All articles
2026 updateUpdated 22 July 202612 min read

EU AI Act Compliance Checklist for SMBs (2026-2028): Build Procurement-Ready AI Governance

The EU AI Act is neither dead nor one single August 2026 deadline. It is applying in stages. For B2B SaaS teams, the practical job is to know where AI is used, record why each use is classified the way it is, close the duties already in force, and make the evidence reviewable by customers.

Scope note: This is an operational readiness guide, not legal advice. A customer proof pack is useful procurement evidence; it is not a document named or universally required by the AI Act. Confirm obligations for each system, role and use case.

Staged application

The timeline that matters now

The Commission describes a staged framework. The dates below separate duties already applying from the next transparency and high-risk milestones.

1 Aug 2024

AI Act entered into force

The regulation became EU law, with obligations applying in stages.

In force

2 Feb 2025

Prohibited practices and AI literacy

Article 5 prohibitions and Article 4 AI literacy duties started applying.

Applies now

2 Aug 2025

GPAI model obligations

Governance rules and obligations for providers of general-purpose AI models started applying.

Applies now

2 Aug 2026

Article 50 and GPAI enforcement

Article 50 transparency duties apply, and the Commission's GPAI enforcement powers start.

2026 milestone

2 Dec 2027

Stand-alone high-risk rules

Application date adopted in the AI Omnibus for specified stand-alone high-risk systems.

Omnibus date

2 Aug 2028

Product-embedded high-risk rules

Application date adopted for high-risk AI embedded in regulated products.

Omnibus date
AI Omnibus status at 11 July 2026: adopted; Official Journal entry into force not assumed. The Council gave its final green light on 29 June and adopted the 2 December 2027 and 2 August 2028 application dates. Its notice identified Official Journal publication as the next step and said the act would enter into force on the third day after publication. Because the cited materials do not provide the final L-series citation, verify that text before relying on an amended date. Read the Council adoption notice.

The operating model

Six records that make readiness visible

Inventory

Know every AI use and owner

Classify

Record role, risk and rationale

Live controls

Check prohibitions and literacy

Vendors

Collect upstream evidence

Proof pack

Answer customer reviews

Roadmap

Prepare for 2026-2028

Step 1

Build an owned AI inventory

Start with systems, features and workflows, not a list of vendor logos. The same model can support a low-impact drafting feature and a materially different recruitment workflow. Record the actual intended use and how the system is used in practice.

  • System name, business owner, technical owner and vendor
  • Intended purpose, actual use and the decision or content it influences
  • People affected, including employees, applicants, customers and children
  • Inputs and data categories, output destination and human review
  • Model or service version, integrations and material vendor dependencies
  • Countries of use, lifecycle status and next review date
Output: one accountable record per AI system or materially distinct use case. Include embedded AI in support, CRM, HR, analytics, security, coding and content tools where it meets the AI-system definition.

Step 2

Classify the system, your role and the evidence

Do not stop at a risk label. A useful classification record shows what facts were assessed and what would trigger a reassessment. At minimum, work through four separate questions:

  1. 1

    Scope

    Does the software and its actual use meet the AI-system definition and territorial scope?

  2. 2

    Role

    Are you acting as provider, deployer, importer or distributor for this system?

  3. 3

    Risk

    Is the use prohibited, potentially high-risk, subject to a transparency duty, or minimal/no-risk under the Act?

  4. 4

    GPAI

    Are you actually a provider of a general-purpose AI model, or are you using a third-party model inside an AI system?

The Commission's GPAI guidance says those obligations apply to GPAI model providers and explains when a modification may be significant enough to change that position. Do not automatically copy foundation-model-provider obligations onto every SaaS product that calls a model API.

Create a first-pass classification

Step 3

Close the duties that already apply

Prohibited-practice screen

Screen every use against Article 5, document the facts and decision, and block disallowed configurations or workflows. Re-run the screen when the purpose, affected group, data or functionality changes.

AI literacy measures

Match guidance or training to the people who operate, procure, build and oversee AI. Keep the audience, content, completion date and refresh trigger. A generic annual slide deck is not the only possible measure, and the Act does not prescribe one universal course.

