Skip to content

Applied AI

The EU AI Act: a practical guide for SMEs

The EU AI Act is in force and you don't need a legal megaproject to respond: inventory your AI uses, place them by risk level and keep minimum evidence.

9 MIN READ

The EU's regulation on artificial intelligence — the AI Act — is already in force, and its obligations arrive in phases. For a small or mid-sized company, the real decision isn't "comply or don't": it's working out which parts actually apply to you and what is worth doing now, without turning the answer into a legal project your business neither needs nor can afford. This guide is for making that decision in the right order: how to inventory the AI uses you already have, how to place them by risk level with recognisable examples, what role you play in each one, what evidence is worth keeping, and how to prepare for the phases without living glued to a calendar.

Before you read the regulation, build the inventory

You can't know what applies to you if you don't know what you use. It sounds obvious, and it's the step almost everyone skips: discussions start with risk categories in the abstract while nobody in the room knows how many AI systems are actually running in the company.

The inventory tends to surprise people, because an SME's AI is rarely "the AI project". It's mostly three things:

  • AI embedded in software you already pay for. The CRM that scores customers, the marketing tool that writes and segments, the HR module that pre-ranks applicants, the ERP that suggests forecasts. Nobody installed it as an "AI system"; it arrived inside something else.
  • Individual use of generative AI. People on the team drafting, translating or summarising with a chat tool, with or without a company account. It exists whether or not anyone decided it should.
  • Anything custom-built, if there is any: an internal assistant, automated classification, an integration with a model.

For each use, record little but useful: what it does, which task or decision it serves, who uses it, what data goes in, whether it's a vendor's system or your own, and — the question that brings the most order — whether its output affects people: a job applicant, an employee, a customer being granted or refused something. A spreadsheet is enough. Don't chase perfect completeness: chase an honest picture you can keep alive. Without that inventory, any conversation about the AI Act is theology; with it, almost everything else becomes concrete.

The risk categories, through an SME's eyes

The AI Act classifies uses, not technologies. That one idea clears up half the confusion: the same model can be a minimal-risk use in one task and a high-risk use in another. The question is never "is this tool legal?" but "what are we using it for?".

Prohibited practices

The regulation bans certain uses outright: manipulation that exploits people's vulnerabilities, social scoring, certain uses of biometric identification. A normal SME is nowhere near any of this — and that's exactly why it's worth knowing: it lets you rule the category out with judgement rather than instinct, and spot the rare exception if someone ever proposes something that edges towards it.

High risk

This is where an SME can walk in without noticing. High-risk uses include areas that sound like big-company territory but creep into small ones: using AI to screen CVs or rank candidates in a hiring process, evaluating employees in ways that affect promotion or continued employment, deciding on individuals' creditworthiness before granting them something. If the HR module in your software "pre-ranks" applications, you're closer to this category than you think.

A high-risk use isn't a banned use: it means serious obligations — risk management, data quality, documentation, human oversight, record-keeping. Most of those obligations sit with whoever builds the system, but whoever uses it has duties too, which is what the next section covers.

Transparency

Some uses aren't high risk but do require that people know what they're dealing with: a customer-facing chatbot has to identify itself as AI to the person talking to it; certain generated or manipulated content has to be labelled as such. For an SME with a customer-facing assistant this is the most common category after minimal risk, and the obligation is so reasonable it deserves honouring even if the regulation didn't exist.

What about general-purpose models?

A frequent doubt: what happens with the big generative models everyone uses. The regulation gives them obligations of their own, but most of those sit with whoever develops them, not with the SME using them. Your part is the usual one: knowing what your team uses them for, with what data, and under which internal policy. If that's in place, this corner of the regulation isn't your problem.

Minimal risk

The vast majority of productivity uses live here: drafting, summarising, sorting email, translating, forecasting internal demand, searching your own documentation. No new specific obligations. That doesn't make these uses a lawless zone — good data and oversight practice still applies, and GDPR hasn't gone anywhere — but it does mean something important: for most SMEs, most of their AI sits here, and the compliance workload is far smaller than the noise suggests.

Your role matters as much as the category

The regulation doesn't hand everyone the same obligations: above all, it distinguishes between whoever provides an AI system and whoever uses it in their operation (what the text calls a deployer). Most SMEs are in the second group: they use third-party systems. That role carries lighter obligations, but real ones:

  • use the system according to the provider's instructions — which implies having read them, something less universal than it sounds;
  • assign meaningful human oversight for uses that affect people: a specific person with the real ability to correct or stop the system, not a ticked box;
  • monitor how it behaves and react if it starts doing strange things;
  • inform people when it's due: your staff if high-risk AI that affects them is in use, your customers when they're talking to a machine.

