EU AI Act compliance checklist 8 min read

The EU AI Act: an 8-point compliance checklist for SMEs

Published on EBM Solution

An operational checklist for artificial intelligence compliance in a business

This EU AI Act compliance checklist is for the companies that have to keep running and serving customers while the rules change around them. The European Union switched the spotlight on the world's first cross-cutting artificial intelligence regulation in August 2024, with gradual application through 2027. What follows is an operational view of what compliance actually means for a small or medium business, rather than another unreadable legal manual.

Why the AI Act concerns your SME even if you only use ChatGPT

Some context first. In 2025, 26.7% of Italian SMEs had tested or were regularly using artificial intelligence tools, a 50% increase on 2024. The problem is awareness: only 8% knew about the regulatory obligations that come with using those tools.

This is not only about companies building complex AI systems. If your business uses APIs from OpenAI, Anthropic or Google, the idea that it is the vendor's responsibility no longer holds: as a user you have obligations of your own. Whether you screen CVs with algorithms, run chatbots for customer service or apply credit scoring, you probably fall into the high-risk systems the Act regulates most strictly.

The four risk categories: where your system sits

The European approach rests on a pragmatic classification with four levels.

Unacceptable risk: systems banned since 2 February 2025, with sanctions up to 35 million euros or 7% of global turnover. This covers social scoring, subliminal manipulation and exploitation of psychological vulnerabilities.

High risk: systems that affect fundamental rights, safety or critical decisions. This is where 70% of the AI systems used by Italian digital companies fall: automated recruiting, credit assessment, human resources management, assisted medical diagnostics.

Limited risk: chatbots and generative systems that must declare their artificial nature immediately, since 2 February 2025. Vague wording does not work: the system must state plainly that it is an artificial intelligence assistant.

Minimal risk: the vast majority of AI systems currently in use, with no specific obligations beyond compliance with the GDPR.

The timeline that matters: when obligations actually start

The dates are concrete, not abstract.

2 February 2025: the bans on unacceptable-risk practices and the AI literacy obligation for staff entered into force. This means mandatory training on the fundamentals of AI for those who use it at work, an up-to-date inventory of the systems in use and internal policies for preventive assessment.

2 August 2025: obligations for general-purpose AI (GPAI) models entered into force, with full technical documentation, transparency on training datasets and copyright compliance. Governance rules and market surveillance structures became fully operational.

2 August 2026: full application for all high-risk systems, with national authorities fully operational. In Italy, the National Cybersecurity Agency (ACN) is the supervisory authority, while AgID handles notifications.

2 August 2027: compliance also required for models placed on the market before 2025. The transition period ends: everyone is in scope.

The 8-point operational checklist

What a company actually has to do to be ready.

1. Complete technical documentation

Saying that the company uses AI is not enough. You need documentation covering the system architecture, the development process, the training data used, the model evaluations and the security measures in place. For high-risk systems, exhaustive technical documentation is required to demonstrate compliance.

2. Solid data governance

Datasets must be relevant, representative and free of discriminatory bias. That means periodic data quality audits, checks on data provenance, traceability of sources and correction mechanisms when problems emerge.

3. Human oversight

No system can operate in complete autonomy on critical decisions. You need an identifiable human owner with real authority to intervene, documented escalation procedures and traceability of final decisions.

4. Algorithmic transparency

Users must understand how the system works and why they receive certain decisions. Saying only that the algorithm decided is not enough: you have to be able to explain the criteria used.

5. Cybersecurity by design

Italian law 132/2025 places strong emphasis on cybersecurity, with ACN competent also under NIS2. This means adequate protection against attacks, continuous vulnerability monitoring and incident response plans.

6. Continuous accuracy testing

Accuracy testing before placing the system on the market, periodic performance evaluations, benchmarks against sector standards and continuous improvement mechanisms.

7. Structured log retention

Retaining logs to allow audits and checks, a minimum retention period consistent with sector rules, and controlled access for the competent authorities.

8. Timely incident reporting

For models with systemic risk, an obligation to monitor and report serious incidents to the European AI Office. This requires clear incident identification procedures, predefined communication channels and respected notification timelines.

Sanctions: numbers worth thinking about

Fines can reach 35 million euros or 7% of annual worldwide turnover for the most serious breaches, 15 million or 3% for failing to meet high-risk system requirements, and 7.5 million or 1% for false or incomplete information.

The logic is clear: the higher the risk, the heavier the consequences. SMEs benefit from a proportional reduction, not an exemption. There is no discount on compliance, only on the size of the sanction.

Practical tools: you are not alone

The European Union has put concrete support tools in place.

European Commission platform: a self-assessment toolkit to evaluate the risk level of your systems and identify the specific obligations.

AIDA (Artificial Intelligence Data Act) toolkit: an operational framework for data management in AI, with sector-specific checklists.

