July 30, 2026
by
AI Expert Team

EU AI Act Compliance Checklist

EU AI Act Compliance Checklist

An EU AI Act compliance checklist is no longer something only large enterprise legal teams need to worry about. If your business uses AI tools, sells into European markets or works with EU-based clients, the new regulation applies to you regardless of where you are headquartered. For UK SMEs still treating this as a distant Brussels problem, the window to prepare is closing faster than most realise.

The EU AI Act entered into force in August 2024. Phased obligations are already active, with the majority of requirements applying from August 2026. That gives SMEs a shrinking runway to understand what the law requires and take practical steps to comply.

What the EU AI Act Actually Requires

The Act classifies AI systems into four risk tiers: unacceptable risk, high risk, limited risk and minimal risk. Most SMEs will operate in the limited or minimal risk categories, but that does not mean there is nothing to do. Even lower-risk AI use comes with transparency obligations and the consequences of getting it wrong range from reputational damage to fines of up to €15 million or 3% of global annual turnover under Article 99 of the EU AI Act.

Understanding where your AI tools sit within the risk framework is the essential first step. After that, the checklist begins.

Does the EU AI Act Apply to UK Businesses?

Yes. The EU AI Act operates on a market-access basis, similar to GDPR. If your AI system is placed on the EU market, used by people in the EU or produces outputs that affect EU citizens, the Act applies to your business. Brexit does not exempt UK companies from this obligation. It means you may face dual compliance requirements: UK AI governance frameworks alongside EU obligations.

Your EU AI Act Compliance Checklist

Work through each section below. This is not an exhaustive legal document, but it gives your leadership team a clear picture of what needs to be addressed.

Step 1: Inventory Your AI Systems

List every AI tool your business uses or has deployed. Include third-party tools, not just software you have built. Many SMEs are surprised to find they are using AI across more functions than they realised, from recruitment screening and customer service chatbots to financial forecasting and content generation.

For each system, record what it does, who uses it and who is affected by its outputs. This inventory forms the foundation of everything that follows.

Step 2: Classify Each System by Risk Level

Map each AI system against the EU AI Act's risk tiers. High-risk systems include AI used in recruitment, credit scoring, education assessment, law enforcement and critical infrastructure. If you operate in any of these sectors, your compliance obligations are significantly more demanding.

Limited-risk systems, such as chatbots and AI-generated content tools, primarily require transparency measures. You must inform users they are interacting with an AI. Minimal-risk systems, such as spam filters or AI-assisted product recommendations, carry no specific obligations beyond general good practice.

Step 3: Assess Your Role Under the Act

The Act distinguishes between providers (those who develop or place AI systems on the market) and deployers (those who use AI systems in a professional context). Your obligations differ significantly depending on which category applies to you, and in many cases SMEs will be deployers of third-party tools.

If you are a deployer, you still carry responsibility for ensuring the AI systems you use comply with the Act, particularly around transparency, human oversight and data governance. Do not assume your software vendor has handled everything on your behalf.

Step 4: Review Transparency and Documentation Requirements

Transparency is a baseline obligation across all risk levels. Users must know when they are interacting with an AI system. For high-risk systems, the requirements go further: technical documentation, conformity assessments, logging of system activity and a clear human oversight mechanism must all be in place.

Even for lower-risk deployments, documenting your AI use is sensible practice. It demonstrates due diligence, supports internal governance and positions your business well if regulatory scrutiny increases. Our AI compliance service covers exactly this ground for SMEs who need structured support.

Step 5: Check Your Data Governance

High-risk AI systems must be trained and operated using data that meets specific quality standards. Bias, gaps and errors in training data can create both regulatory and reputational risk. Even if you are deploying a third-party high-risk system, you need to understand how that system was built and validated.

This connects directly to broader data governance within your business. If your data practices are not already documented, this is the moment to address that. Our AI readiness assessment helps SMEs identify exactly these gaps before they become compliance problems.

