EU AI Act Compliance Checklist for Small Businesses
Small businesses need an AI inventory, role classification, staff literacy, and risk-based controls before they need a giant compliance program.

Bottom line
A practical EU AI Act checklist for small businesses using chatbots, hiring tools, content generators, customer automation, and other AI systems.
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 4 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 4
- Products covered
- 0
- Last checked
- 2026-09-10
Important limits
- • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
*This operational overview is not legal advice. It was reviewed against the EU AI Act, the European Commission's AI Act guidance, and the 2026 AI Omnibus timeline on September 10, 2026.*
The short answer
A small business should begin EU AI Act compliance by inventorying every AI system, identifying whether it is a provider or deployer, screening prohibited and high-risk uses, training staff, and documenting the controls and vendor evidence for each use. Company size does not create a blanket exemption.
The checklist
- List every AI use. Include embedded CRM features, hiring filters, chatbots, fraud tools, content generators, meeting assistants, and employee experiments.
- Record purpose and affected people. A general model used to rewrite copy is different from the same model ranking job applicants.
- Assign your role. Determine whether the company provides, deploys, imports, or distributes the system; obligations differ.
- Stop prohibited practices. Screen manipulative uses, certain social scoring and biometric practices, and other Article 5 prohibitions.
- Classify high-risk uses. Check regulated-product safety components and Annex III areas such as employment, education, credit and essential services.
- Document any exemption. A narrow procedural or preparatory Annex III use may not be high-risk, but providers must document the reasoning; profiling remains high-risk.
- Provide AI literacy. Article 4 measures already apply. Training should match staff knowledge, the system, and the context.
- Check transparency duties. Tell people when required that they are interacting with AI and handle synthetic-content marking where applicable.
- Collect vendor evidence. Keep instructions, intended purpose, limits, conformity material, retention terms, subprocessors, incident contacts, and change notices.
- Operate controls. Assign human oversight, log use, verify relevant input data, monitor incidents, and pause systems that create unexpected risk.
- Review adjacent law. GDPR, employment, consumer, copyright, equality, and sector rules still apply.
- Set a review date. Reassess after material model, purpose, data, vendor, or legal changes.
Timing
Use the companion [EU AI Act high-risk classification guide](/articles/which-ai-tools-eu-ai-act-high-risk-rules) before completing the risk column in the inventory.
The Commission states that prohibited-practice and AI-literacy provisions have applied since February 2, 2025, with enforcement provisions active in 2026. Following the AI Omnibus, Annex III high-risk rules are scheduled for December 2, 2027 and regulated-product high-risk rules for August 2, 2028. Transparency and other obligations have their own timelines; verify the current rule for the specific use.
Bottom line
The defensible small-business program is a short, maintained register with named owners and evidence—not a generic policy nobody uses. Escalate high-risk, biometric, employment, credit, health, education, and public-service uses to qualified counsel.
Sources and verification
Product details and claims were checked against the following primary sources.
Frequently asked questions
Does the EU AI Act apply to small businesses?
Yes when their activity falls within the Act's scope. Some support and proportionality provisions help SMEs, but there is no blanket small-business exemption.
What should a small business do first?
Create an inventory recording each AI system, purpose, users, affected people, data, vendor, organizational role, risk classification, and owner.
Is AI literacy already required?
Article 4 measures have applied since February 2, 2025. Training should reflect staff knowledge, the system, and the context of use.
When do high-risk rules apply?
The Commission's 2026 Omnibus timeline places Annex III rules at December 2, 2027 and regulated-product rules at August 2, 2028. Check current official guidance for your use.
Found this useful?
Get the next one in your inbox.
One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.
Free · one email a week · unsubscribe any time
Read next
Recommended for you

Arcade Review 2026: Agent Authorization, Tools, and Pricing
A research-based Arcade review covering features, pricing, privacy, limitations, alternatives, and a practical buyer test.
Arcade is an actions runtime for AI agents that manages OAuth, user tokens, tool execution, and policy enforcement across thousands of agent-oriented tools.
Read guide
Daytona Review 2026: AI Code Sandboxes, Security, and Pricing
Gentrace Review 2026: AI Agent Evaluation, Tracing, and Fit
GPT-6 Astra vs Claude for Business: Which Should Your Team Choose?