The EU AI Act's deadline for high-risk AI systems is August 2, 2026. With 82 days to go, most SMEs have not started. This checklist tells you exactly what to do — and gives you a free scanner to see where you actually stand.
What Is the EU AI Act?
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on August 1, 2024, and applies to any company that develops, deploys, or uses AI systems in the EU — regardless of where the company is headquartered.
The Act takes a risk-based approach. The higher the risk of an AI system causing harm, the stricter the requirements. There are four tiers:
- Unacceptable risk — Prohibited outright. Examples: real-time biometric surveillance in public spaces, social scoring by governments, AI that exploits psychological vulnerabilities.
- High risk — Allowed, but subject to mandatory conformity assessments, human oversight, documentation, and transparency requirements. This is where most SMEs face their biggest obligations.
- Limited risk — Transparency obligations only (e.g., chatbots must disclose they are AI).
- Minimal risk — No specific obligations. AI spam filters, recommendation systems, and similar tools fall here.
Who Is Affected? (The SME Reality Check)
Many SMEs assume the EU AI Act is a big-enterprise problem. It is not. The regulation explicitly covers:
- EU-based companies that use AI systems (not just build them)
- Non-EU companies whose AI systems affect EU users
- Companies that deploy third-party AI tools in high-risk contexts
The key question is not "did we build an AI?" but "are we deploying AI in a high-risk use case?" If a French HR software company uses a third-party AI to screen CVs — that is a high-risk application under Annex III, and the deployer carries compliance obligations.
High-Risk Use Cases Under Annex III
These are the areas where SMEs most commonly find themselves unexpectedly in scope:
| Domain | Examples |
|---|---|
| Employment | CV screening, hiring tools, performance monitoring AI |
| Education | Automated grading, student behavior monitoring |
| Access to services | Credit scoring, insurance risk assessment |
| Critical infrastructure | AI in energy, water, or transport management |
| Law enforcement | Predictive policing, emotion recognition |
| Migration & asylum | Automated risk assessment tools |
| Administration of justice | Legal outcome prediction tools |
If your company operates in any of these sectors and uses AI, read on. Your August 2 deadline is real.
The 7-Step EU AI Act Compliance Checklist for SMEs
Step 1: Inventory All AI Tools You Use
Start with a complete map. You cannot comply with regulations you have not catalogued. For every AI system in your stack, document:
- What the system does
- Who the vendor is
- What data it processes
- What decisions it influences or automates
Include AI features embedded in SaaS products. A CRM with an AI lead-scoring module is still an AI system. An HRIS with an automated employee evaluation feature is still in scope. The tool being "just a feature" of a larger product does not exempt it.
Practical action: Create a spreadsheet. One row per AI tool. Four columns: tool name, vendor, use case, data processed. This becomes the foundation for every subsequent step.
Step 2: Classify Each Tool by Risk Level
Once you have your inventory, classify each tool. Use the Act's framework:
- Does the tool fall into an unacceptable risk category? If yes, you must stop using it immediately.
- Is it listed in Annex III (high-risk sectors)? If yes, full compliance obligations apply.
- Does it interact with users in ways requiring transparency disclosures? If yes, limited-risk rules apply.
- Does it fall into none of the above? Minimal risk — no specific obligations, but document your reasoning.
Classification is where most SMEs make their first mistake: they assume their risk is low because the AI is a "small feature." The Act classifies by use case, not by technical complexity. A simple rule-based algorithm making credit decisions is high-risk. A sophisticated LLM summarizing internal documents is likely minimal risk.
Not sure about your risk level? The Attestia scanner can classify your AI tools in under two minutes. Run a free scan →
Step 3: Assign a Compliance Owner
The EU AI Act creates specific roles: provider (you built the AI), deployer (you use it), and importer/distributor. Most SMEs are deployers. As a deployer of a high-risk AI system, you are responsible for:
- Ensuring the system is used as intended by the provider
- Implementing human oversight measures
- Monitoring the system for unexpected behavior
- Logging and record-keeping
- Informing workers when AI affects their employment decisions
Assign one person as your AI compliance owner. This does not need to be a dedicated role — in most SMEs it sits alongside other compliance responsibilities. But it must be someone, with documented authority and a schedule for review.
Step 4: Implement Human Oversight for High-Risk Systems
This is the non-negotiable core of high-risk compliance. For every high-risk AI system:
- A qualified human must be able to understand, monitor, and override the AI's output before it has consequential effect
- Automated decisions affecting individuals must be reviewable and contestable
- Staff using the AI must be trained on its limitations and how to interpret its outputs
Human oversight is not a checkbox. Regulators will look for evidence it is real: training records, documented escalation paths, logs of overrides. If you can show "the AI suggested X, a human reviewed it and decided Y" — that is what the regulation is looking for.
