GETTING STARTED9 min

The EU AI Act SME Checklist: What a Small Business Actually Has to Do

A practical EU AI Act SME checklist: how small businesses inventory AI systems, classify their role and risk tier, meet transparency and AI literacy duties, and document the result.

V
Veritome Team
25.07.2026

Key Takeaways

  • 1The EU AI Act applies to organisations of any size, including micro-enterprises; there is no blanket SME exemption, only lighter documentation routes and regulatory sandbox access.
  • 2Most SMEs are deployers of AI systems bought or subscribed from a vendor, not providers, which is the single biggest determinant of how heavy the obligations are.
  • 3For a typical SME using chatbots, CV-screening tools, or generative content tools, the practical duties are AI literacy, transparency, human oversight, and following the provider's instructions for use.
  • 4The prohibited-practice rules and the AI literacy duty have applied since 2 February 2025; the bulk of high-risk system obligations apply from 2 August 2026.
  • 5Putting an SME's own name or trade mark on a third-party high-risk system, or substantially modifying it, converts the SME into a provider with the full documentation burden.
  • 6An AI inventory with owner, purpose, vendor, data used, and affected people is the prerequisite for every other compliance step.

Does the EU AI Act apply to small businesses?

Yes. Regulation (EU) 2024/1689 applies by role and by risk, not by headcount or turnover, so a five-person company that uses an AI system in the EU is in scope exactly as a multinational is. What changes for an SME is the weight of the obligations: micro, small, and medium enterprises may use simplified technical documentation arrangements for high-risk systems, and Member States are required to give SMEs priority access to regulatory sandboxes.

In practice, most SMEs land in the lightest tier. They buy or subscribe to AI tools rather than build them, and those tools are usually not high-risk. The compliance work is then real but bounded: know what you use, confirm nothing is prohibited, meet transparency and literacy duties, and keep a record.

What are the first steps to comply with the EU AI Act?

The ordered sequence below works because each step depends on the one before it. Classification without an inventory is guesswork; documentation without classification documents the wrong things.

Step 1 — Build an AI inventory

List every system in the business that uses AI, including features embedded inside ordinary SaaS — the meeting summariser in the video tool, the ranking model in the recruitment platform, the fraud score in the payments provider. Shadow usage matters: staff pasting customer data into a public chatbot is an AI use of the business.

  • System name and vendor, or "built in-house".
  • Business purpose in one sentence, and who inside the company owns it.
  • Whether it affects people outside the company (customers, applicants, employees).
  • What data goes in, including whether personal data is involved.
  • Whether outputs are acted on automatically or reviewed by a person.

Step 2 — Fix your role for each system

The Regulation assigns duties chiefly to providers (those who develop an AI system, or have one developed, and place it on the market or put it into service under their own name) and to deployers (those who use an AI system under their own authority in a professional capacity). Most SMEs are deployers. The role can flip: putting your own name or trade mark on a high-risk system supplied by someone else, or making a substantial modification to it, brings provider obligations with it.

Step 3 — Place each system in a risk tier

Work top-down. First check the prohibited practices in Art. 5 — for example social scoring, untargeted scraping of facial images to build recognition databases, and emotion inference in the workplace or in education, subject to narrow exceptions. These have been prohibited since 2 February 2025. Next check whether the system is high-risk: either as a safety component of a product already covered by EU product legislation, or because it falls within an Annex III use case such as employment and worker management, access to education, essential private and public services, or creditworthiness assessment. Anything left over is generally subject only to transparency duties, if any.

Step 4 — Map obligations, then document and monitor

Write the obligations against each system, assign an owner, and record the reasoning behind the classification. The reasoning is the artefact a market surveillance authority or a customer's procurement team will ask for, and it is the thing SMEs most often skip.

Which EU AI Act obligations apply to most SMEs?

For an SME that deploys a handful of non-high-risk tools, the recurring duties are short.

  • AI literacy: ensuring staff who use or oversee AI systems have an adequate level of understanding, proportionate to their role and the context. This obligation has applied since 2 February 2025.
  • No prohibited practices: a positive check that nothing in the inventory falls under Art. 5, re-run when tools change.
  • Transparency under Art. 50: telling people they are interacting with an AI system where that is not obvious, and marking synthetic or manipulated content such as deepfakes.
  • Following the provider's instructions for use, and using the system for its intended purpose rather than repurposing it into a different, riskier use.
  • Basic governance: an inventory that is kept current, a named owner per system, and a route for staff to flag problems.
  • If one system does turn out to be high-risk — CV screening and candidate ranking is the common case for SMEs — the deployer obligations expand. They typically include assigning competent human oversight with the authority to intervene, ensuring input data is relevant for the intended purpose where the deployer controls it, retaining automatically generated logs for an appropriate period, informing workers and their representatives before putting the system into use in the workplace, and notifying the provider and the authorities if a serious incident or a risk to health, safety, or fundamental rights emerges.

What is genuinely out of scope for most SMEs

Reading the Regulation front to back makes it look enormous. Large parts of it will never touch a typical small business, and knowing which parts saves weeks.

