EU AI Act compliance guide for SMEs

What Regulation (EU) 2024/1689 requires, when each obligation bites, and the shortest defensible path to conformity for a small or mid-sized organisation.

Michael McCarroll 14 min read Updated June 2026

1. Scope and risk tiers

The AI Act (Regulation (EU) 2024/1689) applies to providers placing AI systems on the Union market and to deployers using them in the Union — including non-EU actors where the output is used in the EU (European Parliament and Council, 2024, Art. 2).

Article 5 prohibits eight categories of unacceptable-risk practice (e.g. social scoring, untargeted scraping of facial images). Article 6 and Annex III define high-risk systems, which carry the bulk of the compliance burden. Limited-risk systems (Art. 50) trigger transparency duties, and minimal-risk systems are unregulated.

2. Timeline that actually matters

  • 2 Feb 2025 — Article 5 prohibitions and AI-literacy duties (Art. 4) apply.
  • 2 Aug 2025 — Obligations on general-purpose AI (GPAI) models and governance chapter.
  • 2 Aug 2026 — Most high-risk obligations, penalties and Annex III systems apply.
  • 2 Aug 2027 — Annex I high-risk product obligations apply in full (European Parliament and Council, 2024, Art. 113).

3. A five-step conformity path

Step 1

Inventory and classify

Maintain an AI system inventory. For each entry, decide provider vs deployer role and classify against Art. 5, Annex III and Art. 50. Document the reasoning — the assessment itself is auditable evidence (European Parliament and Council, 2024, Art. 6(3)).
Step 2

Run a risk-management process

Article 9 requires a continuous, iterative risk-management system across the lifecycle. ISO 31000:2018 principles map directly, and ISO/IEC 23894:2023 provides the AI-specific overlay (ISO, 2018; ISO/IEC, 2023).
Step 3

Produce technical documentation

Annex IV lists the mandatory contents: system description, data governance, monitoring, human oversight, cybersecurity. Treat it as a living document, not a launch artefact.
Step 4

Design human oversight

Article 14 requires effective oversight by natural persons. Specify what an overseer can do (stop, override, disregard) and train them — the training record is evidence.
Step 5

Register and monitor post-market

High-risk systems must be registered in the EU database (Art. 49) and subject to post-market monitoring (Art. 72). Incidents must be reported within 15 days (Art. 73).

4. General-purpose AI (GPAI) obligations

Providers of GPAI models (Chapter V) must maintain technical documentation, publish a summary of training data, and comply with EU copyright law. Models with systemic risk (training compute above 10^25 FLOPs) trigger model evaluation, adversarial testing and cybersecurity duties (European Parliament and Council, 2024, Art. 51–55).

Run AI Act conformity in the same workspace as ISO 27001

Article 9 risk management, Article 15 accuracy/robustness testing, Article 72 post-market monitoring — all map to controls you may already run for ISO 27001 and ISO 42001. Managing them separately creates duplication and evidence gaps.

ISO-STANDARD.app ships a ready-to-adopt ISO 42001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

When does the EU AI Act apply?
The Regulation entered into force on 1 August 2024. Prohibitions on unacceptable-risk systems applied from 2 February 2025, obligations on general-purpose AI models from 2 August 2025, and the bulk of high-risk system obligations apply from 2 August 2026 (European Parliament and Council, 2024).
Does the Act apply to non-EU companies?
Yes. Article 2 gives the Regulation extraterritorial reach where output produced by an AI system is used in the Union, regardless of where the provider or deployer is established (European Parliament and Council, 2024).
What is a 'high-risk' AI system?
Systems listed in Annex III (e.g. biometrics, critical infrastructure, employment, essential services) and systems that are safety components of products covered by Union harmonisation legislation listed in Annex I (European Parliament and Council, 2024).
How does ISO/IEC 42001 help?
ISO/IEC 42001:2023 provides a management-system framework for AI governance and is widely expected to become the presumption-of-conformity route for many Article 9–15 obligations once harmonised standards are published (ISO, 2023; CEN-CENELEC JTC 21, 2024).

References

  • CEN-CENELEC JTC 21 (2024) Work programme on AI standardisation in support of the AI Act. Brussels: CEN-CENELEC.
  • European Parliament and Council (2024) Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L series, 12 July 2024.
  • ISO (2018) ISO 31000:2018 Risk management — Guidelines. Geneva: International Organization for Standardization.
  • ISO (2023) ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system. Geneva: ISO.
  • ISO/IEC (2023) ISO/IEC 23894:2023 Information technology — Artificial intelligence — Guidance on risk management. Geneva: ISO.
Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →