating a customer-service chatbot, a business deploying productivity-monitoring software or a financial company using AI-assisted fraud detection.
An importer introduces an AI system from a third country into the EU market. A distributor makes an AI system available within the supply chain without necessarily developing or importing it.
An SME may have additional responsibilities when an AI system is integrated into a regulated product sold under its name. This is especially relevant where the AI performs a safety-related function.
A supplier agreement can allocate commercial duties, but it cannot override the role the company actually performs under the AI Act. Regulators will look at the business’s real activities, not only the labels used in the contract.
SMEs should record their regulatory role for every system in the AI inventory and reassess it whenever the product, branding, intended purpose or level of control changes.
Build Practical AI Act & Governance Expertise
Understand the EU AI Act, AI governance responsibilities, privacy risks, high-risk AI controls, human oversight and risk management. Build practical knowledge for responsible AI governance and receive a free Certificate of Completion when you successfully complete the course.
Explore AI Act Training →SMEs cannot assess AI Act compliance until they know where and how artificial intelligence is being used across the organisation. An AI systems inventory creates that visibility and provides the foundation for role assessment, risk classification, vendor review, transparency controls and staff training.
For each system, record the product name, supplier, business owner, department, intended purpose and authorised users. The inventory should also identify affected individuals, the data processed, the type of output produced and the level of human involvement.
Compliance fields should include the company’s regulatory role, the system’s risk classification, applicable transparency obligations, contract status and next review date. Recording the intended purpose is particularly important because changing how a system is used can alter its legal classification or the company’s responsibilities.
The inventory should capture more than centrally purchased software. Common examples include employees using public generative AI tools, AI-assisted email drafting, automated meeting transcription, embedded office-software features, candidate screening, customer sentiment analysis, AI image or video generation, fraud or credit tools and employee productivity analytics.
These uses may otherwise remain invisible to legal, compliance, security and procurement teams.
Require employees to notify a designated owner before purchasing a tool, activating an AI feature, uploading business data, running a pilot, integrating an API or using AI to support employment or customer decisions.
The inventory should be treated as a living governance record. Update it when systems, suppliers, features, data sources, intended purposes or business owners change.

AI risk classification should follow a documented decision sequence. SMEs should assess the system’s legal definition, intended purpose and real-world use rather than relying solely on vendor descriptions or the perceived sophistication of the technology.
Not every automated rule, calculator, spreadsheet formula or conventional software application qualifies as an AI system. The assessment should examine how the technology operates, whether it infers how to generate outputs from inputs and the extent to which those outputs influence physical or virtual environments.
The European Commission’s guidelines on the definition of an AI system provide practical, non-binding guidance for applying the legal definition.
Check the intended and actual use against the prohibited-practices rules. A system that involves harmful manipulation, certain forms of social scoring, prohibited emotion recognition or restricted biometric practices may require immediate suspension and legal assessment.
Determine whether the system:
Is a safety component of a regulated product
Falls within a listed high-risk use case
Meets the conditions for an exception or exclusion
The classification depends primarily on intended purpose and impact, not simply technical complexity.
Check whether the system interacts directly with individuals or generates synthetic audio, images, video or text. Additional requirements may apply to deepfakes, emotion-recognition systems and biometric-categorisation tools.
An SME purchasing access to a general-purpose model will not ordinarily become the model provider. However, developing, placing on the market or substantially modifying such a model may create broader provider obligations.
AI Act classification is only one part of the assessment. SMEs should also consider the GDPR, employment law, consumer protection, product safety, intellectual property, cybersecurity and sector-specific regulation.
Record the reasoning, evidence, reviewer and review date for every classification decision.
Some AI uses are prohibited because they create unacceptable risks to individuals, fundamental rights or society. Article 5 of the AI Act covers practices such as harmful manipulation or deception, exploitation of vulnerabilities, certain forms of social scoring and specified individual criminal-risk predictions. It also restricts untargeted facial-image scraping, certain biometric categorisation based on sensitive characteristics, emotion recognition in workplaces and schools, and specific real-time remote biometric identification uses by law-enforcement authorities.
