EU AI Act compliance guide for SMEs
What Regulation (EU) 2024/1689 requires, when each obligation bites, and the shortest defensible path to conformity for a small or mid-sized organisation.
What Regulation (EU) 2024/1689 requires, when each obligation bites, and the shortest defensible path to conformity for a small or mid-sized organisation.
The AI Act (Regulation (EU) 2024/1689) applies to providers placing AI systems on the Union market and to deployers using them in the Union — including non-EU actors where the output is used in the EU (European Parliament and Council, 2024, Art. 2).
Article 5 prohibits eight categories of unacceptable-risk practice (e.g. social scoring, untargeted scraping of facial images). Article 6 and Annex III define high-risk systems, which carry the bulk of the compliance burden. Limited-risk systems (Art. 50) trigger transparency duties, and minimal-risk systems are unregulated.
Providers of GPAI models (Chapter V) must maintain technical documentation, publish a summary of training data, and comply with EU copyright law. Models with systemic risk (training compute above 10^25 FLOPs) trigger model evaluation, adversarial testing and cybersecurity duties (European Parliament and Council, 2024, Art. 51–55).
Article 9 risk management, Article 15 accuracy/robustness testing, Article 72 post-market monitoring — all map to controls you may already run for ISO 27001 and ISO 42001. Managing them separately creates duplication and evidence gaps.
ISO-STANDARD.app ships a ready-to-adopt ISO 42001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.