EU AI Act Readiness for Small Business Failure Modes and Controls
A practical guide to EU AI Act readiness for small business failure modes and controls, with decision checks and a repeatable workflow for small teams.
A practical guide to EU AI Act readiness for small business failure modes and controls, with decision checks and a repeatable workflow for small teams.
Every image is selected for a distinct editorial role, then checked for source, rights and fit before it enters the story.
The AI Omnibus entered into force on 27 July 2026, extending timelines and simplifying obligations for smaller businesses.
High-risk AI systems in Annex III face rules from 2 December 2027, while those in physical products apply from 2 August 2028.
The AI Office began enforcing the AI Act on 2 August 2026, alongside national authorities.
The Commission has published guidelines on high-risk systems, transparency obligations, and serious incident reporting.
The problem is not whether the EU AI Act applies to you. It is that you cannot answer that question without a structured inventory of how AI is actually used in your business. Most small teams have a handful of tools doing quiet work: a chatbot on the website, a summariser in the inbox, a scoring model in recruitment, or a document classifier in customer support. Each of those uses sits somewhere on the risk scale, and the Act's obligations depend on that placement. The intended outcome of this guide is a working method, not a legal opinion. By the end you should be able to list every AI use, note its intended purpose, record who oversees it, and identify which workflows it touches. That evidence base is what a qualified reviewer will need later. Without it, you are guessing. With it, you can have a proper conversation about what applies and what does not. This is a staging exercise, not a compliance certificate.
Before you write anything down, decide what counts as evidence. The European Commission's AI Office has published a set of practical guidelines, including one on the practical application of high-risk requirements and another on transparency obligations. These are primary sources. They matter more than vendor marketing pages or blog posts that summarise the Act from memory. The Commission has also published a template for reporting serious incidents and guidance on the AI system definition. For a small business, the most useful starting points are the official AI Act page and the AI Act Single Information Platform. The AI Omnibus, which entered into force on 27 July 2026, extended timelines and simplified some obligations for small and mid-cap companies. That means any checklist you build now should reflect the amended rules, not the original text alone. Keep a dated list of the sources you used. That list becomes part of your evidence trail.
Start with a simple table. Columns: tool name, what it does, who set it up, what data it sees, and what decision it influences. Do not judge yet. Just record. A chatbot that answers FAQs is different from a chatbot that triages complaints. A summariser that condenses meeting notes is different from a tool that scores job applicants. The Act's risk categories are use-based, not technology-based. The same model can be low-risk in one context and high-risk in another. For each use, write the intended purpose in one sentence. If you cannot write that sentence, you do not yet understand the tool well enough to assess it. That is a finding, not a failure. The inventory is the foundation for everything else. It also helps you spot shadow AI: tools that staff adopted without formal approval. Those are the ones that often cause surprises.
For each AI use, note who is responsible. It might be the person who bought the tool, the person who configured it, or the person who reviews its output. If no one is responsible, that is a gap to close. Also record which workflows the tool touches. Does the chatbot feed into your CRM? Does the summariser send text to your legal team? Does the scoring model influence who gets an interview? These connections matter because the Act looks at the whole system, not just the model. The AI Omnibus extended some SME simplifications to small mid-cap companies, but it also gave the AI Office extended oversight of certain systems. That means your documentation should show a clear line from each tool to its human reviewer. If the tool makes a recommendation, who checks it? If the tool makes an error, how would you know? Write those answers down. They become the operational evidence that a future review can examine.
This guide is operational preparation. It helps you organise facts, identify gaps, and prepare questions. It is not legal advice. The distinction matters because the EU AI Act is a regulation with enforcement consequences, and the AI Office began enforcement on 2 August 2026. National authorities are involved too. A qualified lawyer or compliance professional should review your inventory before you make any public claims about compliance. What you can do now is prepare the ground. You can document your AI uses, record oversight, and note which workflows are affected. You can also track the Commission's published guidelines, including the ones on transparency and high-risk systems. The AI Omnibus has changed some timelines, so make sure your notes reflect the current version. When you do speak to a professional, you will be able to give them a clear picture instead of a vague description. That saves time and money.
The value of this exercise is the evidence trail you leave behind. Keep a dated log of every AI use you identify, every source you consult, and every decision you make about risk level. If you decide a tool is low-risk, write down why. If you decide a tool needs more scrutiny, note what evidence would change your mind. The Commission has published guidelines on the practical application of high-risk requirements and on transparency obligations. Those are reference points you can cite in your log. The AI Omnibus also introduced a simplified obligation for registering exempted AI systems in the EU database, so check whether that applies to you. The goal is not to build a perfect file. It is to build a file that a qualified reviewer can use. If you cannot show your work, you cannot expect anyone to trust your conclusions. This is the difference between a claim and an evidence-based position.
The method only works if it produces action. Set a date, perhaps two weeks from now, to complete your first inventory. Aim for a list of every AI tool in active use, with the intended purpose and the responsible person for each. Then schedule a second pass to map those tools to workflows and note any gaps in oversight. The measurable outcome is not a compliance certificate. It is a document that answers three questions: what AI do we use, who watches it, and what does it touch? If you can answer those, you are ready for a qualified review. If you cannot, you know exactly what to work on next. The AI Act is not going to disappear, and the enforcement clock is already running. The practical move is to build your evidence base now, while you have time to think, rather than later, when you are under pressure.
It can. The Act is use-based, not size-based. A small business using AI for recruitment, credit scoring, or critical infrastructure could be in scope. The AI Omnibus, in force since 27 July 2026, extended some SME simplifications to small mid-cap companies and extended timelines for high-risk systems. The practical step is to inventory your AI uses and assess each one against the Act's risk categories. That inventory is the evidence a qualified reviewer will need.
Under the AI Omnibus, rules for high-risk systems in Annex III, such as those used in biometrics, education, employment, and migration, apply from 2 December 2027. Rules for high-risk systems embedded in physical products like lifts or toys apply from 2 August 2028. The AI Office began general enforcement on 2 August 2026. These dates matter for planning, but your preparation should start now.
You should document every AI use, its intended purpose, the data it processes, the person responsible for oversight, and the workflows it touches. You should also keep a dated log of the sources you consulted, such as the Commission's guidelines on high-risk systems and transparency. This evidence base is what a qualified reviewer will use to assess your position.
No. The AI Act is the original regulation, adopted in 2024. The AI Omnibus is a set of amendments proposed in November 2025, adopted in June 2026, and in force since 27 July 2026. It simplifies some obligations, extends timelines for high-risk systems, and clarifies certain rules. Any readiness work should reflect the amended version, not the original text alone.
You can prepare operationally. You can inventory your AI uses, document oversight, and map affected workflows. You can also track the Commission's published guidelines. What you should not do is make public claims about compliance without qualified review. The Act has enforcement consequences, and a lawyer or compliance professional should assess your specific situation before you make any commitments.