The European Commission’s guidelines on prohibited AI practices provide legal explanations and practical examples to help organisations assess whether a planned or existing use falls within these categories. The guidelines are intended to support interpretation, but the facts and context of each deployment still require careful assessment.
An employer should not assume that a tool is lawful because a supplier markets it as an employee-engagement, wellbeing or productivity solution. If the system attempts to infer employees’ emotions from facial expressions, voice, behaviour or biometric signals, its use may fall within the workplace emotion-recognition prohibition.
Procurement, HR and compliance teams should screen proposed systems for:
Biometric functions
Emotion analysis
Behavioural or social scoring
Manipulative personalisation
Vulnerability targeting
Facial-image collection or scraping
Supplier descriptions should be tested against the system’s actual functionality, intended purpose and possible configurations.
Where a tool may involve a prohibited practice, the SME should stop procurement, testing or deployment and obtain a documented legal assessment before proceeding. Disabling the relevant function may be necessary, but employers should verify that it cannot be reactivated or used indirectly.
High-risk AI is not defined by how advanced, expensive or technically complex a system appears. Classification depends on the system’s intended purpose, the product or activity in which it is used and its potential effect on health, safety or fundamental rights. Under the AI Act, high-risk systems generally fall into two routes: AI connected to certain regulated products and AI used for specified purposes listed in Annex III.
An AI system may be classified as high-risk when it serves as a safety component of a product covered by specified EU product legislation, or when the AI-enabled product itself must undergo a third-party conformity assessment before being placed on the market.
This route may be relevant to SMEs developing or selling regulated machinery, medical devices, safety equipment or other products covered by the legislation referenced in the AI Act.
The Annex III categories most relevant to SMEs can include AI used for:
Recruitment and candidate selection
Employment decisions and worker management
Task allocation and performance monitoring
Access to vocational education or training
Creditworthiness assessment
Risk assessment and pricing in certain life and health insurance contexts
Access to essential private or public services
Certain biometric applications
Specified safety, law-enforcement, migration and justice purposes
Employment-related systems require particularly close assessment. Examples include CV-screening and candidate-ranking tools, automated interview analysis, promotion recommendations, disciplinary or dismissal decision support, employee task-allocation software and performance-monitoring systems.
An SME should assess what the system actually influences. A tool described as administrative support may still be high-risk when its output materially shapes who is recruited, promoted, monitored or dismissed.
Some Annex III systems may fall outside high-risk classification when they perform a narrow procedural or preparatory task, improve the result of a completed human activity, detect patterns without replacing human assessment, or do not materially influence the relevant decision. Systems that profile individuals remain subject to stricter treatment.
Employers should not rely on an exception without recording the intended purpose, decision impact, human involvement and supporting evidence. The European Commission’s guidelines for providers and deployers of high-risk AI systems provide practical classification examples, but each SME remains responsible for assessing its own system and use case.
This section is primarily relevant to SMEs that develop, brand or substantially modify high-risk AI systems. Providers carry broader responsibilities than businesses that simply use an AI tool because they must demonstrate that the system meets the AI Act’s requirements before and after it reaches the market.
Core provider controls include:
A continuous risk-management system
Appropriate data and data-governance controls
Technical documentation
Automatic record-keeping and logging capabilities
Clear instructions and transparency information for deployers
Effective human-oversight design
Appropriate accuracy, robustness and cybersecurity
A documented quality-management system
Conformity assessment before market placement or use
Registration where required
Post-market monitoring
Serious-incident reporting
Corrective action when non-compliance or risk is identified
These controls should operate across the system’s lifecycle rather than being completed only at product launch.
A deployer, distributor or other business may become the provider when it places an AI system on the market under its own name or trademark, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk. A change that affects regulatory compliance may also require the system to undergo a new conformity assessment.
SMEs should avoid creating a paperwork-heavy compliance structure that is disconnected from product development. Evidence should instead be integrated into existing operational records, including:
Product requirements
Testing and validation records
Change-management processes
Security reviews
Supplier documentation
Release and approval decisions
This approach makes compliance evidence easier to maintain, audit and update while supporting effective product governance.
This section is particularly relevant to SMEs that purchase and use high-risk AI rather than develop it. A deployer must operate the system within its intended purpose and take appropriate technical and organisational measures to follow the provider’s instructions.
Depending on the system and context, the SME may need to:
Assign competent personnel to provide human oversight
Ensure input data is relevant and sufficiently representative where it controls that data
Monitor the system’s operation and identify unexpected risks
Retain automatically generated logs under its control
Suspend use when the system may create unacceptable risks
Report serious incidents or malfunctions through the required channels
Inform workers and employee representatives before certain workplace deployments
Cooperate with competent authorities
Complete a fundamental-rights impact assessment where the legal conditions apply
The Commission’s official Navigating the AI Act questions and answers provides practical guidance on deployer responsibilities, including input-data quality, affected-person notices and fundamental-rights assessments.
Human review must be meaningful, not a routine approval of the AI output. The designated reviewer should understand the system’s purpose, limitations and expected performance. They must be able to recognise automation bias, interpret outputs critically, reject or override recommendations, escalate concerns and stop use where necessary.
The SME should give reviewers sufficient authority, time, information and training to intervene effectively.
Before deployment, request and review:
Instructions for use
The intended-purpose statement
Risk-classification information
Performance limitations
Human-oversight requirements
Logging capabilities
Incident procedures
Cybersecurity information
Relevant compliance documentation
Vendor claims do not remove the deployer’s responsibility to configure, monitor and use the system lawfully. The SME should record its review, operational controls and any unresolved limitations in the AI inventory.
Some AI systems are subject to transparency requirements even when they are not classified as high-risk. Article 50 of the AI Act applies to specified interactive, generative and content-manipulation systems, with the relevant obligations applying from 2 August 2026. SMEs should assess whether they act as the provider of the system, the deployer using it or both.
Where required, individuals must be informed that they are interacting with an AI system unless this is already obvious to a reasonably informed and attentive person.
Relevant SME examples may include:
Customer-service chatbots
AI reception systems
Automated support assistants
Voice bots
The notice should be clear, timely and visible before or during the interaction, rather than hidden in lengthy terms and conditions.
Providers of certain systems that generate synthetic audio, images, video or text may need to enable machine-readable marking so the content can be detected as artificially generated or manipulated. Deployers may also need to label deepfakes and disclose specified AI-generated text published to inform the public on matters of public interest, subject to relevant exceptions and editorial safeguards.
SMEs should establish approval rules for synthetic spokespersons, AI-generated testimonials, manipulated product demonstrations, news-style content, voice cloning, deepfake video and undisclosed automated conversations. Human editorial review should verify accuracy, context, permissions and the risk of misleading customers.
Document:
Where interaction notices appear
Which content is labelled
Who performs editorial review
Which machine-readable marking features are enabled
Which legal exceptions are relied upon
The European Commission’s official guidelines on transparency obligations for AI systems provide practical guidance for applying Article 50 consistently and proportionately.
Effective AI training should be proportionate to the SME’s systems, workforce and risk exposure. Article 4 requires providers and deployers to take measures that support the development of AI literacy among staff and other people who operate or use AI systems on their behalf. The approach should reflect the organisation’s regulatory role, employees’ technical knowledge and experience, the context in which AI is used, the decisions it affects and the people who may be harmed. The current framework does not prescribe one identical course or a specific level of literacy for every employee.
Employees who use or encounter AI should understand:
What AI is and which systems the company permits
Common limitations, including hallucinations and unreliable outputs
Confidentiality and personal-data risks
Intellectual-property concerns
Bias and discrimination risks
Human-review expectations
Incident-reporting procedures
Prohibited or unauthorised uses
Training should use examples drawn from the organisation’s actual workflows, such as drafting emails, analysing customer information or generating marketing content.
Enhanced instruction may be required for HR teams using recruitment AI, marketers publishing AI-generated content, developers creating AI products, procurement teams assessing vendors, managers relying on automated recommendations and compliance personnel overseeing AI governance.
