EU AI Act checklist for SMEs: inventory, living docs, and disclosures

The EU AI Act applies to you if you place an AI system on the EU market, deploy one inside the EU, or your outputs affect people living in the EU, regardless of where your company is based. If any of that is true, your first move is not to read the full Regulation cover to cover. It is to build an inventory of every AI system you use or build, then run each one through the EU AI Act Compliance Checker to get a first-pass risk classification.
TL;DR:
- Most SMEs should prioritize creating a comprehensive inventory of all AI systems and classify them using the official compliance checker before diving into detailed regulations.
- High-risk AI systems affecting safety or fundamental rights require detailed technical documentation, ongoing monitoring, and registration in an EU database before deployment.
- Automating assessment, documentation, and evidence collection helps SMEs meet compliance efficiently and aligns with existing GDPR and cybersecurity processes to avoid duplication.
- Transparency disclosures, such as chatbot labelling and AI-content notices, are already enforceable since August 2025, with higher obligations phased in through 2028.
- Using platforms like ShieldIQ can streamline the compliance process by providing automated assessments, draft documents, and deadline tracking, reducing manual effort for SMEs.
Table of Contents
- EU AI Act checklist: the step-by-step sequence for a project sprint
- What are the EU AI Act risk tiers, and which one applies to you?
- What technical documentation does the EU AI Act require?
- How can SMEs run this checklist without a dedicated compliance team?
- When do EU AI Act deadlines actually take effect?
- How do you use the official compliance checker effectively?
- Where SMEs actually go wrong on this checklist
- How ShieldIQ turns this checklist into a working compliance programme
- Sources
- FAQ
EU AI Act checklist: the step-by-step sequence for a project sprint
Most compliance leads try to read the Regulation before they act. That is backwards. Run the checklist first, then read the detail once you know which parts actually apply to you.
- Inventory everything. List every AI system in use, including third-party APIs, embedded models inside vendor software, and open-source components. Name an owner for each.
- Classify by risk tier. Run each system through the official checker and record the outcome against the system in your inventory.
- Start living technical documentation. Do not wait for a finished product. Begin capturing design choices, data sources, and test results as you go.
- Build minimum controls. Add logging and traceability, a human oversight step, bias testing where relevant, and basic cybersecurity checks.
- Fix transparency gaps immediately. Add user disclosure notices to chatbots and label AI-generated content. These obligations are already active and cost little to implement.
- Prepare conformity outputs for high-risk systems. Line up documentation and, where required, book an external conformity assessment before deadlines bite.
- Assign deadlines and a review cadence. Give each task an owner, a due date, and a recurring review slot, not a one-off tick box.
The scope guidance on ShieldIQ's blog is worth a read if you are still unsure whether your business is even in scope before you run the sprint.
Pro Tip: Tackle transparency disclosures first. They typically take a developer a day or two, they are already enforceable, and they are the fastest way to show an auditor you have started.
What are the EU AI Act risk tiers, and which one applies to you?
The Act sorts systems into four tiers, and the tier decides how much work you face.
- Prohibited: Systems using manipulative techniques, social scoring, or real-time biometric categorisation in banned contexts. These cannot be used at all, so if you spot one internally, stop using it.
- High-risk: Systems affecting hiring, credit scoring, education access, law enforcement, or safety components in regulated products. These trigger conformity assessments, technical documentation, and registration obligations.
- Limited-risk: Chatbots, emotion-recognition tools, and generative content systems. These mainly require transparency disclosures to users.
- Minimal-risk: Everything else, such as spam filters or internal scheduling tools. No mandatory obligations beyond general good practice.
Decide the tier by asking three questions: what is the system's intended purpose, could it materially affect someone's fundamental rights or safety, and does it sit in a sector the Act specifically flags, such as employment or credit. If it lands as high-risk, Regulation (EU) 2024/1689 requires a conformity assessment, ongoing documentation, and registration in an EU database before deployment.
What technical documentation does the EU AI Act require?
For high-risk systems, technical documentation needs to cover the system's design and purpose, the data sources used to train and validate it, test results, risk mitigation measures, and a post-market monitoring plan.
Article 53 sets separate obligations for providers of general-purpose AI models, who must maintain technical documentation, share information with downstream developers, and in some cases publish a training data summary. Annex IV sets out the equivalent detail expected for high-risk systems generally.
- Design specification and intended purpose
- Data governance records: sources, collection methods, known limitations
- Validation and test results, including accuracy and robustness metrics
- Risk mitigation measures and residual risk disclosures
- Post-market monitoring plan and incident logging procedure
Retrofitting this after launch is slow and expensive. Guidance on Annex IV recommends treating documentation as a living file updated at each development milestone, not a report written at the end. A software bill of materials covering component versions, dataset sources, validation dates, and a changelog turns post-market monitoring from a scramble into a lookup exercise when an auditor asks.
High-risk providers who leave documentation until pre-launch often find they cannot reconstruct early validation decisions, because the people who made them have moved on or the records were never kept centrally. Automating evidence capture from day one avoids that gap entirely.
How can SMEs run this checklist without a dedicated compliance team?
Most SMEs do not have a security or legal team sitting idle waiting to document AI systems. The realistic path is automation, not headcount.
- Run an automated assessment against your inventory to get a scored gap analysis and a prioritised remediation list, rather than starting from a blank spreadsheet.
- Use AI-assisted policy drafting to produce a first draft of governance documents and technical write-ups, then review and adjust rather than writing from scratch.
- Set up deadline tracking so conformity and registration dates surface automatically instead of relying on someone remembering a spreadsheet tab.
- Collect evidence continuously: logs, disclosure records, and test outputs saved as they happen, not reconstructed weeks later.
Prioritise the four tasks that cut the most regulatory exposure for the least effort: the inventory, the documentation baseline, transparency disclosures, and basic cybersecurity hygiene. Integrating this work with your existing GDPR and cybersecurity processes avoids duplicating effort across frameworks, since much of the evidence, such as data handling records and incident logs, overlaps directly.
Pro Tip: If you already run GDPR records of processing activities, extend the same template to cover AI systems rather than building a parallel register from zero.
When do EU AI Act deadlines actually take effect?
Some obligations are already live. Transparency duties, such as chatbot disclosure and labelling AI-generated content, have applied since August 2025 under the Act's phased rollout. The bigger structural obligations land from 2 August 2026 onward, with high-risk conformity and registration windows extending through 2027 and 2028 depending on the system category.
| Obligation | Status |
|---|---|
| Prohibited practices ban | Already in force |
| Transparency disclosures (chatbots, AI-generated content) | Already in force |
| GPAI provider obligations (Article 53) | Phasing in from August 2026 |
| High-risk conformity assessment and registration | Phasing in through 2027–2028 |
Set a quarterly review cadence for anything classified high-risk, and an annual review for limited and minimal-risk systems. Enforcement sits with an AI Office and national competent authorities, and fines scale as a proportion of turnover for serious breaches, which is reason enough to build the review habit now rather than after a first warning letter.
How do you use the official compliance checker effectively?
Use the official checker as your first pass on every system, then bring in an internal or third-party assessment only for anything it flags as high-risk or ambiguous.
- Run each inventoried system through the checker individually rather than assessing the whole portfolio at once.
- Export the resulting flowchart or PDF and attach it directly to that system's file in your inventory.
- Feed the output into three things auditors will ask for: a risk register, a technical documentation status tracker, and a remediation timeline with owners and dates.
Treat the export as a starting brief for your project plan, not a finished compliance file. It tells you where to dig further, not the full answer.
Where SMEs actually go wrong on this checklist
The single highest-impact task is the inventory and classification step, and most SMEs skip straight to documentation without it. That is a mistake: you cannot document a system you have not formally recognised as in scope.

