The EU AI Act's deadline for high-risk AI systems is August 2, 2026. With 82 days to go, most SMEs have not started. This checklist tells you exactly what to do — and gives you a free scanner to see where you actually stand.

What Is the EU AI Act?

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on August 1, 2024, and applies to any company that develops, deploys, or uses AI systems in the EU — regardless of where the company is headquartered.

The Act takes a risk-based approach. The higher the risk of an AI system causing harm, the stricter the requirements. There are four tiers:

Who Is Affected? (The SME Reality Check)

Many SMEs assume the EU AI Act is a big-enterprise problem. It is not. The regulation explicitly covers:

The key question is not "did we build an AI?" but "are we deploying AI in a high-risk use case?" If a French HR software company uses a third-party AI to screen CVs — that is a high-risk application under Annex III, and the deployer carries compliance obligations.

High-Risk Use Cases Under Annex III

These are the areas where SMEs most commonly find themselves unexpectedly in scope:

DomainExamples
EmploymentCV screening, hiring tools, performance monitoring AI
EducationAutomated grading, student behavior monitoring
Access to servicesCredit scoring, insurance risk assessment
Critical infrastructureAI in energy, water, or transport management
Law enforcementPredictive policing, emotion recognition
Migration & asylumAutomated risk assessment tools
Administration of justiceLegal outcome prediction tools

If your company operates in any of these sectors and uses AI, read on. Your August 2 deadline is real.

The 7-Step EU AI Act Compliance Checklist for SMEs

Step 1: Inventory All AI Tools You Use

Start with a complete map. You cannot comply with regulations you have not catalogued. For every AI system in your stack, document:

Include AI features embedded in SaaS products. A CRM with an AI lead-scoring module is still an AI system. An HRIS with an automated employee evaluation feature is still in scope. The tool being "just a feature" of a larger product does not exempt it.

Practical action: Create a spreadsheet. One row per AI tool. Four columns: tool name, vendor, use case, data processed. This becomes the foundation for every subsequent step.

Step 2: Classify Each Tool by Risk Level

Once you have your inventory, classify each tool. Use the Act's framework:

Classification is where most SMEs make their first mistake: they assume their risk is low because the AI is a "small feature." The Act classifies by use case, not by technical complexity. A simple rule-based algorithm making credit decisions is high-risk. A sophisticated LLM summarizing internal documents is likely minimal risk.

Not sure about your risk level? The Attestia scanner can classify your AI tools in under two minutes. Run a free scan →

Step 3: Assign a Compliance Owner

The EU AI Act creates specific roles: provider (you built the AI), deployer (you use it), and importer/distributor. Most SMEs are deployers. As a deployer of a high-risk AI system, you are responsible for:

Assign one person as your AI compliance owner. This does not need to be a dedicated role — in most SMEs it sits alongside other compliance responsibilities. But it must be someone, with documented authority and a schedule for review.

Step 4: Implement Human Oversight for High-Risk Systems

This is the non-negotiable core of high-risk compliance. For every high-risk AI system:

Human oversight is not a checkbox. Regulators will look for evidence it is real: training records, documented escalation paths, logs of overrides. If you can show "the AI suggested X, a human reviewed it and decided Y" — that is what the regulation is looking for.

Step 5: Get Documentation From Your AI Vendors

As a deployer, you are not fully responsible for the technical performance of the AI itself — but you are responsible for using it within its intended scope and relying on conformant providers. This means:

Vendors who cannot provide documentation for high-risk systems are not compliant providers. Using their tools exposes you to regulatory liability. Ask the question before August 2.

Step 6: Establish Record-Keeping and Incident Reporting

The Act requires deployers of high-risk systems to:

For most SMEs, this means ensuring your AI tools have audit logging enabled and that you retain those logs. If your vendor does not offer logging — that is a problem you need to solve before the deadline.

Step 7: Train Your Staff and Update Contracts

Two final steps that are easy to defer and expensive to skip:

Staff training: Workers who interact with high-risk AI systems must receive adequate training before use. This includes understanding what the AI does, what it does not do, how to interpret its outputs, and how to escalate or override. Training does not need to be elaborate — a documented one-hour briefing with a sign-off sheet is defensible. Zero training is not.

Contract updates: Review your SaaS agreements with AI vendors. You need contractual guarantees covering: (1) the vendor's compliance obligations as a provider, (2) your right to request documentation and technical information, (3) incident notification requirements, and (4) what happens if their system is found non-compliant. Many standard SaaS contracts are silent on these points. Negotiate addenda now — after a regulator arrives is not the time.

Common SME Mistakes (And How to Avoid Them)

Mistake 1: "We don't build AI, so we're not affected."

Wrong. The Act applies to deployers — companies that use AI in a professional context — not just to developers. If you use an AI-powered hiring tool, credit assessment system, or student grading platform, you have obligations. Building nothing does not exempt you from using something.

Mistake 2: "Our AI vendor handles compliance."

Partially true. Providers have their own obligations (technical documentation, conformity assessments, registration). But deployers have separate, independent obligations that vendors cannot discharge on your behalf: human oversight, logging, staff training, incident reporting. You share the burden — you do not offload it.

Mistake 3: "We'll wait for guidance from our industry association."

August 2, 2026 is a fixed date. Industry guidance and national AI authority frameworks are useful — but waiting for them before starting your inventory is how you arrive at the deadline with nothing done. The checklist above uses what is already in the final published regulation. Start now.

Mistake 4: "The fines won't apply to SMEs."

The Act explicitly provides for reduced fines for SMEs and startups (Article 99 cap at €7.5M or 1% of global turnover for operators, lower than the €35M/7% cap for providers). But reduced fines are not zero fines. More importantly: fines are not the only risk. Regulatory investigation, operational disruption, reputational damage, and customer churn from a public non-compliance finding are all real costs. SMEs are not immune.

Mistake 5: "We'll use AI Act as a differentiator later."

The SMEs that will use compliance as a differentiator are the ones who started early enough to have real documentation, real oversight processes, and real vendor relationships — not the ones who scrambled in July 2026. Start now and the differentiator is available. Start in August and the differentiator is a legal requirement you barely met.

What Happens After August 2, 2026?

The August 2 deadline covers high-risk AI systems under Annex III. The full enforcement timeline for context:

National market surveillance authorities are being established now. The European AI Office is operational. Enforcement will not wait for every SME to catch up.

How Attestia Helps

Attestia is a free EU AI Act compliance scanner designed for SMEs. You describe your AI tools, and the scanner:

The scan takes about 2 minutes. No account required to start.

Run your free compliance scan →

Summary: Your Compliance Checklist

  1. ✅ Inventory all AI tools in use across your business
  2. ✅ Classify each tool by risk level (unacceptable / high / limited / minimal)
  3. ✅ Assign a compliance owner with documented responsibility
  4. ✅ Implement human oversight processes for all high-risk systems
  5. ✅ Request documentation and conformity evidence from AI vendors
  6. ✅ Enable logging and establish incident reporting procedures
  7. ✅ Train staff and update vendor contracts

The deadline is 82 days away. Start with the inventory — everything else follows from knowing what you have.


This article provides general educational information about the EU AI Act and does not constitute legal advice. For advice specific to your situation, consult a qualified legal professional.