Free Checklist

EU AI Act Compliance Checklist for SMEs

7 practical steps to get your small business compliant before the August 2026 enforcement deadline — no legal degree required.

Enforcement begins August 2, 2026 — fines up to €15M. Start now.
01
Conduct a full AI system inventory
List every AI-powered tool your company uses — internal and external. Include SaaS products (CRM, hiring platforms, analytics, chatbots, customer support tools, marketing automation, AI writing assistants). For each tool, note: what it does, what data it processes, who accesses it, and who made the purchase decision.
Action Required Foundation
02
Classify each AI system by risk level
Apply the EU AI Act's risk tiers to your inventory. Systems that manipulate human behavior, exploit vulnerabilities, or score social behavior are unacceptable risk and must be removed. Systems in healthcare, education, employment, law enforcement, or border control are high-risk and face strict obligations. General-purpose AI and chatbots are limited risk — transparency obligations only.
Annex III Risk Tiers Classification Required
03
Fulfill high-risk obligations for affected systems
If you have high-risk AI systems, you must: establish a risk management system, use high-quality training data, maintain technical documentation (see Step 4), implement human oversight measures, ensure accuracy and robustness, log system activity. High-risk systems also require a conformity assessment before deployment — get this from an accredited body or use the self-assessment route if your sector allows it.
Art. 9–14 Obligation
04
Create technical documentation for each high-risk system (Annex IV)
Article 11 requires a technical file for every high-risk system covering: description and intended purpose, system architecture, training data methodology, testing procedures and results, risk mitigations in place, human oversight protocols. Annex IV provides the exact structure — use it as your template. Documentation must be kept up to date as your systems evolve.
Annex IV Art. 11 Documentation Required
05
Assign EU AI Act roles and responsibilities
Identify your providers (build/sell AI systems), deployers (use AI in business operations), and importers/distributors as applicable. Providers have the most obligations. Deployers must: use high-risk systems according to provider instructions, monitor outputs, maintain records of use, designate a person responsible for oversight. Assign named owners for each role — these are your accountability points.
Art. 3, 26 Role Assignment
06
Train employees on AI literacy and compliance (Article 4)
Article 4 requires that personnel using high-risk AI systems have sufficient training in: how the system works, what it can and cannot do, the risks it presents, how to interpret outputs correctly, when to escalate or override automated decisions. Document who has been trained and when. This isn't optional — regulators will ask for training records during an audit.
Art. 4 Training Required
07
Set up post-market monitoring and incident reporting
Deployers of high-risk systems must: log system usage to the extent relevant to risk, monitor for failures and biases post-deployment, report serious incidents to the system provider and national authority within 72 hours (within 24 hours for incidents posing immediate harm). Keep a log of what you monitored, what you found, and what you did about it. Post-market data feeds back into Step 1 — update your inventory when your stack changes.
Art. 29 Ongoing Obligation Monitoring Required

Turn this checklist into automated compliance.

Attestia scans your AI stack, classifies each system, generates your Annex IV documentation, and monitors compliance continuously — all from €149/month.

Try the free EU AI Act scanner →