AI Act prohibited practices for SMEs should be handled as a decision problem, not as an abstract legal list. The practical goal is to screen use cases before they create legal and operational exposure, then decide whether to stop, redesign, or allow them with controls. For an SME, the right output is a documented decision, a named owner, and a clear threshold for action.
Executive answer
Start by identifying use cases that influence people, access, work, scoring, or vulnerability. Some AI practices are prohibited under the EU AI Act when they involve manipulation, exploitation of vulnerabilities, or certain forms of social scoring and surveillance; the legal text is the primary reference for classification in the AI Act, and the Commission explains how the framework separates prohibited, high-risk, and lower-risk uses in its overview of the regulatory framework. For SMEs, the outcome of an AI readiness assessment is not “use AI” or “avoid AI”; it is a defensible decision on each use case.
Decision criteria
Apply four checks: the business purpose, who is affected, how autonomous the system is, and what data or signals it uses. Owner: business lead, with legal, privacy, or compliance input when people are affected. Evidence to inspect: workflow description, vendor documentation, prompts or rules, data sources, retention settings, and human override paths. Decision threshold: if the system can influence hiring, access to a service, individual ranking, or a vulnerable person’s treatment, escalate immediately. CNIL guidance is useful here because it stresses purpose limitation, proportionality, and data control in AI use in its AI guidance. That is exactly where AI governance becomes operational for SMEs.
Matrix to complete
Use this weighted decision matrix with your team. Score each item from 1 to 5 and set an escalation threshold before any pilot.
| Criterion | Owner | Evidence to inspect | Score 1-5 | Threshold |
|---|---|---|---|---|
| Does the use case affect a person or a sensitive group? | Business lead | Workflow map and affected population | 4+ = enhanced review | |
| Can it influence an important decision? | HR / Sales / Operations | Decision rules and human oversight | 4+ = pause | |
| Are the data inputs limited and lawful? | IT / Privacy | Legal basis, minimisation, retention | 3+ = fix required | |
| Does the vendor explain system limits? | Procurement / Legal | Documentation, clauses, logs | 3+ = no-go | |
| Is human review effective? | Business lead | Escalation process and sampling | 4+ = conditional go |
Total score: 0-8 low priority, 9-15 targeted review, 16-25 stop and run a full AI audit for SMEs. This turns AI risk assessment into a practical threshold instead of a guess.
Interpretation
High scores mean the SME should stop deployment and document the reason. Mid-range scores mean the team should correct the blocking issues before a pilot. Low scores do not mean “no risk”; they mean the use case may proceed with proportionate controls. If several use cases are competing for attention, rank them by impact on people and decision criticality, not by technical novelty. That is usually the fastest way to reduce exposure without slowing useful work.
Action plan
Primary owner: business lead. Control owner: IT, privacy, or compliance. Evidence pack to collect within 7 days: use-case inventory, vendor terms, input data list, decision path, human review steps, and any past incidents. Decision threshold: if the use case touches hiring, service access, vulnerable users, or a significant individual outcome, it should not go live before review. SMEs can also compare sensitive contexts to see how screening works in practice; these internal articles show the approach in regulated settings small healthcare businesses and law firms. For a broader entry point, see AI AUDIT for SMEs and the AI AUDIT blog. If you want to move from uncertainty to a structured review, the booking page is a practical starting point.
Hypothetical example
A small professional services firm wants an AI tool to pre-screen job applications and rank candidates. Owner: HR. Evidence: ranking criteria, data inputs, appeal route, and human sign-off. Interpretation: because the system affects access to employment, the threshold should be strict. Decision: no automated ranking without human review and documented criteria. After 30 days, measure value with three indicators: number of files reviewed by a human, number of corrections made, and time saved without a drop in quality.
Process in steps
- Inventory current or planned AI use cases.
- Identify the people, roles, or groups that may be affected.
- Review the purpose, data inputs, system settings, and human oversight.
- Score the matrix and set a stop, review, or conditional-go threshold.
- Record the decision, owner, and supporting evidence.
- Fix any blocking issues before a pilot or release.
- Revisit the dossier after 30 days of real use.
Frequently asked questions
How should an SME make the decision?
Use the matrix, assign an owner, and set a clear stop or review threshold before deployment. The goal is not to guess; it is to create a defensible record of the decision.
What evidence matters most?
Check purpose, data inputs, vendor limits, human oversight, and the impact on affected people. If the evidence is missing, the answer is not ready.
How should value be measured after 30 days?
Track time saved, correction rate, exceptions, and avoided incidents. If risk increases, the value case is not validated.
Final check
Before sign-off, ask three questions: is the use case prohibited, controllable, or acceptable; is the evidence sufficient; and is human supervision actually effective? If any answer is unclear, the decision should be delayed. For SMEs, that discipline helps prevent a useful tool from becoming a durable risk.