The EU AI Act Compliance Checklist for SMB operators
Outcome: Identify which of three EU AI Act roles you play and the exact obligations that follow, in under an hour.
If your business uses AI tools built by someone else (ChatGPT, Claude, Copilot, Notion AI) to do your own work, you are almost certainly fine. The EU AI Act puts its heaviest obligations on the companies that build and sell AI systems, not on the businesses that use them. The hard part is not the compliance work. It is figuring out which of three roles you actually play, because everything else follows from that.
This checklist answers that first. It is based on hands-on experience implementing AI across 500+ client projects, and it gets most operators to a clear answer in under an hour. It is a practical starting point, not legal advice; once you know where you stand, run the relevant sections past your lawyer.
What's inside
The checklist is structured so you stop as soon as you find your path:
- Three opening questions that determine your obligations and send you to the right section. Most readers exit at the first one.
- A role definition section so you can label yourself a User, a Deployer, or a Provider, because your obligations follow your role, not your industry.
- A five-minute prohibited-uses screen. These are banned outright and no compliance process makes them legal.
- A risk classification section covering minimal, limited, and high-risk use cases, with concrete SMB examples in each tier.
- A vendor due-diligence checklist with the five questions to ask before signing any contract for a third-party AI system.
- Operational requirements for the small number of operators who confirm high-risk systems.
- Three scenarios most guides skip: who carries the obligation when you implement AI for clients, whether the Act reaches you if you are outside the EU, and how no-code automations are classified.
- A key-dates timeline and a quick-reference table mapping every role and tier to its specific obligations.
The one question that settles 95% of cases
Are you building an AI product to sell or deploy to others, or are you using someone else's tool for your own work? If you use off-the-shelf AI tools internally for content, operations, customer service, coding, or research, you screen for prohibited uses and you are done. No registration, no conformity assessment, no documentation beyond what GDPR already demands.
The exceptions are narrow but worth checking: a customer-facing chatbot needs one disclosure line, and any system that makes or heavily influences decisions about individual people in hiring, credit, insurance, healthcare, education, or justice lands in high-risk territory and needs real work before 2 August 2026.
Why the deadline still matters
There has been a lot of noise about a provisional agreement to delay the high-risk obligations. Until that is formally adopted and published, 2 August 2026 remains the operative deadline, and conformity assessments for complex systems take three to six months. If you are building something high-risk, the timeline allows less room than it appears.
Grab the checklist
The full EU AI Act Compliance Checklist (every section, the agency-operator and non-EU scenarios, and the role-by-tier reference table) unlocks right below. Enter your email and the PDF is yours.
There is a specific kind of relief in knowing which category you are in. Not optimism. Just clarity. Start with the three questions.
Enter your email and we'll send the download link for “The EU AI Act Compliance Checklist for SMB operators”. The whole thing, not a sample. You'll also get FutureBrief, my weekly brief for SMB operators.