Employees responsible for high-risk AI should understand the system’s intended purpose, performance limitations, input-data requirements and warning signals. They should also know how to interpret outputs, resist automation bias, override recommendations, preserve logs and escalate incidents or fundamental-rights concerns. Deployers of high-risk systems retain specific obligations to ensure that personnel responsible for human oversight are appropriately trained.
Maintain records of training content, target audiences, attendance, completion dates, knowledge checks, role-specific modules, refresher schedules and material updates.
The Commission’s AI literacy questions and answers confirms that AI literacy measures should be risk-based and adapted to staff knowledge, organisational roles and actual use contexts. Buying a generic AI course alone does not complete compliance. Training must connect directly to the SME’s systems, responsibilities and identified risks.
AI Act compliance does not replace data-protection compliance. When an AI system processes personal data, the EU AI Act and the GDPR may apply at the same time. The AI Act focuses on system risks, regulatory roles and AI-specific controls, while the GDPR governs how personal data is collected, used, stored and shared. The CNIL confirms that organisations using personal data through AI systems must continue to respect the GDPR and individuals’ rights.
For each AI use, SMEs should assess:
What personal data is processed?
What is the lawful basis?
Does the system use sensitive data?
Have affected individuals received clear information?
Is the processing necessary and proportionate?
Does it involve automated decision-making?
Is a data protection impact assessment required?
How long will the data be retained?
Is data transferred outside the EEA?
Can individuals exercise access, correction, objection and deletion rights?
Generative AI creates additional risks when employees enter customer, applicant or employee information into prompts. SMEs should examine whether providers retain prompts, reuse data for model training or transfer information internationally.
Other issues include model memorisation, unclear training-data sources, inaccurate outputs and the practical ability to respond to data-subject requests. The CNIL notes that some AI models may remain subject to the GDPR when they memorise personal data from training.
SMEs can coordinate AI risk classification, data protection impact assessments, legitimate-interest assessments, security reviews, vendor due diligence and fundamental-rights analysis. This reduces duplication and helps teams identify connected risks.
However, one assessment does not automatically replace another. Each must address its own legal requirements and decision criteria. The CNIL’s official AI compliance guidance for professionals provides a practical starting point for aligning AI use with GDPR obligations.
Most SMEs rely on third-party AI rather than building systems internally. That does not remove compliance responsibility. Vendor-provided AI should be reviewed before purchase, controlled through contract terms and monitored throughout its use.
Before approval, request clear information on:
The system’s intended purpose
The supplier’s AI Act role
Risk classification
Prohibited-use restrictions
Technical and performance limitations
Training-data information where relevant
Data-processing terms
Security controls
Human-oversight requirements
Logging functions
Incident-notification procedures
Subcontractors and hosting locations
Audit or assurance evidence
Exit and data-deletion procedures
Commitments to notify material changes
Supplier claims should be compared with the system’s actual configuration and proposed business use.
Contracts should address regulatory cooperation, access to compliance documentation, incident notification, cybersecurity, model or system changes, subcontracting, data use, intellectual property, liability, termination and transition assistance.
The agreement should also clarify who is responsible for maintaining logs, configuring transparency notices, supporting human oversight and notifying the SME when changes may affect risk classification or legal obligations.
Vendor due diligence is not complete at signing. Require reassessment when the supplier changes the model, adds functionality, alters the intended purpose, appoints new subprocessors, modifies data-use terms, experiences a security incident or changes its risk-classification position.
SMEs should record reviews, unresolved issues and required corrective actions in the AI inventory. A vendor relationship should be suspended or escalated where essential documentation, security assurances or legal controls remain unavailable.
Effective AI governance for SMEs does not require a large committee or a complex corporate structure. A smaller organisation can manage AI risk effectively by assigning clear responsibilities, applying proportionate controls and documenting how important decisions are made.
Responsibility should be distributed across the people who understand the business, legal and technical risks. Relevant roles may include:
An executive sponsor
An AI compliance owner
A business-system owner
An information-security lead
An HR or legal representative
A procurement owner
In a smaller company, one person may perform several roles. However, accountability should remain clear for system approval, risk classification, monitoring, incidents and regulatory escalation.