  • Provider obligations for high-risk systems — risk management systems, conformity assessment, CE marking, EU declarations of conformity, post-market monitoring plans — apply only if the SME actually develops or rebrands such a system.
  • Obligations on providers of general-purpose AI models apply to those who train and place such models on the market, not to businesses that use them through an API or a subscription.
  • Notified body procedures and registration in the EU database are provider- and, for certain public-sector deployers, deployer-specific; they do not attach to ordinary commercial use of a low-risk tool.
  • Purely personal, non-professional use of AI by individuals is outside the Regulation, as is, subject to conditions, free and open-source software that is not high-risk and not placed on the market as such.
  • Research and development activity prior to placing a system on the market is treated differently from deployment in production.

The honest summary for a typical SME: three or four obligations that apply always, one classification exercise that must be done properly, and a large body of law that applies to somebody else in the supply chain.

Dates to work backwards from

  • 1 August 2024 — the Regulation entered into force.
  • 2 February 2025 — prohibitions on unacceptable-risk practices and the AI literacy obligation began to apply.
  • 2 August 2025 — obligations for providers of general-purpose AI models and the governance and penalties framework began to apply.
  • 2 August 2026 — the general date of application, including the Annex III high-risk obligations and the Art. 50 transparency rules.
  • 2 August 2027 — application for high-risk AI systems that are safety components of products covered by EU product legislation listed in Annex I.

An SME planning work in 2026 should treat 2 August 2026 as the hard edge for anything Annex III-adjacent, and treat the literacy and prohibited-practice checks as already due.

  • Inventory every AI system and AI feature in use, including embedded SaaS functionality and informal staff usage.
  • Record your role — provider or deployer — for each entry, and flag any tool you resell or white-label.
  • Screen every entry against the Art. 5 prohibited practices and record the outcome.
  • Screen every entry against the Annex III use cases and the product-safety route, and record the reasoning, not just the verdict.
  • Deliver proportionate AI literacy training to staff who use or oversee these systems, and keep evidence of who was trained and when.
  • Add AI transparency notices where users interact with a system or receive AI-generated content.
  • Read and retain each vendor's instructions for use, and note any way your actual use departs from the intended purpose.
  • Assign a named human overseer for anything high-risk, and confirm log retention with the vendor.
  • Diarise a review whenever a tool is added, a vendor ships a significant model change, or a use case expands.
  • Store the whole thing in one place so it can be produced on request by a customer, an auditor, or an authority.

Frequently Asked Questions

Does the EU AI Act apply to small businesses?

Yes. Regulation (EU) 2024/1689 applies according to the role an organisation plays and the risk of the AI system, not according to company size, so micro and small enterprises are in scope. The Regulation does include proportionality measures for SMEs: simplified technical documentation arrangements for high-risk systems, priority access to regulatory sandboxes, and penalty ceilings that take account of an SME's economic viability. There is no exemption based on headcount or turnover.

What are the first steps to comply with the EU AI Act?

Four steps, in order. First, inventory every AI system and AI feature in use, including functionality embedded in ordinary SaaS. Second, fix your role for each one — most SMEs are deployers rather than providers. Third, classify each system: check the prohibited practices in Art. 5, then check whether it is high-risk under Annex III or as a product safety component. Fourth, map the resulting obligations, document the reasoning behind each classification, and set a review trigger for when tools or uses change.

Which EU AI Act obligations apply to most SMEs?

For an SME deploying ordinary, non-high-risk tools the recurring duties are: ensuring adequate AI literacy among staff who use or oversee AI systems; confirming that no system falls under the Art. 5 prohibitions; meeting the Art. 50 transparency duties, including disclosing AI interaction and marking synthetic content; using each system in line with the provider's instructions and intended purpose; and keeping a current inventory with a named owner per system. High-risk deployment adds human oversight, log retention, worker notification, and incident reporting.

Is my SME a provider or a deployer under the EU AI Act?

A deployer uses an AI system under its own authority in a professional capacity. A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trade mark. Buying or subscribing to a tool makes you a deployer. You become a provider if you put your own name or trade mark on a high-risk system supplied by someone else, or if you make a substantial modification to such a system. That switch brings the full provider documentation and conformity burden.

Is using ChatGPT or a similar tool regulated for an SME?

Using a general-purpose AI model through a subscription or API generally makes you a deployer, not a provider of the model — the model provider carries the model-level obligations. Your practical duties are AI literacy for staff, transparency where customers interact with an AI system or receive AI-generated content, and not using the tool for a prohibited or unexamined high-risk purpose. Data protection law applies in parallel and independently, which matters when staff paste personal or confidential data into a public tool.

When do the main EU AI Act deadlines fall?

The Regulation entered into force on 1 August 2024. The prohibitions on unacceptable-risk practices and the AI literacy obligation began to apply on 2 February 2025. Obligations for providers of general-purpose AI models and the governance and penalties framework began to apply on 2 August 2025. The general date of application, covering Annex III high-risk obligations and the Art. 50 transparency rules, is 2 August 2026. High-risk systems that are safety components of products under the Annex I legislation follow on 2 August 2027.

EU AI Act updates, in your inbox

Deadlines, enforcement news and practical compliance guidance. One confirmation email first, then only the updates — one-click unsubscribe in every one.