5 stepsfrom unsure to defensible
Aug 2026enforcement in force since
Feb 2025literacy duty already live
No DPOrequired to start

Most EU SMEs do not have a compliance officer, and the EU AI Act does not require you to hire one to get started. What it does require is that you take real, documented measures. This is a practical five-step plan you can run yourself, sized for a small business, and built for the situation you are in now: the enforcement and penalty framework switched on in August 2026.

The goal is not perfection. It is defensibility: a clear picture of the AI you use, the risks it carries, and evidence that you acted. Start now, because the AI literacy duty has been live since February 2025 and supervision has been live since August 2026.

Readiness is not a certificate. It is being able to show, on the day someone asks, that you knew where your AI was and did something about it.

Agentic Fluxus

Do not wait for the high-risk deferral to save you. The high-risk Annex III obligations were deferred to 2 December 2027, but the literacy duty, the prohibited practices, and the enforcement framework were not. Enforcement is live now, so treat readiness as overdue rather than upcoming.

The Five Steps at a Glance

From inventory to records

A plan a small team can actually run

Inventory

Find every AI tool in use

Classify

Sort by risk and role

Literacy

Train the people who use AI

Transparency

Disclose AI to users

Records

Keep the evidence

Step 1: Inventory Your AI

Find every AI tool in use

List every AI system anyone in the business uses, including the informal ones. Copilot, ChatGPT, the AI features quietly added to your CRM, your design tools, and your support desk all count. Ask each team what they actually use, not what is officially approved. Most inventories surface more AI than leadership expected. You cannot govern what you have not named.

Step 2: Classify by Risk and Role

Sort by risk and role

For each tool, note who uses it, what decisions it influences, and who is affected. Flag anything that touches hiring, credit, education, or essential services, since these are the high-risk Annex III domains (obligations deferred to 2 December 2027, but worth diarising now). Everything else is likely limited or minimal risk, where transparency and literacy are your main duties. This step tells you where to spend effort.

Typical SME exposure once AI is mapped

Step 3: Close the Literacy Gap

Train the people who use AI

Article 4 requires you to take measures to support the development of AI literacy, calibrated to each role. Deliver role-relevant training covering how the tools work, their risks, the obligations that attach, and safe human oversight. A generic 'what is AI' video does not satisfy the duty on its own. Include contractors and freelancers who use AI on your behalf, because the obligation reaches them through you.

Step 4: Fix Transparency

Disclose AI to users

Since 2 August 2026 the transparency rules have been in effect, except the Article 50(2) machine-readable marking duty for providers of generative AI, which applies from 2 December 2026. If customers interact with an AI chatbot, or you publish AI-generated content, disclose it clearly. This is usually a small change to wording and interface, and it removes an easy, visible source of non-compliance. Review every customer-facing point where AI is involved and make the disclosure plain.

Step 5: Keep the Records

Keep the evidence

Compliance you cannot evidence is compliance you cannot prove. Keep a simple, living record: your AI inventory, your risk notes, who was trained on what and when, and your transparency measures. For a small business this can be a single maintained document. When a market surveillance authority asks, this is what defends you.

What Good Looks Like

After the five steps

A named inventory

You know every AI tool in the business

Risk clarity

You know which tools need the most attention

Trained people

Article 4 measures cover staff and contractors

Evidence on file

You can show measures, not just intent

Compliance Checklist

SME readiness plan

Click to check off

Common Questions

Begin with an inventory of every AI tool in use, then classify by risk and role, train the people who use AI, fix transparency, and keep records. You do not need a compliance officer to take these first steps.

Enforcement is already live: the penalty framework and Article 4 supervision have applied since August 2026, and the literacy duty itself since February 2025. The next fixed date is 2 December 2027, when the high-risk Annex III obligations apply.

Only if you use AI in domains like hiring, credit, or essential services. Those obligations were deferred to 2 December 2027, but you should identify and diarise them now.

An AI inventory, risk notes, a training log showing who was trained on what and when, and a note of your transparency measures. A single maintained document is enough for most SMEs.

Free tool: want a shortcut to Step 1 and Step 2? Run the AI Readiness Check to map your exposure in about ten minutes.

What To Do Right Now

10 min
Run the free AI Readiness Check to map your exposure.
1 hour
Complete your AI inventory across every team.
3.5 hrs
Train your team to Article 4 with the Agentic Fluxus staff course.

Ready to get your team compliant?

Staff AI Compliance Awareness · €39/person · Certificate included · 14-day guarantee

View Course