Step 5: Get Documentation From Your AI Vendors
As a deployer, you are not fully responsible for the technical performance of the AI itself — but you are responsible for using it within its intended scope and relying on conformant providers. This means:
- Ask vendors whether their high-risk AI systems are CE-marked or have completed conformity assessments
- Request a copy of their technical documentation (Article 11) and instructions for use (Article 13)
- Review their EU Declaration of Conformity (Article 47) if it is a high-risk system
- Check the EU AI database (Article 71) once operational — high-risk providers must register there
Vendors who cannot provide documentation for high-risk systems are not compliant providers. Using their tools exposes you to regulatory liability. Ask the question before August 2.
Step 6: Establish Record-Keeping and Incident Reporting
The Act requires deployers of high-risk systems to:
- Keep logs of the AI system's operation for at least six months (or longer per sector-specific rules) — and ensure those records meet the evidence standards auditors will actually look for
- Monitor performance after deployment and document any issues
- Report serious incidents to the relevant national authority (the Act defines serious incidents as those causing death, serious injury, or significant harm to fundamental rights)
- Cooperate with authorities during market surveillance
For most SMEs, this means ensuring your AI tools have audit logging enabled and that you retain those logs. If your vendor does not offer logging — that is a problem you need to solve before the deadline.
Step 7: Train Your Staff and Update Contracts
Two final steps that are easy to defer and expensive to skip:
Staff training: Workers who interact with high-risk AI systems must receive adequate training before use. This includes understanding what the AI does, what it does not do, how to interpret its outputs, and how to escalate or override. Training does not need to be elaborate — a documented one-hour briefing with a sign-off sheet is defensible. Zero training is not.
Contract updates: Review your SaaS agreements with AI vendors. You need contractual guarantees covering: (1) the vendor's compliance obligations as a provider, (2) your right to request documentation and technical information, (3) incident notification requirements, and (4) what happens if their system is found non-compliant. Many standard SaaS contracts are silent on these points. Negotiate addenda now — after a regulator arrives is not the time.
Common SME Mistakes (And How to Avoid Them)
Mistake 1: "We don't build AI, so we're not affected."
Wrong. The Act applies to deployers — companies that use AI in a professional context — not just to developers. If you use an AI-powered hiring tool, credit assessment system, or student grading platform, you have obligations. Building nothing does not exempt you from using something.
Mistake 2: "Our AI vendor handles compliance."
Partially true. Providers have their own obligations (technical documentation, conformity assessments, registration). But deployers have separate, independent obligations that vendors cannot discharge on your behalf: human oversight, logging, staff training, incident reporting. You share the burden — you do not offload it.
Mistake 3: "We'll wait for guidance from our industry association."
August 2, 2026 is a fixed date. Industry guidance and national AI authority frameworks are useful — but waiting for them before starting your inventory is how you arrive at the deadline with nothing done. The checklist above uses what is already in the final published regulation. Start now.
Mistake 4: "The fines won't apply to SMEs."
The Act explicitly provides for reduced fines for SMEs and startups (Article 99 cap at €7.5M or 1% of global turnover for operators, lower than the €35M/7% cap for providers). But reduced fines are not zero fines. More importantly: fines are not the only risk. Regulatory investigation, operational disruption, reputational damage, and customer churn from a public non-compliance finding are all real costs. SMEs are not immune.
Mistake 5: "We'll use AI Act as a differentiator later."
The SMEs that will use compliance as a differentiator are the ones who started early enough to have real documentation, real oversight processes, and real vendor relationships — not the ones who scrambled in July 2026. Start now and the differentiator is available. Start in August and the differentiator is a legal requirement you barely met.
What Happens After August 2, 2026?
The August 2 deadline covers high-risk AI systems under Annex III. The full enforcement timeline for context:
- February 2, 2025 — Prohibited AI practices banned (already in force)
- August 2, 2025 — GPAI model obligations and governance rules apply
- August 2, 2026 — High-risk AI systems (Annex III) must be compliant
- August 2, 2027 — High-risk AI systems in Annex I (sector-specific legislation) must comply
National market surveillance authorities are being established now. The European AI Office is operational. Enforcement will not wait for every SME to catch up.
How Attestia Helps
Attestia is a free EU AI Act compliance scanner designed for SMEs. You describe your AI tools, and the scanner:
- Classifies each tool by risk level using the Act's framework
- Identifies which compliance obligations apply to you
- Generates a plain-language compliance report you can share with stakeholders
- Flags the specific actions you need to take before August 2
The scan takes about 2 minutes. No account required to start.
Run your free compliance scan →
Summary: Your Compliance Checklist
- ✅ Inventory all AI tools in use across your business
- ✅ Classify each tool by risk level (unacceptable / high / limited / minimal)
- ✅ Assign a compliance owner with documented responsibility
- ✅ Implement human oversight processes for all high-risk systems
- ✅ Request documentation and conformity evidence from AI vendors
- ✅ Enable logging and establish incident reporting procedures
- ✅ Train staff and update vendor contracts
The deadline is 82 days away. Start with the inventory — everything else follows from knowing what you have.
This article provides general educational information about the EU AI Act and does not constitute legal advice. For advice specific to your situation, consult a qualified legal professional.