Step 6: Establish Human Oversight Protocols

For high-risk AI systems, the Act requires meaningful human oversight. This means a qualified person must be able to understand, monitor and where necessary override the AI system's outputs. Tick-box oversight does not satisfy this requirement.

Review whether your team has sufficient understanding of the AI tools they work with to exercise genuine oversight. If not, AI training for your team is a practical and immediate step.

Step 7: Appoint Responsibility and Log Activity

Someone in your business needs to own AI compliance. In a larger organisation that might be a designated AI officer. In an SME it is more likely a senior leader who takes responsibility for the compliance register, monitors regulatory updates and ensures obligations are met as the law evolves.

Keep a log of AI use, decisions made with AI support and any incidents where AI outputs were incorrect, harmful or disputed. This log is not just a regulatory requirement for high-risk systems. It is good operational discipline.

What Happens If UK SMEs Ignore This?

The EU AI Act is enforced by national market surveillance authorities across EU member states. UK businesses trading into the EU can be investigated, have products or services restricted and face financial penalties. Beyond enforcement, the reputational cost of being found non-compliant in a B2B context can be significant, particularly if your clients are large enterprises who will increasingly require supply chain AI compliance as part of their own obligations.

The GDPR experience is a useful reference point here. Many SMEs underestimated their exposure until enforcement actions began making headlines.

How AI Expert Helps SMEs Navigate This

Our AI consulting services are built around practical, commercially focused support for SMEs. We do not bury clients in legal complexity. We help you understand what applies to your business, what it requires and how to build the right processes without disproportionate cost or disruption.

Jon Rew, Managing Director at Scimitar Sports, describes how working with AI Expert changed his team's perspective: 'We learned a lot from the AI Readiness Assessment, which is surprising as it didn't take long to complete. The report highlighted things that were likely costing us money and they were, which we addressed in the AI Workshop. We're now implementing the AI Roadmap with a phased plan and AI Expert are supporting us every step of the way.'

That same structured approach applies directly to compliance work. Start with an honest assessment of where you are, build a clear roadmap for what needs to change and implement it in a way your team can actually sustain.

If you are uncertain where to begin, our AI Workshop is a fixed-fee diagnostic that cuts through the noise and tells you exactly what matters for your business. We also cover compliance considerations in depth through our dedicated AI compliance guidance.  

Frequently Asked Questions:

Does the EU AI Act apply to UK businesses after Brexit?

Yes. The Act applies to any business placing AI systems on the EU market or deploying AI that affects EU users, regardless of where that business is based. UK companies selling into Europe or serving EU clients need to assess their obligations now.

What is a high-risk AI system under the EU AI Act?

High-risk AI systems are those used in sensitive areas including recruitment, credit scoring, education, healthcare, law enforcement and critical infrastructure management. These systems face the most stringent obligations, including technical documentation, conformity assessments and mandatory human oversight.

Do I need to comply if I only use third-party AI tools?

If you deploy third-party AI tools in a professional context, you are classified as a deployer under the Act and carry compliance responsibilities. You cannot assume your software provider has met all obligations on your behalf. You must verify the tools you use are compliant and implement the required transparency and oversight measures yourself.

When do EU AI Act obligations fully apply?

The Act entered into force in August 2024. Prohibitions on unacceptable-risk AI applied from February 2025. Obligations for high-risk systems and most other requirements apply from August 2026. Some sector-specific provisions have longer transition periods running to 2027. The EU AI Act compliance checklist set out above is not an optional exercise for businesses trading in or into Europe. It is a practical, time-sensitive response to a regulatory framework that carries real commercial consequences. Start with your AI inventory, understand your risk classification and put the right governance structures in place before the August 2026 deadlines arrive. If you want expert guidance tailored to your business, get in touch with AI Expert today.

Share this post

Subscribe to our AI newsletter

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.