Skip to main content
AI Regulation

AI Act Compliance Checklist for SMEs

A practical step-by-step checklist for small and medium enterprises preparing for EU AI Act compliance, including SME-specific provisions and cost-saving strategies.

AROG AI Team
March 25, 2026
8 min read
Key Takeaways
  • 1SMEs get reduced conformity assessment fees and simplified documentation requirements
  • 2Start with AI inventory and risk classification — most SME systems are limited or minimal risk
  • 3High-risk compliance requires 9 specific measures — prioritize risk management and documentation first
  • 4The EU provides regulatory sandboxes where SMEs can test compliance approaches for free

If you are running a small or medium-sized enterprise in the EU, you might think the AI Act is only for Big Tech. It is not. Any company that deploys or develops AI systems operating within the EU falls under the regulation — and that includes the SaaS tools, chatbots, and predictive models that most modern SMEs rely on daily.

The good news: the EU AI Act includes specific provisions designed to make compliance more accessible for SMEs, including reduced fees, simplified processes, and access to regulatory sandboxes. This checklist gives you a structured, priority-ordered path to compliance — so you know exactly what to do and when.

Who Needs This Checklist?

The EU AI Act applies to you if your company:

  • Develops AI systems that are placed on the EU market or used in the EU
  • Deploys AI systems within the EU (even if the AI was built by a third party)
  • Imports AI systems into the EU market
  • Distributes AI systems to EU users

This means if you use AI-powered tools from providers like HubSpot, Salesforce, or any platform with predictive analytics, automated scoring, or chatbot features — you are a deployer under the Act and have specific obligations. If you are unsure, start with our free risk classifier to assess each of your AI systems.

Phase 1: Pre-Compliance Foundation (Start Now)

These are the steps every SME should complete immediately, regardless of risk level:

1

Complete AI Systems Inventory

List every AI tool and service across your organization. Include third-party SaaS tools with embedded AI features (CRM scoring, chatbots, automated email tools, HR screening, fraud detection). Most SMEs are surprised to find they use 5-15 AI systems they were not aware of.

2

Classify Each System by Risk Level

Map each AI system to the four-tier risk framework: Unacceptable, High, Limited, or Minimal. Remember: classification is based on use case, not technology. Use our free risk classifier to automate this step.

3

Conduct Gap Analysis

For each AI system, identify the gap between your current practices and the AI Act requirements for that risk tier. This reveals your compliance workload and helps you prioritize.

4

Designate an AI Compliance Lead

Appoint someone in your organization to own AI Act compliance. This does not need to be a full-time role — in many SMEs it can be an addition to an existing compliance, legal, or IT leadership role.

Phase 2: High-Risk System Compliance

If any of your AI systems are classified as high risk (per Annex III of the AI Act), you must implement all of the following measures before August 2026:

1

Risk Management System (Article 9)

Establish an ongoing, iterative process to identify and mitigate risks throughout the AI system's lifecycle. This must be documented and regularly updated.

2

Data Governance (Article 10)

Ensure training, validation, and testing data is relevant, representative, free of errors, and complete. Implement data quality criteria and bias detection procedures.

3

Technical Documentation (Article 11)

Produce comprehensive technical documentation covering system design, development process, capabilities, limitations, and intended purpose. Maintain this documentation before the system is placed on the market.

4

Record-Keeping / Logging (Article 12)

Implement automatic logging of events during operation. Logs must be retained for a period appropriate to the intended purpose and at least 6 months.

5

Transparency and User Information (Article 13)

Provide clear instructions for use, including system capabilities, limitations, intended purpose, and information about accuracy, robustness, and cybersecurity measures.

6

Human Oversight (Article 14)

Design systems so humans can effectively oversee operation. Implement mechanisms for human intervention, including the ability to override or stop the system.

7

Accuracy, Robustness, and Cybersecurity (Article 15)

Ensure consistent performance, resilience against errors and adversarial attacks, and appropriate cybersecurity measures throughout the system's lifecycle.

8

Conformity Assessment (Article 43)

Before placing the system on the market, complete a conformity assessment. For most high-risk systems, this can be done through internal assessment; certain biometric systems require third-party assessment.

9

EU Database Registration (Article 49)

Register the high-risk AI system in the EU public database before it is placed on the market or put into service.

Phase 3: Limited-Risk Compliance

If your AI systems are classified as limited risk, your obligations are lighter but still mandatory:

1

AI Disclosure for Chatbots and Virtual Assistants

Under Article 50(1), users must be informed that they are interacting with an AI system. Add a clear notice at the start of any chatbot or virtual assistant interaction: "You are chatting with an AI assistant."

2

AI-Generated Content Labeling

Under Article 50(2), AI-generated or manipulated content (text, audio, image, video) must be labeled as such. If your marketing team uses AI to generate content, it must be disclosed.

3

Deepfake Disclosure

Under Article 50(4), synthetic media that depicts real people or events must be clearly labeled. This includes AI-generated images, voice cloning, and video manipulations.

4

Document Your Transparency Measures

Keep records of how and where you disclose AI usage. This serves as your compliance evidence if audited.

Timeline: What to Do When

Here is your prioritization roadmap based on the enforcement timeline:

  • Already in effect: All prohibited AI practices are banned since February 2025. If you operate any banned systems, discontinue them immediately.
  • Now - Q2 2026: Complete your AI inventory, risk classification, and gap analysis. Begin high-risk compliance work. This is your preparation window.
  • August 2026: Full enforcement for high-risk AI systems. All compliance measures must be in place. Fines can be imposed from this date.
  • August 2027: Remaining provisions take effect, including rules for AI systems embedded in regulated products (medical devices, vehicles, etc.).

Important for SMEs: Do not wait until August 2026. Compliance takes 6-12 months for high-risk systems. If you start now, you have adequate time. If you wait until mid-2026, you will likely miss the deadline.

SME-Specific Advantages Under the AI Act

The EU AI Act includes several provisions specifically designed to support SMEs. Take advantage of these:

Reduced Conformity Assessment Fees

Article 43 mandates that notified bodies must apply reduced fees for SMEs, including startups and micro-enterprises, proportionate to their size and specific interests.

Simplified Documentation

The European Commission will provide simplified technical documentation templates tailored to SME needs. These are expected before the August 2026 deadline.

Regulatory Sandboxes

Under Articles 57-58, EU member states must establish AI regulatory sandboxes. SMEs get priority access to these sandboxes, where you can test your AI systems in a controlled regulatory environment — for free.

Proportionate Penalties

While maximum fines can reach 35 million EUR, penalties for SMEs are calculated as a percentage of turnover, and caps are adjusted proportionally for smaller enterprises.

For a comprehensive walkthrough of all compliance requirements, read our full AI Act compliance guide.

Start Your Compliance Journey Today

Begin with a free risk assessment to understand which of your AI systems need attention. Our diagnostic consultation starts from EUR 200 — a fraction of the cost of non-compliance penalties.

Keep Reading

Related Articles