These duties have applied since 2 February 2025. A later high-risk application date is not a reason to defer them.

Step 4

Collect vendor evidence before the security review

When a B2B SaaS product depends on upstream models or AI-enabled tools, put the evidence behind those dependencies in one place before a buyer asks for it.

Intended-purpose documentation and provider instructions
Known limitations, prohibited uses and human-oversight guidance
Model or feature version and material change notices
Data-use, retention, subprocessor and geographic information
Security documentation and incident-notification route
Contractual allocation of responsibilities and evidence gaps

Missing evidence is itself useful information. Record the request, owner, response and compensating control instead of marking an unsupported checkbox complete.

Step 5

Assemble a customer proof pack

Procurement teams need a concise, reviewable answer, not your full internal governance archive. Create a customer-facing pack that explains the relevant product use and links to controlled evidence. Keep internal incident detail, privileged advice and unrelated systems out of the default export.

ArtifactWhat it demonstratesQuestion it answers
AI system registerShows scope, ownership, use cases and dependenciesWhich AI systems touch our data or users?
Classification recordPreserves role, risk outcome, rationale and review dateHow did you assess this use under the AI Act?
Prohibited-use checkRecords the Article 5 screen and any restrictionsHow do you prevent unacceptable uses?
AI literacy recordLinks relevant training or guidance to roles and AI usesAre staff equipped to operate and oversee the system?
Vendor evidence fileKeeps instructions, limitations, terms and change noticesWhat do you rely on from model and tool providers?
Transparency recordMaps notices, labels and technical marking to each useWhen and how do you tell people AI is involved?
Change and incident logMakes reviews repeatable when systems or use cases changeHow do you keep the assessment current?

Label drafts, owners, approval dates and evidence gaps. Do not call a pack "certified," "audit-ready" or "compliant" unless you have a defensible basis for that specific claim.

Step 6

Prepare for Article 50 transparency

Article 50 transparency obligations apply from 2 August 2026. The exact control depends on whether you are the provider or deployer, the kind of content involved and how it is used. Build a use-case matrix instead of adding the same disclosure to every AI feature.

Scenario to assessReadiness actionLikely owner
People interact directly with an AI systemAssess whether a clear AI interaction notice is required and whether an exception applies.Product / UX
A provider generates or manipulates audio, image, video or textPrepare machine-readable marking and detection measures that meet the Article 50 standard.Engineering
A deployer publishes a deepfakePrepare a clear disclosure that the content was artificially generated or manipulated.Content / Legal
A deployer publishes AI text on a matter of public interestAssess the disclosure duty and the human-review/editorial-responsibility exception.Editorial
The Commission's Article 50 Code of Practice is a voluntary way to support compliance with marking and labelling duties; the legal obligations come from the Act. Record which route you follow, technical test results, the final notice or label, and who approved it.

Step 7

Build the high-risk roadmap without pretending it is due today

If a use may fall into a high-risk area, preserve the classification rationale now and build a dated gap plan. The Commission lists the following areas among the high-risk use cases:

Biometrics
Critical infrastructure
Education and vocational training
Employment and worker management
Access to essential services
Law enforcement
Migration, asylum and border control
Administration of justice and democratic processes

Use the runway to assign ownership, confirm provider/deployer responsibilities, collect instructions and logs, test human oversight, map data governance, and identify which technical or legal evidence is still missing. Track the Official Journal text, standards and Commission guidance as they develop.

90-day execution plan

Turn the checklist into a procurement asset

Days 1-30

Establish the baseline

Name the owner, inventory systems, map roles, screen prohibited uses and record literacy measures.

Days 31-60

Close evidence gaps

Request vendor evidence, validate classifications, map Article 50 scenarios and assign controls.

Days 61-90

Test the proof

Build the customer pack, run a mock procurement review and publish the high-risk roadmap.

Primary sources

Verify against the current text

This article uses Commission and Council materials available on 11 July 2026. Re-check them when a system changes and before making a legal or contractual representation.

Konformis

Build evidence customers can review

Structure your AI inventory, preserve classification rationale, track controls and export a customer-facing proof pack. Konformis supports the workflow; it does not provide legal advice or certify compliance.