What is the key point?

An SME readiness plan should begin with scope, an AI inventory and role-and-risk classification, then prioritise the evidence and controls that apply. The aim is a defensible operating position, not an enterprise-sized compliance programme.

Step one: know where AI is used

Start with a list. Every AI tool, feature, vendor model, or workflow that touches your product, employees or customers. Include the intended purpose, data involved and who is responsible. This inventory is the foundation everything else builds on.

Most companies can complete this in a week. Most have never written it down.

Step two: classify your EU AI Act role

For each system, you need to know whether you are a provider, deployer, distributor or importer under the AI Act. Role determines which obligations apply. Many SMEs using third-party AI models are deployers with specific requirements around transparency, oversight and documentation.

A quick classification exercise for your main AI systems takes a day and gives you a defensible position if buyers ask.

Step three: document your controls

Write down how AI decisions are reviewed, who can override them, how incidents are reported and what supplier checks you do. A one-page control summary per system is enough for most procurement questions.

Three steps. Most SMEs can complete them in six to eight weeks. The output is real evidence, not a compliance checkbox.

Primary source

Frequently asked questions

What should an SME do first for EU AI Act readiness?

Identify every material AI system the business builds, buys or uses, assign an owner, and document the organisation's likely role and risk classification.

Can an SME take a proportionate approach?

Yes. Governance and evidence should reflect the organisation's role, risk exposure, size and resources, while still meeting any obligations that apply.

What evidence should an SME retain?

Keep the inventory, classification rationale, policies, supplier evidence, risk and impact assessments, oversight records, training evidence, monitoring and incident decisions.

Use the relevant guide to deepen your understanding, or move straight to a practical assessment.