EU AI Act compliance checklist for SMEs
For European SMEs, agencies, consultancies, and SaaS operators using third-party or in-house AI.
Use a first-pass checklist to identify what is in use, who owns it, what data and vendors are involved, and where review should begin.
This is an operational starting point for organising a review—not a certificate of compliance and not a substitute for legal advice.
A reviewable starting point
- Start from how your organisation actually uses AI.
- Name the owner, evidence, and open question for each record.
- Keep the next review visible as tools and guidance change.
What to capture
What to put on the first pass
A useful checklist turns a broad question about AI into a set of records someone can own, review, and update.
- 01
Inventory and ownership
List AI tools, embedded features, and internal use cases. Assign an owner and record the team, purpose, and review contact for each one.
- 02
Data and vendors
Capture the data categories involved, the vendor or account, relevant processing questions, and the evidence your team already has.
- 03
Policy and controls
Note permitted and restricted uses, approval points, access controls, documentation, and the internal policy that should govern the work.
- 04
Human oversight and response
Describe where people review outputs, what happens when an output is wrong, and who handles incidents, complaints, or escalation.
- 05
Literacy and review cadence
Record how relevant people are made aware of the systems they use and set a practical date to revisit the record as tools and guidance change.
Practical workflow
From checklist to operating record
The checklist is useful when it creates a next action and a clear place to keep the evidence.
- 01
Discover
Ask teams, procurement, IT, and client-facing leads what AI they use or provide. Start with facts rather than trying to classify everything immediately.
- 02
Organise
Group the answers into systems, use cases, owners, vendors, data, controls, and open questions. Mark what is known, missing, and due for review.
- 03
Review
Prioritise the records that need qualified review, agree the next control or policy action, and set a cadence that keeps the record current.
Scope and sources
Read the sources, keep the boundary
ProofCairn provides operational governance support, not legal advice or a definitive legal classification. Applicability depends on your role, system, use case, jurisdiction, and current guidance; professional review may be needed. The checklist helps you prepare the facts a reviewer will need; it does not decide which duties apply to your organisation.
Questions worth asking
Keep uncertainty visible.
Does this checklist prove that an SME is compliant?
No. It helps an organisation organise a first review and identify gaps. The duties that apply vary with the role, system, use case, jurisdiction, and current guidance, so a completed checklist is not a legal conclusion.
Where should a small team start?
Start with the AI tools and use cases people actually use, then assign owners and record data, vendor, oversight, and evidence questions. The free scan can help identify which dimension to examine first.
Are the same deadlines and duties right for every organisation?
The European Commission explains that the AI Act applies progressively and that responsibilities depend on the role and context. Check current Commission guidance and the legal text before deciding what your organisation needs to do.
Five minutes to a clearer next step
Start with the free AI Governance Readiness Check.
Answer ten practical questions about how your organisation uses generative AI and get a prioritised operational signal.
Not legal advice, not a compliance test, and not a definitive legal classification.