EU AI Act Checklist for SMBs: What You Actually Need to Do
Last updated: June 2026 · Guardrail Studio
The EU AI Act is the first broad AI law, and it reaches further than most SMBs realize. Here's a practical checklist to find your risk tier and document compliance — without hiring a legal team.
Does the EU AI Act apply to your business?
The Act applies to providers and deployers of AI systems whose output is used in the EU — which means it can apply to you even if you're based in Singapore, the UK, or the US, if you serve EU customers or your AI-assisted output reaches the EU. Rather than guess, assume it may apply and take the proportionate steps below; they're good practice under every major framework anyway.
The four risk tiers — which one are you?
- Unacceptable risk — banned outright (e.g., social scoring, manipulative AI).
- High risk — AI used in hiring, credit, education, or safety-critical contexts. Strict obligations: risk management, documentation, human oversight.
- Limited risk — chatbots and AI-generated content. Transparency obligations: tell people they're dealing with, or seeing, AI.
- Minimal risk — spam filters, most productivity AI. Few specific obligations; follow good practice.
Most SMBs live in 'limited' or 'minimal' — but if you use AI to make decisions about people, you're likely in 'high risk', which is exactly why a good policy forbids unsupervised AI decisions about individuals.
SMB checklist: 8 things to do now
- Inventory the AI tools your team actually uses.
- Classify each use case by risk tier (most will be minimal/limited).
- Put a written AI usage policy in place.
- Add transparency: label AI-generated content and AI chat interactions where expected.
- Require human oversight for any decision affecting a person.
- Vet vendors' data-training and retention terms before approving a tool.
- Train staff and keep a training record.
- Maintain a risk register and review it as the Act's provisions phase in.
What documentation the EU AI Act expects
For most SMBs the evidence that matters is straightforward: a current AI policy, a record of your AI use cases and their risk classification, proof of human oversight on higher-risk uses, and staff training records. You don't need a compliance department — you need the right documents, kept current.
How Guardrail's regulation cheat-sheet covers this
Guardrail's AI Policy OS includes a regulation cheat-sheet that explains the EU AI Act risk tiers in plain English, plus the policy, risk register, training, and oversight rules that produce exactly the documentation the Act expects.
Document EU AI Act compliance the practical way
Policy, 25-risk register, staff training, playbooks, and proof — editable and live in an afternoon.
Get the AI Policy OS from S$129 →Frequently asked questions
Does the EU AI Act apply to non-EU companies?
It can. The Act has extraterritorial reach — if your AI system's output is used in the EU, or you sell to EU customers, obligations may apply regardless of where you're based. Don't assume you're exempt because you're outside the EU.
What risk tier is my business likely in?
Most SMB uses of everyday AI tools fall under 'minimal' or 'limited' risk, which mainly means transparency obligations. The exception is using AI for decisions about people — hiring, credit, performance — which can be 'high risk' with strict obligations.
What documentation does the EU AI Act expect?
For most SMBs: a written AI policy, a record of your AI use cases and their risk, evidence of human oversight on higher-risk uses, and training records. Guardrail's kit provides all of these as editable templates.