EU AI Act Readiness for Small Business Measurement Plan
A practical guide to EU AI Act readiness for small business measurement plan, with decision checks and a repeatable workflow for small teams.
A practical guide to EU AI Act readiness for small business measurement plan, with decision checks and a repeatable workflow for small teams.
Every image is selected for a distinct editorial role, then checked for source, rights and fit before it enters the story.
Supporting the implementation of the AI Act with clear guidelines | Shaping Europe’s digital future: The AI Office has already published guidelines for providers and deployers of AI high-risk systems, transparency obligations, and a template for reporting serious incidents.
EU agrees to simplify AI rules to boost innovation and ban nudification apps to protect citizens | Shaping Europe’s digital future: The Commission proposed the Digital Omnibus on AI as part of the EU's simplification agenda to boost Europe's competitiveness.
AI Omnibus enters into force | Shaping Europe’s digital future: On 27 July 2026, the AI Omnibus entered into force, extending timelines for high-risk AI systems in Annex III to 2 December 2027 and for systems embedded in physical products to 2 August 2028.
AI Act | Shaping Europe’s digital future: The AI Act defines four levels of risk for AI systems and applies strict obligations to high-risk systems before they can be placed on the market, including risk assessment, high-quality datasets, logging and documentation.
Most small business owners I speak with treat the EU AI Act as a distant compliance deadline they will address later. The practical problem is not the law itself but the absence of a repeatable way to know what you have, where it sits and what evidence you would need to show if asked. The intended outcome of a measurement plan is not a legal filing. It is a current, defensible inventory that lets you answer two questions: which of our AI uses might attract regulatory attention, and what record would we produce to explain them. According to the AI Act policy page on Shaping Europe’s digital future, the regulation defines four levels of risk and applies strict obligations to high-risk systems before they can be placed on the market. That framing matters because it tells you the measurement plan must first sort uses by risk tier, not by technical complexity. A common failure mode is starting with the technology stack instead of the business process. If you begin by listing models and APIs, you will miss the point. The Act regulates specific uses, not general-purpose tools. Your first action is to write down the outcome each AI system produces for a real person: a hiring recommendation, a credit decision, a content moderation flag. If you cannot name the affected person and the decision in one sentence, you have not yet defined the use well enough to measure it.
A measurement plan is only as reliable as the evidence it references. Before you draft a single row in your inventory, decide what counts as a trustworthy source. The AI Act policy page on Shaping Europe’s digital future explains that high-risk systems must be supported by adequate risk assessment, high-quality datasets, activity logging and detailed documentation. That tells you the evidence you collect should be verifiable, dated and linked to a specific system version. I recommend three categories: official regulatory text and published Commission guidelines, internal process documentation that describes how a system is used in practice, and technical logs that show what the system actually did. Avoid relying on marketing claims or vendor assurances that are not backed by auditable records. The AI Omnibus, which entered into force on 27 July 2026, extended timelines and simplified some obligations for small and mid-cap companies, but it did not remove the need for evidence. If anything, the extended deadlines give you more time to build a proper evidence trail. Use that time to collect dated screenshots of configuration settings, signed-off process documents and any correspondence with providers about system capabilities. If you cannot produce a dated record, treat the claim as unverified and flag it for review.
The core of the measurement plan is a simple table that lists every AI use in your business, its intended purpose and the risk tier it might fall into. Start with the outcome each system produces for a real person, as described in the first section. Then map that outcome to the risk categories defined in the AI Act: unacceptable, high, transparency or minimal. The AI Act policy page on Shaping Europe’s digital future provides a clear breakdown of what falls into each tier. For example, AI systems used in employment, education or access to essential services are likely to be high-risk. A chatbot that answers general product questions is probably minimal risk, but one that screens job applicants is not. Record the system name, the business process it supports, the data it uses, the decision it influences and the risk tier you have assigned. Add a column for the evidence you hold and a column for gaps. This inventory is not a one-off exercise. It should be reviewed whenever you add a new AI tool, change a workflow or receive updated regulatory guidance. The AI Office has published guidelines for providers and deployers of high-risk AI systems, and those guidelines will evolve. Your inventory should evolve with them.
A measurement plan must show who is responsible for each AI use and which workflows are affected. For each entry in your inventory, name the person or role that oversees the system in practice, not just the person who signed the procurement form. If the system influences a decision about an individual, record which internal process that decision feeds into and who reviews it. The AI Act policy page on Shaping Europe’s digital future notes that high-risk systems require human oversight, transparency and logging. Even if your system is not classified as high-risk today, recording oversight now creates a habit that will serve you if the classification changes. Map the affected workflows end to end. If a system flags content for review, document what happens after the flag: who sees it, what action they take and where that action is recorded. If a system scores loan applications, document how the score is used in the final decision and whether the applicant can challenge it. This workflow mapping is not about building a perfect process diagram. It is about being able to show, with dated evidence, that you know how AI decisions move through your business and where a human can intervene.