GPAI code of practice: published on 10 July 2025, it offers a voluntary fast track to demonstrate compliance with the obligations for general-purpose models. Those who sign up can apply the standardised procedures, reducing audits and documentation.

Regulatory sandboxes: controlled environments to test AI systems before market release, with member states required to establish at least one by 2 August 2025. In Italy, at the end of the sandbox the regulator issues an exit report that can be used to demonstrate AI Act compliance.

The Italian landscape: a hidden competitive advantage

Italy is the first EU country with a national framework fully aligned with the AI Act, through law 132/2025 approved in September 2025. What can look like an extra bureaucratic burden is in practice an opportunity.

The Italian law introduces a one-billion-euro fund through Cdp Venture Capital to support SMEs and companies active in AI, cybersecurity, quantum computing and ICT. So there are incentives as well as constraints for those investing in compliance and responsible innovation.

Proportionate measures for SMEs and startups are included to avoid barriers to innovation, with attention to not stifling the small technology companies that make up the Italian production fabric.

The US approach: two philosophies compared

While Europe implements a horizontal, risk-based framework, the United States develops a sectoral approach through the coordination of existing agencies. There is no single American AI Act: each sector (healthcare, finance, transport) applies its own rules through the competent authorities.

This means European companies, at first carrying heavier obligations, may end up at an advantage over time: a single clear framework beats ten uncoordinated sector rules. European certification is likely to become a global benchmark, exactly as happened with the GDPR.

How to turn compliance into a competitive advantage

The AI Act is not only a cost. Companies that adapt early gain concrete benefits.

Access to funding: the European Union and Italian institutions are activating calls, vouchers and non-repayable grants designed to help companies through the adjustment process. These funds cover specialist advice, technology upgrades and staff training.

Certification as a distinguishing factor: certifying high-risk systems becomes a real competitive advantage that sets a company apart. In tenders and B2B relationships, certified compliance carries weight.

Lower reputational risk: an AI incident can cost far more than any fine. Solid governance processes protect the brand.

Customer trust: in a market full of vague tech promises, demonstrating regulatory compliance signals seriousness and reliability.

What to do on Monday morning

First, a preventive audit: map all AI systems in use, classify them by risk level and identify compliance gaps.

Second, structured internal training: the literacy obligation for every employee who uses artificial intelligence, with paths differentiated by role. A master's degree is not needed; two to four hours of practical training on how it works, its limits and responsible use are.

Third, a contract review: add AI-Act-ready clauses to contracts with technology vendors. If you use cloud services, external APIs or software as a service with AI components, you need to ensure your vendors are compliant too.

Fourth, operational documentation: map the systems used, update privacy notices and policies on transparency and automated decisions, and keep traceability of final decisions with a human in the loop.

A path, not a formality

The AI Act rewards companies that turn compliance into part of their operating culture rather than a formal exercise. Behind every regulatory obligation sits a concrete need of their customers: trust, transparency, control. EBM Solution supports companies through the mapping, the policy work and the architectural choices that make the obligations demonstrable.

Compliance reduces exposure without removing it: criminal liability under article 437-bis now concerns those who deploy the systems.

Have a project in mind?

Do you know where to start?

The goal is to pin down the problem, the priorities and the timing.

Book a first call

Frequently asked questions

Does the AI Act apply to a company that only uses ChatGPT?

Yes. It applies to any organisation that uses AI systems in a professional context in the European Union, regardless of size. Using a general-purpose tool through a consumer interface still makes the company a deployer with its own obligations.

What is a high-risk AI system for a small business?

High-risk systems are listed in Annex III of the Act. The most common cases for small companies are recruitment tools that screen or rank candidates and services with scoring components on customers.

Which deadlines are already active?

The bans on unacceptable practices and the AI literacy obligation have applied since 2 February 2025. General-purpose model obligations applied from 2 August 2025, and full application for high-risk systems starts on 2 August 2026.

What are the sanctions?

Up to 35 million euros or 7% of worldwide turnover for the most serious breaches, 15 million or 3% for high-risk system requirements, and 7.5 million or 1% for false or incomplete information. SMEs get a proportional reduction, not an exemption.

Where does a company start?

With an inventory of the AI systems in use, their risk classification and the data that passes through them. Without that picture, any compliance assessment is built on nothing.

Sources

Regulation (EU) 2024/1689 (AI Act) — full text on EUR-Lex, including articles 4, 26, 50, 99 and Annex III: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202401689

European Commission — official AI Act page with the application timeline, deadlines and priority actions: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

Italian law 132 of 23 September 2025 — provisions and delegations to the Government on artificial intelligence: https://innovazione.gov.it/notizie/articoli/approvata-in-via-definitiva-la-legge-italiana-sull-intelligenza-artificiale/

European Commission — General-Purpose AI Code of Practice, published 10 July 2025: https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai