Operational guide / EU AI Act checklist

EU AI Act compliance checklist for SMEs

For European SMEs, agencies, consultancies, and SaaS operators using third-party or in-house AI.

Use a first-pass checklist to identify what is in use, who owns it, what data and vendors are involved, and where review should begin.

This is an operational starting point for organising a review—not a certificate of compliance and not a substitute for legal advice.

A reviewable starting point

Turn a broad AI question into owned next steps.
  • Start from how your organisation actually uses AI.
  • Name the owner, evidence, and open question for each record.
  • Keep the next review visible as tools and guidance change.
Practical governance support / not legal advice

What to capture

What to put on the first pass

A useful checklist turns a broad question about AI into a set of records someone can own, review, and update.

  • 01

    Inventory and ownership

    List AI tools, embedded features, and internal use cases. Assign an owner and record the team, purpose, and review contact for each one.

  • 02

    Data and vendors

    Capture the data categories involved, the vendor or account, relevant processing questions, and the evidence your team already has.

  • 03

    Policy and controls

    Note permitted and restricted uses, approval points, access controls, documentation, and the internal policy that should govern the work.

  • 04

    Human oversight and response

    Describe where people review outputs, what happens when an output is wrong, and who handles incidents, complaints, or escalation.

  • 05

    Literacy and review cadence

    Record how relevant people are made aware of the systems they use and set a practical date to revisit the record as tools and guidance change.

Practical workflow

From checklist to operating record

The checklist is useful when it creates a next action and a clear place to keep the evidence.

  1. 01

    Discover

    Ask teams, procurement, IT, and client-facing leads what AI they use or provide. Start with facts rather than trying to classify everything immediately.

  2. 02

    Organise

    Group the answers into systems, use cases, owners, vendors, data, controls, and open questions. Mark what is known, missing, and due for review.

  3. 03

    Review

    Prioritise the records that need qualified review, agree the next control or policy action, and set a cadence that keeps the record current.

Scope and sources

Read the sources, keep the boundary

ProofCairn provides operational governance support, not legal advice or a definitive legal classification. Applicability depends on your role, system, use case, jurisdiction, and current guidance; professional review may be needed. The checklist helps you prepare the facts a reviewer will need; it does not decide which duties apply to your organisation.

Questions worth asking

Keep uncertainty visible.

Does this checklist prove that an SME is compliant?

No. It helps an organisation organise a first review and identify gaps. The duties that apply vary with the role, system, use case, jurisdiction, and current guidance, so a completed checklist is not a legal conclusion.

Where should a small team start?

Start with the AI tools and use cases people actually use, then assign owners and record data, vendor, oversight, and evidence questions. The free scan can help identify which dimension to examine first.

Are the same deadlines and duties right for every organisation?

The European Commission explains that the AI Act applies progressively and that responsibilities depend on the role and context. Check current Commission guidance and the legal text before deciding what your organisation needs to do.

Five minutes to a clearer next step

Start with the free AI Governance Readiness Check.

Answer ten practical questions about how your organisation uses generative AI and get a prioritised operational signal.

Not legal advice, not a compliance test, and not a definitive legal classification.