At minimum, the governance framework should include:
An AI usage policy
An AI systems inventory
A risk-classification process
Procurement and vendor review
An approved-tools list
Prohibited-use rules
Human-oversight requirements
An AI incident procedure
A role-based training programme
A periodic review process
These controls should connect to existing privacy, cybersecurity, employment and procurement procedures wherever possible.
Approval requirements should reflect the potential risk:
Low-risk productivity tool: business-owner approval
Tool processing personal data: privacy and security review
Employment or customer decision system: legal and compliance review
Potential high-risk system: formal risk assessment and executive approval
Potential prohibited practice: stop use and escalate immediately
ISO/IEC 42001 can help organisations structure an AI management system around leadership, risk, controls, monitoring and continual improvement.
However, ISO certification is not a universal AI Act requirement, and the standard does not replace legal classification or role-specific compliance. SMEs can adopt selected principles to strengthen governance without immediately pursuing formal certification.
AI compliance continues after deployment. SMEs should monitor how systems perform in practice, whether users follow approved procedures and whether changes affect the original risk assessment.
An AI incident may involve:
Discriminatory or unsafe output
An incorrect decision affecting an individual
Loss of meaningful human control
Personal-data exposure
A security compromise
Unexpected system behaviour
Missing transparency information
Use outside the intended purpose
Repeated hallucinations causing material harm
Employee use of an unapproved AI tool
Incidents should be assessed according to their actual impact, not only their technical severity.
The response process should cover:
Immediate containment
Preservation of logs and evidence
Assessment of affected individuals
Internal notification
Vendor notification
Legal and regulatory assessment
Corrective action
Documentation
Follow-up monitoring
Clear ownership is essential so employees know when and how to escalate concerns.
Compliance should be reviewed when models are updated, new features are activated, business use changes, new data sources are introduced or vendor terms are revised. Reassessment may also be necessary after performance declines, incidents, security events or changes to regulation and official guidance.
Each material change should trigger an update to the AI inventory, risk classification and applicable controls.
AI Act penalties depend on the nature, severity and duration of the infringement, the organisation’s role and the circumstances of the case. Enforcement exposure may arise from prohibited AI practices, failure to meet system-specific or operator obligations, providing incorrect or misleading information, refusing to cooperate with competent authorities or breaching general-purpose AI requirements where applicable. Member States must provide penalties and enforcement measures that are effective, proportionate and dissuasive.
The AI Act requires authorities to consider proportionality, including the interests and economic viability of SMEs. However, smaller businesses are not immune from enforcement. A company that cannot demonstrate its risk classification, human oversight, supplier controls, training or incident response may face greater difficulty defending its compliance position.
Regulatory fines are only one part of the risk. Non-compliance may also lead to:
Suspension of an AI project
Product withdrawal or restricted deployment
Contract and supplier disputes
Exclusion from procurement opportunities
Loss of customer and investor confidence
Employment or discrimination claims
Parallel GDPR enforcement
Security incidents
Reputational damage
Costly system replacement or redesign
The most effective response is prevention. SMEs should prioritise accurate system inventories, documented classification decisions, meaningful human oversight, vendor due diligence and timely corrective action rather than focusing only on maximum penalty figures.

A proportionate roadmap helps SMEs move from uncertainty to evidence-based compliance without creating unnecessary bureaucracy.
Appoint an AI compliance owner and create a complete AI systems inventory. Record whether the business acts as a provider, deployer, importer or distributor for each system. Check immediately for prohibited practices, establish an approved-tools list and stop employees from entering confidential or personal data into uncontrolled public AI tools.
Introduce a basic AI usage policy and begin role-based AI literacy measures for employees, managers and specialist teams.
Assess whether each tool falls within the AI Act definition. Identify potential high-risk AI systems and any Article 50 transparency obligations. Document the reasoning behind each classification, escalate uncertain cases and review whether the system also triggers GDPR requirements.
Review AI contracts and request relevant compliance documentation from suppliers. Assess data use, security, intended purpose, logging, incident procedures and system limitations.