The recurring failure I see is fragmented records. One team knows about the hiring chatbot, another has quietly added a vendor's embedded scoring tool, and nobody has connected the two into a single register. Documentation written late, after a product has already shipped, is the second most common failure, and it is almost always worse than documentation written early and imperfectly.
Treat this as continuous governance, not a project with an end date. The systems change, the vendors change, and the Act's guidance will keep evolving.
— Matthew Lemon
How ShieldIQ turns this checklist into a working compliance programme
Running this checklist manually across a growing AI footprint takes real hours every month, hours most SMEs would rather spend on the product itself. ShieldIQ's EU AI Act module maps directly onto each step above: automated assessments generate the scored gap analysis, AI-driven policy drafting produces governance and technical documentation drafts, and deadline tracking keeps registration and conformity dates visible without a spreadsheet.

A typical engagement includes an initial automated assessment to establish your current gap position, a prioritised remediation plan built from that scoring, and recurring monitoring so evidence keeps accumulating instead of piling up before an audit. For SMEs already juggling GDPR, ISO 27001, or NIS2 obligations, the platform manages AI Act compliance alongside those frameworks from one dashboard, so overlapping evidence, such as data governance records, is captured once and reused. Visit the EU AI Act compliance page to run an assessment and see your gap analysis, or look at consulting services if you want a vCISO to guide the remediation plan directly.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act)
- EU AI Act Compliance Checker | AI Act Service Desk
- AI Act | Shaping Europe’s digital future
FAQ
Does the EU AI Act apply to non-EU companies?
Yes. It applies extraterritorially whenever a system is placed on the EU market or its output affects people in the EU, regardless of where the provider is based.
What is the first step in an EU AI Act checklist?
Build a full inventory of every AI system in use, including third-party APIs and embedded vendor tools, then classify each one by risk tier using the official checker.
Which AI systems count as high-risk under the Act?
Systems that materially affect hiring decisions, credit scoring, education access, or safety components in regulated products typically fall into the high-risk tier, triggering conformity assessments and registration duties.
Are transparency obligations already enforceable?
Yes. Disclosure duties for chatbots and labelling of AI-generated content have applied since August 2025, well ahead of the main 2026 to 2028 phase-in for high-risk obligations.
Can a platform like ShieldIQ help with EU AI Act compliance?
Yes. ShieldIQ's platform runs automated assessments, drafts governance documentation, and tracks deadlines, which covers most steps in this checklist without needing an internal compliance team.