The EU AI Act in practice: what SMEs actually need to do
An AI registry, risk assessments, employee AI literacy: a plain-language guide to the obligations that apply to ordinary businesses using AI.
Most coverage of the EU AI Act focuses on the handful of "high-risk" use cases and headline fines. What gets less attention is the set of baseline obligations that apply far more broadly, including to small and medium businesses that are simply using AI tools day to day, not building them. Here's what that actually looks like in practice.
You're probably a "deployer," not a "provider"
If your business uses AI tools built by someone else, such as a chatbot, a CV-screening feature or an AI writing assistant, you're generally a "deployer" under the Act rather than a "provider." Deployer obligations are lighter than provider obligations, but they're not nothing, and they scale with how the tool is used.
AI literacy is a baseline requirement
One of the most broadly applicable obligations is ensuring staff who use or are affected by AI systems have a sufficient level of AI literacy: understanding what the tools do, their limitations, and how to use them responsibly. In practice, this means short, role-specific training rather than a generic policy document nobody reads.
Keep an inventory of what you actually use
An AI registry (a simple, maintained list of the AI systems your business uses, what they're used for and who's responsible for them) is good practice regardless of formal requirements, and it becomes the foundation for everything else: risk classification, training scope and incident response.
Risk assessments aren't only for "high-risk" systems
Even where a tool doesn't fall into a formally high-risk category, a short risk assessment (what could go wrong, who's affected, and what the mitigation is) is a useful and increasingly expected exercise. For tools that touch hiring, credit, or other decisions about people, this becomes more important, not optional.
A Responsible AI policy ties it together
Rather than a long compliance document, an effective Responsible AI policy is short enough that people actually read it: what tools are approved, what data can and can't be put into them, who to ask before adopting something new, and how issues get reported.
Where to start
If none of this exists yet, the starting point isn't a legal review, but an inventory. Once you know what AI tools are actually in use across your business (often more than leadership expects), the registry, risk assessments and policy follow naturally and can usually be put together over a few weeks.
This is exactly the kind of documentation we help clients put together as part of an engagement, drafted with both the legal requirements and your day-to-day operations in mind.
Not sure what applies to your business?
Book a free intro call and we'll walk through what's relevant to your size and sector.
Book your intro call