Define meaningful human oversight, establish incident-notification requirements and add AI due diligence to procurement and change-management processes.
Where relevant, review the provider’s instructions, assign trained oversight personnel and validate operational controls. Configure logging, prepare monitoring and escalation procedures, assess fundamental-rights impacts and confirm any worker or employee-representative notification duties.
Refresh the AI inventory regularly and review material system or vendor changes. Monitor regulatory guidance, analyse incidents, repeat staff training and audit high-impact systems.
Policies and controls should be updated after significant changes in functionality, intended use, data sources or legal requirements. Material risks, unresolved weaknesses and corrective actions should be reported to leadership.
Use this checklist to test whether your organisation has the basic controls needed for proportionate, evidence-based AI Act compliance.
Have we appointed an AI compliance owner?
Have we identified all AI systems in use?
Have we assigned a business owner to each system?
Have we recorded whether we act as provider, deployer, importer or distributor?
Have we checked for prohibited AI practices?
Have we assessed whether any system is high-risk?
Have we identified applicable transparency obligations?
Have we documented the reasoning behind each classification?
Have relevant employees received AI training?
Is training tailored to actual roles, systems and risks?
Are human reviewers trained to challenge and override outputs?
Are completion records and refresher schedules retained?
Does the system process personal or sensitive data?
Have we assessed GDPR obligations?
Are confidential inputs restricted?
Have cybersecurity risks been reviewed?
Are logs retained securely and for an appropriate period?
Has the supplier disclosed the system’s intended purpose?
Have we requested relevant compliance documentation?
Does the contract address incidents and system changes?
Are subcontractors, hosting locations and data flows understood?
Are users following approved instructions?
Is human oversight meaningful?
Are required transparency notices active?
Is AI-generated content labelled where necessary?
Is there a documented incident procedure?
Is each system reviewed after material changes and at scheduled intervals?
Mistake 1: Assuming the AI Act only affects AI developers
Correction: Assess whether the business also acts as a deployer, importer, distributor or product manufacturer.
Mistake 2: Treating every AI tool as high-risk
Correction: Apply the legal classification criteria based on intended purpose, product category and decision impact.
Mistake 3: Assuming all generative AI is low-risk
Correction: Review transparency, data protection, intellectual property, confidentiality and use-case risks.
Mistake 4: Buying a generic policy without creating an inventory
Correction: Build the compliance programme around the organisation’s actual AI systems, suppliers and workflows.
Mistake 5: Relying entirely on the vendor
Correction: Verify documentation, configure operational controls and monitor how the system performs in practice.
Mistake 6: Providing the same AI training to everyone
Correction: Tailor training to employee roles, systems, decision-making authority and risk exposure.
Mistake 7: Ignoring employee use of public AI tools
Correction: Establish approved tools, input restrictions, escalation routes and clear reporting rules.
Mistake 8: Treating compliance as a one-time project
Correction: Review vendor updates, system changes, incidents, performance issues and new regulatory guidance on an ongoing basis.
AI Act compliance starts with people understanding how AI works, where its risks arise and when human judgement is required. Employees should know how to use AI tools without exposing confidential information, relying uncritically on inaccurate outputs or creating avoidable legal, privacy and operational risks.
The French Compliance Institute’s AI for Everyone course introduces the practical foundations of artificial intelligence, responsible use and informed decision-making for non-technical professionals.
The course can support broader AI literacy efforts, but it should form part of a wider programme tailored to the organisation’s systems, employee roles and risk exposure.
The AI Act can apply to SMEs acting as providers, deployers, importers, distributors or product manufacturers. Compliance should begin with an AI inventory, a clear role assessment and documented risk classification. Prohibited and high-risk uses require the closest attention, supported by transparency, meaningful human oversight, vendor controls and reliable records.
GDPR and other legal requirements still apply, while AI training should reflect the company’s actual systems, employees and risk exposure. SMEs that understand their AI systems, train their staff and introduce proportionate governance controls will be better prepared to use AI productively while meeting the requirements of EU AI regulation.