EU AI Act SME Governance Checklist
Use this as an operating checklist before legal review. It is not legal advice.
Regulatory snapshot: reviewed 2026-08-04. Recheck the official AI Act text, implementation timeline, Commission guidance, and applicable national rules before every decision; dates and classification guidance can change.
AI Inventory
| System | Vendor/owner | Purpose | Users | Data | Output use | Risk rating |
|---|---|---|---|---|---|---|
| Internal / customer / public | Public / internal / confidential / restricted | Draft / recommendation / action / decision | Low / limited / possible high-risk |
Role Classification
- Candidate role(s): provider / deployer / importer / distributor / product manufacturer / other.
- Record the facts supporting each candidate role; “buyer” is not itself a statutory role.
- Record substantial modification, own-name/brand use, and downstream deployment facts.
- Have qualified counsel confirm the role and obligations for the actual system and use.
Minimum Controls
- Named owner.
- Approved use boundary.
- Data rule.
- Human oversight rule.
- Disclosure rule.
- Logging and recordkeeping rule.
- Vendor evidence collected.
- Stop condition documented.
Legal-classification escalation flags
These flags are intentionally broader than a definitive Annex I/III classification. Escalate before launch, but do not label a system high-risk or prohibited from this checklist alone:
- Employment or worker management.
- Education or vocational training.
- Credit, insurance, or access to essential services.
- Healthcare or medical triage.
- Law enforcement, migration, asylum, or border control.
- Critical infrastructure.
- Biometrics, emotion recognition, or sensitive categorization.
- Decisions that materially affect rights, opportunities, or access.
Current timeline check
- Official source and access date:
- Rule or obligation being assessed:
- Applicable date under the current consolidated timeline:
- Transitional or sector-specific rule:
- Counsel confirmation:
Vendor Evidence
- Training opt-out or data-use terms.
- Data processing location.
- Retention controls.
- Subprocessor list.
- Security documentation.
- Admin controls and audit logs.
- AI Act/GDPR documentation.
- Change notification process.
Review Cadence
- Inventory review owner:
- Review frequency:
- Last review:
- Open risks:
- Next action: