If you need to screen high-risk AI systems under the AI Act, the real buying question is not just “does this tool look useful?” but “what evidence shows that stricter obligations may apply, and should we proceed, pause, or reject?”. This article is for SME leaders, procurement, HR, IT, and compliance teams evaluating AI-enabled software or embedded AI features. The practical outcome is a documented buying decision, a vendor scorecard, and a short list of clauses or evidence to request before moving forward. The EU AI Act creates duties that depend on the system’s role, context, and use case, so the earliest value comes from recognizing when a pilot is no longer a routine purchase. For the legal frame, see the EU AI Act and the Commission’s European Commission AI Act overview.

Buying decision: what the SME should get

The goal is not certainty; it is a decision that is defensible enough to buy, hold, or reject. The owner is the business sponsor, with IT and legal as reviewers. Evidence to inspect: written use case, the system’s role in the workflow, data sources, human override points, logging, and escalation paths. Decision threshold: if the vendor cannot explain whether the system recommends, filters, ranks, or decides, the project should move to a stricter review. That matters because some uses may trigger tighter obligations under the AI Act, especially where outcomes affect access, selection, or rights. For the operational compliance lens, see CNIL AI guidance, which stresses careful handling of data, purpose, and people affected.

Evidence to request before you move on

The procurement owner should ask for evidence before negotiating on price or features. Request a system description, intended purpose, model or service limits, logging and incident handling, human oversight controls, update process, and any available testing or validation summary. If the answer is marketing language rather than auditable material, pause the pilot. The question is not “does the vendor say it is compliant?” but “what can we verify ourselves?”. For a contextual landing point and service detail, use AI AUDIT EN and AI AUDIT blog EN. If the discussion touches recruitment or HR, this related page may help shape the evidence pack: AI audit for HR and recruitment.

Vendor scorecard: a reusable decision asset

Use the vendor scorecard as a procurement scorecard, not a marketing score. The procurement owner fills it in; compliance or risk reviews the result. Score each item 0 to 2: 0 = missing, 1 = partial, 2 = clear and verifiable. Here is a compact template:

Criterion Evidence to inspect Threshold / next action
Intended use Written use case If ambiguous, stop review
Decision role Recommend, rank, filter, decide If automated decision-making is unclear, escalate
Data inputs Source, type, sensitivity If sensitive data is unexplained, pause
Human oversight Override and review process If no human backstop, reject provisionally
Logging and incidents Logs, alerts, remediation If no traceability, limit to pilot
Maintenance and updates Versioning, patch cadence If unknown, request annexes

Practical threshold: if two non-negotiable lines score 0, the answer is “not ready to buy.” If at least four lines score 2 and the human role is clear, the project can move to a controlled pilot.

Five-step process for screening a higher-risk buying case

  1. Define the exact use. Write down the use case, who will use it, who is affected, and when the system acts.
  2. Map the AI role. State whether the system suggests, ranks, filters, prioritizes, or decides.
  3. Verify vendor evidence. Request the documents above and keep the responses in the procurement file.
  4. Test human oversight. Check who can correct, suspend, challenge, or override an output.
  5. Decide the review level. Classify the case as standard purchase, controlled pilot, stricter review, or provisional rejection.

This sequence helps teams avoid confusing a useful feature with a use case that needs tighter control. It also makes it easier to spot when AI Act obligations may become more demanding depending on the nature of the processing and the operational context. If any step remains unclear after step 3, do not speed up to signature; ask for a written clarification before moving on.

Rejection signals: when caution should win

The business sponsor should reject or freeze the purchase when the vendor avoids evidence, confuses product claims with compliance, or refuses to explain who can review and change outputs. Another warning sign is a system described as “assistive” while it actually filters, ranks, or excludes people without a clear appeal path. In that case, the risk is organizational as much as technical. If the use case sits close to a high-scrutiny area under the AI Act, do not negotiate on price first; move to an AI readiness assessment or a fuller AI audit for SMEs that checks data, workflow, and oversight. For the official legal sources, see EU AI Act and European Commission AI Act overview.

Clearly labeled hypothetical example

Hypothetical example: a service SME is considering an AI tool to screen job applications before interviews. The vendor provides a demo, but the documentation does not clearly say whether the system only sorts CVs or also automatically rejects some profiles. The scorecard shows 2 for intended use and logs, 1 for data inputs, and 0 for human oversight because no manager can explain how to reverse a rejection. In that case, the sensible decision is not to buy immediately; the team should request the appeal mechanism, confirm the system’s exact role, and resume only with verifiable evidence. This example does not create a general legal conclusion, but it shows how an SME can use the scorecard to avoid mistaking a pre-screening tool for a decision that would require tighter control.

Next step: measure value after 30 days

Value should be measured after 30 days using three signals: time saved, human corrections made, and incidents handled. If the system speeds work but creates extra checking without improving quality, its net value may be weak. Decision threshold: if the pilot cannot show a clear record of corrections, error avoidance, and escalations, it is not ready for broader deployment. For a helpful next step, see AI AUDIT EN or use the contextual checkout page here: payment EN. For adjacent HR use cases, review AI audit for HR and recruitment.

Which evidence should be checked before deciding?

Check the intended use, automation level, logs, human oversight, and incident handling. If two of these are missing, the purchase decision should be paused.

What indicates stricter obligations may apply?

The key signal is the system’s role in a sensitive decision. If it ranks, filters, or influences access without a clear explanation or appeal path, the review should be stronger.

How should value be measured after 30 days?

Compare time saved, human corrections, and incidents handled. If oversight work rises without a clear benefit, narrow the scope or stop the pilot.