Two warnings that prevent nasty surprises. First: roles can shift. If you substantially modify a third party's system, or put it on the market under your own brand, you can end up carrying provider obligations without ever intending to. Before heavily customising a tool or reselling it inside your product, that question deserves five minutes. Second: the regulation also expects the people operating AI to have enough training to use it with judgement. AI literacy isn't decorative — it's a cross-cutting obligation and, as it happens, the best effort-to-result ratio on this entire list.

The evidence worth keeping

"How much is enough?" is the standard anxiety of anyone who hears the words documentation and traceability. The principle that defuses it: evidence proportional to the risk of the use. A minimal-risk use needs little more than a line in the inventory; a use that affects people needs you to be able to tell the whole story.

A reasonable baseline for an SME:

  • The living inventory, dated and owned. It's the first piece of evidence and the most profitable one: it shows you know what you use.
  • For each relevant use: its purpose written in one sentence, what data goes in, who oversees it and how.
  • An internal policy for generative AI: short, concrete, actually communicated. What's allowed, what data never leaves the company, who to ask when in doubt.
  • The provider's documentation: what they say about their system, what category they claim, what terms they sign. Keeping it costs little and is worth a great deal in any serious conversation.
  • A log of incidents and decisions: when a system did something unexpected, what was done, when something was switched off and why. Half a page per episode.

None of this calls for solemn formats or a new document management system: short documents, dated, owned, kept somewhere everyone knows. And it's worth noticing something: almost everything on this list is something you'd want even if the AI Act didn't exist. Knowing which systems you use, for what, on which data and under whose oversight isn't regulatory bureaucracy — it's the minimum documentation of a well-run operation. Seen that way, the regulation mandates something that already paid for itself.

Phases without a calendar: how not to be late without living by dates

The AI Act's obligations didn't all land on the same day and won't arrive in one go: some phases are already in force and others keep coming. That's where the two symmetrical mistakes come from: waiting to "see what happens" until something bites, or planning against specific dates that get misremembered and turn compliance into a last-minute sprint.

The practical way out is that the order of work doesn't depend on the calendar. Inventorying, classifying, assigning oversight and keeping evidence serves every phase — the ones in force and the ones to come. A company that has this done doesn't need the dates memorised; a company that doesn't isn't saved by knowing them.

One simple priority rule: if any use in your inventory points at high risk — decisions about people: hiring, evaluating, granting — that one comes first and without waiting, because that's where obligations weigh most and where a mistake does genuine damage. If your whole inventory is minimal risk and transparency, the hygiene described in this guide is the bulk of the work, and what remains is keeping it current.

And a warning against the opposite excess, which also exists: over-compliance. Commissioning an enormous compliance programme for an inventory of three light uses is as poor a decision as ignoring the regulation. Fear sells oversized projects; the inventory gives you the true measure before you sign anything.

Five questions before you commission a compliance project

If you're considering getting help with the AI Act — from a law firm, a consultancy, or us — these five questions tell you how much project you genuinely need:

  1. Do we have the inventory of AI uses? If not, it comes first, and you can build it in-house.
  2. Does any use affect decisions about people: hiring, evaluating, granting, sanctioning?
  3. For each use, are we using a third party's system, have we modified it, or do we offer it as our own?
  4. What evidence could we show today if someone asked?
  5. Who owns this topic inside the company?

With those answers, the scope sizes itself: sometimes it's a project, very often it's a short list of internal homework. And a sixth question, free of charge, for the future: add one checkbox to your software purchasing process — "does this tool have AI inside?". It's the cheapest way to stop the inventory going stale within months.

One last thing, and it's how we see it: in the day-to-day of an SME, the AI Act is a data, process and systems matter far more than a lawsuit in waiting. That's how we treat it — as engineering and management: inventory, controls, oversight, evidence that works — not as a legal opinion. Where legal interpretation is needed, the word belongs to your advisors; our job is making sure that when that conversation comes, you have something orderly to show. If you want to see how this fits the way we work, here's our approach.

After reading

Does this sound like your case?

If this describes something sitting on your desk, tell us about it. We'll come back with a first read before proposing anything.

Tell us about your case

A first 30-minute call with direct senior interlocution — no commitment and no sales pitch.