AI Act checklist for SMEs: a 30-day plan
A four-week AI Act plan for SMEs covering inventory, roles, risk, AI literacy, transparency, vendors, controls and evidence.
AI ACT · IMPLEMENTATION PLAN
You will not “finish compliance” in 30 days, but you can move from informal tool use to a controllable system: know which AI you have, who owns it, where risks sit, what must stop and which evidence is missing. This plan produces decisions, not merely documents.
Before day 1: name the owner and stop rule
A management sponsor sets the objective, while one owner coordinates product, IT, legal/privacy, security, HR and marketing. Do not delegate the project solely to technical or legal staff. Each system needs an operating owner able to change access, stop use and request evidence. [EU-LIT] [EU-DESK]
Initial rule: stop or escalate potential prohibited practices, sensitive decisions about people, unauthorised data, publishing or irreversible action without approval. Do not wait for inventory completion to limit an obvious risk. Record who decided and how long suspension lasts. [EU-PROH] [EU-RISK] [EU-REG]
Week 1: discover and inventory
Interview teams and check extensions, subscriptions, APIs, automation, shared accounts, embedded AI features and card-paid tools. Include shadow AI. For each use case record purpose, owner, vendor, users, data, output, affected people, integration and status. [EU-LIT] [EU-DESK]
The week’s deliverable is register v1 plus unknowns, not a perfect inventory. Mark active, under review, restricted and retired. Evidence includes tool exports, owner responses and key settings. Any ownerless use case enters review rather than remaining “everyone’s”. [EU-LIT] [EU-DESK]
Week 2: role, risk and data
For each system identify possible provider, deployer, importer or distributor roles and document why. Screen prohibited practices, Article 6 and Annexes I/III, Article 50 transparency, GPAI and sector rules. Use the law and Compliance Checker as support, not certification. [EU-REG] [EU-DESK] [EU-PROH] [EU-RISK] [EU-A50]
Map data flow and keep AI Act separate from GDPR: categories, purpose, assessed lawful basis, vendors, sub-processors, location, retention and rights. Prioritise by consequence and uncertainty. Cases involving people, sensitive data, autonomous action or unclear role receive an owner and remediation deadline. [EDPB-28] [EU-REG]
Week 3: people, interface and controls
Build role-based AI literacy: management understands accountability and stopping; users verify output and protect data; developers control versions, permissions and tests; editors check sources and metadata; support recognises errors and escalates. Retain participation and practical assessment, not just slides. [EU-LIT] [EU-LIT-REP]
Implement priority controls: first-interaction AI disclosure where applicable, draft and confirmation for actions, data minimisation, role access, justified logs, escalation, override, adversarial testing and rollback. For content, separate technical marking, visible disclosure and editorial review. [EU-A50] [EU-A50-G] [EU-LIT] [EU-REG]
Week 4: vendors, tests and evidence
Assess vendors by actual product: model and version, role, data, training, retention, region, sub-processors, security, change notice and exit. Connect answers to contract and configuration. Marketing statements or generic certifications do not replace use-case controls. [EU-GPAI-G] [OAI-DPA] [OAI-SUB]
Test normal, ambiguous, adversarial and failure scenarios, then assemble the evidence pack: system record, classification and sources, data map, vendor, tests, limits, transparency copy, training, approval, incident and rollback. A new colleague should be able to reconstruct the decision. [EU-DESK] [EU-LIT] [EU-REG]
Day 30: management review and the next 90 days
Management approves active systems, restrictions, accepted risks, budget and owners. Each action has a deadline and evidence: missing contract, failed test, training, interface change, data deletion or specialist review. “Continue temporarily” needs an expiry date. [EU-DESK] [EU-LIT]
The next 90 days integrate remediation into procurement, release, security, privacy, editorial and incident processes. Reassess the register when model, purpose, data, vendor or impact changes. Readiness is a living decision system, not a file closed on day 30. [EU-DESK] [EU-REG] [EU-LIT]
Official sources and verification date
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- European Commission — AI Act Service Desk and Compliance Checker
- European Commission — AI Literacy Questions & Answers
- European Commission — repository of AI literacy practices
- European Commission — transparency obligations under Article 50
- European Commission — guidelines on transparency obligations
- European Commission — high-risk AI system classification
- European Commission — guidelines on prohibited AI practices
- European Commission — guidelines for general-purpose AI model providers
- European Data Protection Board — Opinion 28/2024 on AI models
- OpenAI — Data Processing Addendum
- OpenAI — current sub-processor list