EU AI Act

The SMB EU AI Act Compliance Checklist: 15 Steps Before August 2026

February 1, 2026 · 8 min read · By Jasone Rodriguez

The EU AI Act is the world's first comprehensive AI regulation, and it affects far more companies than most realize. If your organization uses AI systems and serves EU customers, even from outside Europe, you need to prepare. Here are 15 concrete steps SMBs should take before the August 2, 2026 enforcement deadline.

Phase 1: Assessment (Do This Now)

1

Inventory all AI systems in your organization

List every AI system your company uses: from customer-facing chatbots to internal analytics tools. Include third-party AI services (ChatGPT, Copilot, Salesforce Einstein) and any custom ML models. Many organizations discover they use 3-5x more AI systems than they initially estimated.

2

Classify each system under the EU AI Act risk tiers

The Act defines four risk levels: prohibited (social scoring, real-time biometric surveillance),high-risk (hiring decisions, credit scoring, medical devices),limited risk (chatbots, emotion detection), and minimal risk (spam filters, games). Your obligations scale dramatically with risk level.

3

Determine if the Act applies to your organization

The EU AI Act applies to: (a) any organization placing AI systems on the EU market, (b) any organization deploying AI systems within the EU, (c) providers or deployers outside the EU whose AI system output is used within the EU. If you serve EU customers through any AI-powered feature, you're likely in scope.

4

Assess your current compliance posture

Before building a compliance plan, understand where you stand today. Do you have documented AI policies? Is there human oversight for high-risk decisions? Are your AI systems transparent to users? A gap analysis reveals exactly what needs to change.

Phase 2: Documentation (Q1 2026)

5

Create an AI Use Policy

Document your organization's principles for AI use: what AI can and cannot be used for, who approves new AI deployments, how decisions are reviewed, and how employees should interact with AI tools. This becomes your governance foundation.

6

Document risk assessments for high-risk systems

Any high-risk AI system requires a formal risk assessment covering: intended purpose, potential harms, mitigation measures, data quality requirements, accuracy metrics, and human oversight procedures. This must be updated when the system changes.

7

Create model cards for each AI system

Model cards document the technical and ethical aspects of each AI system: what it does, what data it was trained on, known limitations, performance metrics across different populations, and intended vs. prohibited use cases.

8

Establish a data governance policy

AI systems are only as good as their data. Document how data is collected, processed, stored, and deleted for each AI system. Address data quality requirements, bias mitigation procedures, and data subject rights (especially under GDPR, which overlaps significantly).

9

Write an incident response plan

What happens when your AI system produces harmful outputs or makes an incorrect decision? Define clear procedures for identifying, reporting, investigating, and remediating AI incidents. Include escalation paths, notification requirements, and post-incident review processes.

Phase 3: Implementation (Q2 2026)

10

Implement human oversight mechanisms

High-risk AI systems must have human oversight. This doesn't mean a human reviews every decision, but it means humans can: understand the system's capabilities, monitor operations, interpret outputs, and override or reverse decisions when necessary.

11

Ensure transparency and user notification

Users interacting with AI systems must be told they're interacting with AI. If your chatbot handles customer service, it needs to disclose that. If AI generates content, it should be labeled. Emotion detection and biometric categorization systems have additional notification requirements.

12

Set up monitoring and logging

High-risk AI systems require ongoing monitoring: track accuracy metrics, detect drift, log decisions, and maintain audit trails. This isn't just a compliance checkbox; it's how you catch problems before they become incidents.

13

Train your team on AI governance

AI literacy is now a legal requirement under the EU AI Act (enforced since February 2, 2025). Ensure your team understands: which AI systems they use, what the risks are, how to escalate concerns, and what the organization's AI policies are.

Phase 4: Ongoing Compliance

14

Schedule quarterly reviews

AI governance isn't a one-time project. Schedule quarterly reviews to: reassess risk levels for existing systems, evaluate newly adopted AI tools, update documentation, review incident logs, and adjust policies as the regulatory landscape evolves.

15

Monitor regulatory updates

The EU AI Act is framework legislation: implementing acts, guidelines, and harmonized standards are still being developed. Subscribe to updates from the EU AI Office, your industry association, and reliable AI governance publications. The rules will get more specific over time.

Start Your Compliance Journey Today

Our free assessment quiz identifies your risk level and top compliance gaps in 2 minutes. No account required.

Take the Free Assessment