GuideUpdated 2026-09-10

EU AI Act Compliance Checklist for Small Businesses

Small businesses need an AI inventory, role classification, staff literacy, and risk-based controls before they need a giant compliance program.

By DiscoverAI Editorial TeamReviewed by DiscoverAI Editorial Review2 min readWork & OperationsHow we evaluate
Paper-cut illustration of a small business desk with an AI inventory, risk checklist, staff training, vendor evidence, and review calendar
Original DiscoverAI editorial illustration. Editorial illustration: compliance starts with a precise inventory, roles, risk classification, and owners.

Bottom line

A practical EU AI Act checklist for small businesses using chatbots, hiring tools, content generators, customer automation, and other AI systems.

Editorial accountability

Who checked this guide

Meet the editorial team →
Evaluation type
Research-based verification
Last materially checked
Evidence
4 listed sources

Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.

Editorial basis

What this guidance is based on

Editorial basis
Source-led analysis
Primary references
4
Products covered
0
Last checked
2026-09-10

Important limits

  • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
  1. The short answer
  2. The checklist
  3. Timing
  4. Bottom line

*This operational overview is not legal advice. It was reviewed against the EU AI Act, the European Commission's AI Act guidance, and the 2026 AI Omnibus timeline on September 10, 2026.*

The short answer

A small business should begin EU AI Act compliance by inventorying every AI system, identifying whether it is a provider or deployer, screening prohibited and high-risk uses, training staff, and documenting the controls and vendor evidence for each use. Company size does not create a blanket exemption.

The checklist

  1. List every AI use. Include embedded CRM features, hiring filters, chatbots, fraud tools, content generators, meeting assistants, and employee experiments.
  2. Record purpose and affected people. A general model used to rewrite copy is different from the same model ranking job applicants.
  3. Assign your role. Determine whether the company provides, deploys, imports, or distributes the system; obligations differ.
  4. Stop prohibited practices. Screen manipulative uses, certain social scoring and biometric practices, and other Article 5 prohibitions.
  5. Classify high-risk uses. Check regulated-product safety components and Annex III areas such as employment, education, credit and essential services.
  6. Document any exemption. A narrow procedural or preparatory Annex III use may not be high-risk, but providers must document the reasoning; profiling remains high-risk.
  7. Provide AI literacy. Article 4 measures already apply. Training should match staff knowledge, the system, and the context.
  8. Check transparency duties. Tell people when required that they are interacting with AI and handle synthetic-content marking where applicable.
  9. Collect vendor evidence. Keep instructions, intended purpose, limits, conformity material, retention terms, subprocessors, incident contacts, and change notices.
  10. Operate controls. Assign human oversight, log use, verify relevant input data, monitor incidents, and pause systems that create unexpected risk.
  11. Review adjacent law. GDPR, employment, consumer, copyright, equality, and sector rules still apply.
  12. Set a review date. Reassess after material model, purpose, data, vendor, or legal changes.

Timing

Use the companion [EU AI Act high-risk classification guide](/articles/which-ai-tools-eu-ai-act-high-risk-rules) before completing the risk column in the inventory.

The Commission states that prohibited-practice and AI-literacy provisions have applied since February 2, 2025, with enforcement provisions active in 2026. Following the AI Omnibus, Annex III high-risk rules are scheduled for December 2, 2027 and regulated-product high-risk rules for August 2, 2028. Transparency and other obligations have their own timelines; verify the current rule for the specific use.

Bottom line

The defensible small-business program is a short, maintained register with named owners and evidence—not a generic policy nobody uses. Escalate high-risk, biometric, employment, credit, health, education, and public-service uses to qualified counsel.

Sources and verification

Product details and claims were checked against the following primary sources.

Frequently asked questions

Does the EU AI Act apply to small businesses?

Yes when their activity falls within the Act's scope. Some support and proportionality provisions help SMEs, but there is no blanket small-business exemption.

What should a small business do first?

Create an inventory recording each AI system, purpose, users, affected people, data, vendor, organizational role, risk classification, and owner.

Is AI literacy already required?

Article 4 measures have applied since February 2, 2025. Training should reflect staff knowledge, the system, and the context of use.

When do high-risk rules apply?

The Commission's 2026 Omnibus timeline places Annex III rules at December 2, 2027 and regulated-product rules at August 2, 2028. Check current official guidance for your use.

Found this useful?

Get the next one in your inbox.

One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.

Free · one email a week · unsubscribe any time

Read next

More on Work & Operations