Regfortis
EU AI Act compliance checklist for SMEs
A practical, prioritised checklist covering key currently applicable EU AI Act obligations for SMEs deploying AI tools, with clear deadlines and links to detailed guidance on each requirement.
Last regulatory review: 14 August 2026 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
How to use this checklist
This checklist is organised by deadline — the most urgent obligations first. Work through Section 1 immediately: these are legal requirements already in force. Sections 2 and 3 cover preparation for upcoming obligations. The checklist assumes your business is a deployer — a company using AI systems developed by others. If your business develops or places AI systems on the market (a provider), additional obligations apply that are not fully covered here.
Immediate — obligations in force now
1
Act now
Article 4 — AI literacy
In force: 2 August 2026
- Identify every AI system or AI-powered tool your business currently uses in a professional context.
- Map which staff members or contractors interact with, oversee, or make decisions based on those AI systems.
- Assess whether each person's existing knowledge is adequate for the AI they use and the risk it carries — a customer service chatbot user needs less AI literacy support than an HR manager using AI-assisted shortlisting.
- Provide appropriate briefings, guidance documents, or training. No specific format or certification is required by law — proportionality applies.
- Document what you have done: who was briefed, when, and on which AI systems. Keep records in case of supervisory enquiry.
- Schedule a review date — at least annually, or whenever a new AI system is adopted.
Article 50 — Transparency
In force: 2 August 2026
- Identify any AI systems your business deploys that directly interact with customers, employees, or members of the public — chatbots, virtual assistants, automated response systems.
- Ensure users are told they are interacting with an AI before or at the start of the interaction, unless it is obvious from context.
- If your business generates or distributes AI-created images, audio, video, or text content, ensure appropriate technical measures or disclosure labels are in place to identify it as AI-generated.
- Document your transparency measures and the basis for any "obvious from context" exceptions you rely on.
Article 5 — Prohibited AI practices
In force: 2 February 2025
- Confirm your business does not use AI systems that manipulate users subliminally or exploit vulnerabilities of persons with disabilities, elderly persons, or economically vulnerable groups.
- Confirm you do not operate a social scoring system that rates individuals based on their behaviour in unrelated contexts.
- Confirm you do not use real-time remote biometric identification systems in publicly accessible spaces (narrow law-enforcement exceptions exist but do not apply to most SMEs).
- Confirm you do not use AI to infer emotions of employees or students in professional or educational settings, beyond safety-relevant applications.
December 2026 — new prohibitions (Regulation (EU) 2026/1744)
2
Prepare now
Regulation (EU) 2026/1744 (the Omnibus amendment) added two further practices to the Article 5 prohibited list. These apply from 2 December 2026. Consult the official text at EUR-Lex to confirm the exact scope of each prohibition as it applies to your business.
- Review the two new Article 5 prohibitions added by Regulation (EU) 2026/1744 against your current and planned AI use-cases.
- If any planned AI deployment falls within the new prohibitions, discontinue or redesign before 2 December 2026.
December 2027 — Annex III high-risk AI obligations
3
If your business uses AI systems in the Annex III high-risk categories (employment/HR, credit scoring, insurance, education assessment, critical infrastructure, etc.), the full Chapter III deployer obligations apply from 2 December 2027 under Article 26.
- Review your AI system inventory against the Annex III high-risk categories.
- For each high-risk system, identify the provider and obtain any required technical documentation.
- Prepare a fundamental rights impact assessment for each Annex III system your business deploys.
- Implement human oversight measures for Annex III AI decisions as required by Article 26(2).
- Register applicable Annex III AI systems in the EU AI public database before the deadline.
Read the full Annex III guide
Ongoing — AI system inventory and monitoring
∞
- Maintain an AI system inventory documenting every AI tool your business uses, its purpose, provider, risk category, and compliance status.
- Review and update the inventory whenever a new AI tool is adopted or an existing one is significantly changed.
- Designate a person responsible for AI compliance — even if this is a part-time role in a small team.
- Monitor EU AI Act guidance from the European AI Office as it is published.
Frequently asked questions
Do small businesses need to comply with the EU AI Act?
Yes. The EU AI Act applies to all businesses operating in the EU or deploying AI for EU users, regardless of size. There is no SME or headcount exemption. However, the proportionality principle means that a small business using a basic AI tool has lighter obligations in practice than a larger organisation using AI for consequential decisions such as CV screening or credit assessment.
Which EU AI Act obligations apply right now, in August 2026?
Two obligations are in force from 2 August 2026: Article 4 (AI literacy), which requires businesses to take proportionate measures to ensure staff dealing with AI have sufficient AI literacy; and Article 50 (transparency), which requires disclosure to users when they interact with an AI system. Article 5 prohibited practices have applied since 2 February 2025.
When do Annex III high-risk AI obligations apply to deployers?
The full Chapter III obligations — including fundamental rights impact assessments, human oversight, EU AI database registration, and the Article 26 deployer duties — apply from 2 December 2027. This date was amended from the original 2 August 2026 by Regulation (EU) 2026/1744. Businesses with high-risk AI use-cases should begin preparation now.
What are the penalties for non-compliance with Articles 4 or 50?
Under Article 99(3) of Regulation (EU) 2024/1689, violations of obligations including Articles 4 and 50 can attract fines of up to €15 million or 3% of global annual turnover, whichever is higher. These are maximum figures — supervisory authorities apply them proportionately. Early and documented compliance is the most effective mitigation.
Get a personalised compliance picture
The free Regfortis assessment evaluates all current obligations against your specific AI use-cases and produces a prioritised action list for your business.
Start free assessment
Back to full guide
Related guides
- EU AI Act key dates and deadlines
- Article 4: AI literacy in detail
- Article 50: transparency requirements
- Annex III high-risk AI guide
- AI system inventory guide
- Official regulatory sources
This checklist is for informational purposes only and does not constitute legal advice. Verify all obligations against the official text of Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744.