EU AI Act Compliance Checklist for SMBs (2026-2028): Build Procurement-Ready AI Governance
The EU AI Act is neither dead nor one single August 2026 deadline. It is applying in stages. For B2B SaaS teams, the practical job is to know where AI is used, record why each use is classified the way it is, close the duties already in force, and make the evidence reviewable by customers.
Staged application
The timeline that matters now
The Commission describes a staged framework. The dates below separate duties already applying from the next transparency and high-risk milestones.
1 Aug 2024
AI Act entered into force
The regulation became EU law, with obligations applying in stages.
2 Feb 2025
Prohibited practices and AI literacy
Article 5 prohibitions and Article 4 AI literacy duties started applying.
2 Aug 2025
GPAI model obligations
Governance rules and obligations for providers of general-purpose AI models started applying.
2 Aug 2026
Article 50 and GPAI enforcement
Article 50 transparency duties apply, and the Commission's GPAI enforcement powers start.
2 Dec 2027
Stand-alone high-risk rules
Application date adopted in the AI Omnibus for specified stand-alone high-risk systems.
2 Aug 2028
Product-embedded high-risk rules
Application date adopted for high-risk AI embedded in regulated products.
The operating model
Six records that make readiness visible
Inventory
Know every AI use and owner
Classify
Record role, risk and rationale
Live controls
Check prohibitions and literacy
Vendors
Collect upstream evidence
Proof pack
Answer customer reviews
Roadmap
Prepare for 2026-2028
Step 1
Build an owned AI inventory
Start with systems, features and workflows, not a list of vendor logos. The same model can support a low-impact drafting feature and a materially different recruitment workflow. Record the actual intended use and how the system is used in practice.
- System name, business owner, technical owner and vendor
- Intended purpose, actual use and the decision or content it influences
- People affected, including employees, applicants, customers and children
- Inputs and data categories, output destination and human review
- Model or service version, integrations and material vendor dependencies
- Countries of use, lifecycle status and next review date
Step 2
Classify the system, your role and the evidence
Do not stop at a risk label. A useful classification record shows what facts were assessed and what would trigger a reassessment. At minimum, work through four separate questions:
- 1
Scope
Does the software and its actual use meet the AI-system definition and territorial scope?
- 2
Role
Are you acting as provider, deployer, importer or distributor for this system?
- 3
Risk
Is the use prohibited, potentially high-risk, subject to a transparency duty, or minimal/no-risk under the Act?
- 4
GPAI
Are you actually a provider of a general-purpose AI model, or are you using a third-party model inside an AI system?
The Commission's GPAI guidance says those obligations apply to GPAI model providers and explains when a modification may be significant enough to change that position. Do not automatically copy foundation-model-provider obligations onto every SaaS product that calls a model API.
Create a first-pass classificationStep 3
Close the duties that already apply
Prohibited-practice screen
Screen every use against Article 5, document the facts and decision, and block disallowed configurations or workflows. Re-run the screen when the purpose, affected group, data or functionality changes.
AI literacy measures
Match guidance or training to the people who operate, procure, build and oversee AI. Keep the audience, content, completion date and refresh trigger. A generic annual slide deck is not the only possible measure, and the Act does not prescribe one universal course.
Step 4
Collect vendor evidence before the security review
When a B2B SaaS product depends on upstream models or AI-enabled tools, put the evidence behind those dependencies in one place before a buyer asks for it.
Missing evidence is itself useful information. Record the request, owner, response and compensating control instead of marking an unsupported checkbox complete.
Step 5
Assemble a customer proof pack
Procurement teams need a concise, reviewable answer, not your full internal governance archive. Create a customer-facing pack that explains the relevant product use and links to controlled evidence. Keep internal incident detail, privileged advice and unrelated systems out of the default export.
| Artifact | What it demonstrates | Question it answers |
|---|---|---|
| AI system register | Shows scope, ownership, use cases and dependencies | Which AI systems touch our data or users? |
| Classification record | Preserves role, risk outcome, rationale and review date | How did you assess this use under the AI Act? |
| Prohibited-use check | Records the Article 5 screen and any restrictions | How do you prevent unacceptable uses? |
| AI literacy record | Links relevant training or guidance to roles and AI uses | Are staff equipped to operate and oversee the system? |
| Vendor evidence file | Keeps instructions, limitations, terms and change notices | What do you rely on from model and tool providers? |
| Transparency record | Maps notices, labels and technical marking to each use | When and how do you tell people AI is involved? |
| Change and incident log | Makes reviews repeatable when systems or use cases change | How do you keep the assessment current? |
Label drafts, owners, approval dates and evidence gaps. Do not call a pack "certified," "audit-ready" or "compliant" unless you have a defensible basis for that specific claim.
Step 6
Prepare for Article 50 transparency
Article 50 transparency obligations apply from 2 August 2026. The exact control depends on whether you are the provider or deployer, the kind of content involved and how it is used. Build a use-case matrix instead of adding the same disclosure to every AI feature.
| Scenario to assess | Readiness action | Likely owner |
|---|---|---|
| People interact directly with an AI system | Assess whether a clear AI interaction notice is required and whether an exception applies. | Product / UX |
| A provider generates or manipulates audio, image, video or text | Prepare machine-readable marking and detection measures that meet the Article 50 standard. | Engineering |
| A deployer publishes a deepfake | Prepare a clear disclosure that the content was artificially generated or manipulated. | Content / Legal |
| A deployer publishes AI text on a matter of public interest | Assess the disclosure duty and the human-review/editorial-responsibility exception. | Editorial |
Step 7
Build the high-risk roadmap without pretending it is due today
If a use may fall into a high-risk area, preserve the classification rationale now and build a dated gap plan. The Commission lists the following areas among the high-risk use cases:
Use the runway to assign ownership, confirm provider/deployer responsibilities, collect instructions and logs, test human oversight, map data governance, and identify which technical or legal evidence is still missing. Track the Official Journal text, standards and Commission guidance as they develop.
90-day execution plan
Turn the checklist into a procurement asset
Days 1-30
Establish the baseline
Name the owner, inventory systems, map roles, screen prohibited uses and record literacy measures.
Days 31-60
Close evidence gaps
Request vendor evidence, validate classifications, map Article 50 scenarios and assign controls.
Days 61-90
Test the proof
Build the customer pack, run a mock procurement review and publish the high-risk roadmap.
Primary sources
Verify against the current text
This article uses Commission and Council materials available on 11 July 2026. Re-check them when a system changes and before making a legal or contractual representation.
- European Commission: AI Act framework and application timeline
- Council of the EU: final green light for the Digital Omnibus on AI
- Official AI Act text: Regulation (EU) 2024/1689
- European Commission: GPAI provider guidelines
- European Commission: GPAI Code of Practice
- European Commission: Article 50 transparency Code of Practice
Konformis
Build evidence customers can review
Structure your AI inventory, preserve classification rationale, track controls and export a customer-facing proof pack. Konformis supports the workflow; it does not provide legal advice or certify compliance.