I need to be clear about what this measurement plan is and is not. It is an operational tool that helps you organise evidence and identify gaps. It is not legal advice, and it does not replace a qualified review by a lawyer who understands the AI Act and your specific business. The AI Act policy page on Shaping Europe’s digital future states that high-risk systems are subject to strict obligations before they can be placed on the market, and those obligations include conformity assessments that require legal and technical expertise. Your measurement plan prepares you for that conversation. It gives your legal adviser a structured starting point instead of a pile of vendor brochures and vague recollections. Keep the plan in a format that is easy to share and update. A shared spreadsheet or a simple document works better than a proprietary tool that only one person can access. Date every entry and every revision. If you later need to demonstrate that you took reasonable steps to prepare, a dated, versioned record is far more useful than a polished document with no history.
A measurement plan that sits in a drawer is not a plan. It is a snapshot that decays the moment you change a workflow or update a model. Build a maintenance rhythm that matches your business cadence. For most small teams, a quarterly review is enough, provided you also review when you add a new AI tool or change a process that an existing tool touches. During each review, check three things. First, has the risk classification of any system changed because of new regulatory guidance or a change in how you use it? Second, is the evidence you hold still current and dated? Third, are the oversight roles still accurate? The AI Omnibus, which entered into force on 27 July 2026, extended timelines for high-risk systems in Annex III to 2 December 2027 and for systems embedded in physical products to 2 August 2028. Those dates are not far away. Use the time to build a maintenance habit, not to postpone the first review. If you start now, you will have several review cycles completed before the obligations apply, and you will have a dated trail that shows you were preparing, not scrambling.
The measurement plan is only useful if it leads to action. The final section of your plan should list the concrete next steps you will take before the next review. For each gap you identified in the inventory, write a single action, assign it to a named person and set a completion date. Common next steps include documenting a workflow that is currently only in someone’s head, requesting dated configuration evidence from a vendor, or asking a legal adviser to review a specific high-risk classification. Do not try to close every gap at once. Pick the three that matter most, where the gap is widest or the risk is highest, and close those first. The AI Act policy page on Shaping Europe’s digital future makes clear that the regulation is risk-based. Your preparation should be too. If you have a system that influences employment decisions, sort that before you worry about a chatbot that answers opening-hours questions. The measurement plan is not a project with an end date. It is a practice. Start small, keep it current and let the evidence accumulate. When the obligations apply, you will have something to show that is better than a last-minute panic.
It is a structured inventory that records every AI use in your business, its intended purpose, the risk tier it might fall into under the AI Act, the evidence you hold and the gaps you need to close. The plan is an operational tool, not a legal filing. It helps you answer two questions: which of our AI uses might attract regulatory attention, and what record would we produce to explain them. The AI Act policy page on Shaping Europe’s digital future defines four risk levels, and your plan should sort uses by risk tier, not by technical complexity.
The AI Omnibus, which entered into force on 27 July 2026, extended the timelines. High-risk AI systems listed in Annex III must comply from 2 December 2027. High-risk systems embedded in physical products such as machinery or toys must comply from 2 August 2028. Prohibitions on certain AI practices, including nudification apps, apply from December 2026. These dates give small businesses time to prepare, but the measurement work should start now so you have a dated trail of evidence before the obligations apply.
Start by writing down the outcome each system produces for a real person, such as a hiring recommendation or a credit decision. Then map that outcome to the risk categories defined in the AI Act: unacceptable, high, transparency or minimal. The AI Act policy page on Shaping Europe’s digital future provides a breakdown. Systems used in employment, education or access to essential services are likely high-risk. A chatbot answering product questions is probably minimal risk. If you are unsure, flag the system for qualified legal review.
Collect verifiable, dated evidence in three categories: official regulatory text and published Commission guidelines, internal process documentation that describes how a system is used in practice, and technical logs that show what the system actually did. Avoid relying on vendor marketing claims without auditable records. Dated screenshots of configuration settings, signed-off process documents and correspondence with providers about system capabilities are all useful. If you cannot produce a dated record, treat the claim as unverified.
No. The measurement plan is an operational tool that organises evidence and identifies gaps. It prepares you for a conversation with a qualified legal adviser but does not replace one. The AI Act requires conformity assessments for high-risk systems that need legal and technical expertise. Your plan gives your adviser a structured starting point. Keep it in a shareable, dated format so you can demonstrate that you took reasonable steps to prepare before the obligations applied.