AI Act deployer obligations for SMEs apply when a small or medium-sized business uses an AI system to support decisions, sort requests, monitor activity, or influence people and operations. The practical goal is not to produce a legal essay. It is to make a decision you can defend: keep the use case, constrain it, or stop it until the evidence is strong enough. For an SME, the concrete outcome should be clear ownership, evidence on input data and human oversight, and a threshold that triggers action.
Executive answer
The AI Act is built around risk control, not only paperwork. It allocates obligations based on the role of the actor and the type of system, and it includes requirements around human oversight, data quality, documentation, and incident handling for certain use cases EU AI Act. The European Commission’s overview makes the same point: obligations depend on the use case and where the organisation sits in the AI value chain Commission overview.
For an SME, the right question is not “are we fully compliant yet?” but “do we have enough evidence to decide safely?”. That is where an AI audit for SMEs or an AI readiness assessment becomes useful: it translates governance language into a decision threshold.
Decision criteria
Before deployment or continued use, management should verify five concrete criteria.
| Criteria | Owner | Evidence to inspect | Decision threshold |
|---|---|---|---|
| Actual system use | Business lead | Use case description and affected population | If the system influences a sensitive decision, escalate review |
| Input data | IT / business owner | Source, freshness, quality, usage rights | If data is incomplete or uncontrolled, fix before rollout |
| Human oversight | Operations manager | Who can review, override, and correct | If no one can intervene, restrict the use case |
| Logging / incidents | Security / compliance | Incident log and usage traces | If no follow-up exists, implement a minimum register |
| Impact on people | Leadership / HR / legal | Possible effects on customers, workers, candidates | If impact is high, formal approval is needed |
AI governance should answer one practical question: who takes responsibility when the system is wrong? In most SMEs, the absence of a named owner is already a risk signal.
Matrix to complete
Use a weighted decision matrix with criteria, scores, and a decision threshold. Score each item from 1 to 5, multiply by its weight, and total the result.
| Criterion | Weight | Score 1-5 | Weighted score | Evidence |
|---|---|---|---|---|
| Control of input data | 30% | |||
| Effective human oversight | 25% | |||
| Traceability and incidents | 20% | |||
| Impact on rights or opportunities | 15% | |||
| Ability to correct quickly | 10% |
Recommended threshold:
- 80/100 or above: keep the use case with routine control.
- 60 to 79/100: allow only under conditions and with a remediation plan.
- Below 60/100: suspend or sharply limit until corrected.
Recommended owner: COO or managing director, with business and IT execution. Evidence to inspect: logs, validation steps, usage policy, incident register, vendor notice, data rights.
If you are comparing an audit offer, focus on reusable deliverables first: the matrix, the risk register, the priorities, and the decision threshold. A practical reference point is this AI audit report example for SMEs, which shows the kind of output that helps management decide.
Interpretation
A weak score on human oversight is not mainly a technical issue; it is an operating model issue. Someone must be able to pause, correct, or escalate. A weak score on input data means the system may be producing consistent but unreliable outputs. No incident log means the SME cannot show that it is monitoring how the system behaves over time.
The CNIL guidance stresses the need to document purposes, secure data, and anticipate effects on individuals in AI projects CNIL AI guidance. That matches what an AI audit for SMEs should do: turn risk into evidence and evidence into a decision.
Action plan
In 7 days, an SME can produce a useful decision.
- Name one owner per use case.
- Evidence: responsibility note.
- Threshold: no use case without an owner.
- Next action: create a simple AI usage register.
- Verify input data.
- Evidence: source, update frequency, usage rights, exclusions.
- Threshold: any uncontrolled source blocks rollout.
- Next action: fix or remove the source.
- Test human oversight.
- Evidence: an error scenario and the intervention path.
- Threshold: if no human can take back control, restrict use.
- Next action: define a control point.
- Start incident tracking.
- Evidence: a minimal log of errors and corrections.
- Threshold: no trace means immediate remediation.
- Next action: maintain a basic incident register.
For broader context, see AI AUDIT’s English homepage and the English blog. If you want to turn this framework into a decision-ready deliverable, the English order page is here.
Hypothetical example, clearly identified
A professional services SME uses an AI assistant to pre-screen incoming requests. The sales lead expects time savings, but nobody checked the data source or set a human review step for sensitive cases.
Using the matrix: input data 2/5, human oversight 1/5, incidents 1/5, impact 4/5, quick correction 3/5. The likely score falls below the threshold. Decision: limit the tool to internal drafting, prohibit automated client decisions, and launch a targeted AI audit for SMEs on the control points.
FAQ
AI Act deployer obligations for SMEs where to start?
Start by naming an owner, listing AI use cases, and checking input data. Evidence: a use case register. Next action: classify each use case by impact.
AI Act deployer obligations for SMEs checks before making a decision?
Check human oversight, incident traceability, and data usage rights. Evidence: procedures, logs, vendor terms. Threshold: if one item is missing, delay the decision.
AI Act deployer obligations for SMEs cost risks and priorities?
Start with use cases affecting customers, workers, or candidates. Owner: leadership with business input. Evidence: the weighted matrix. Next action: fix the weaknesses that push the score below 60/100.