If you are a UK SME with customers or operations in the EU, or AI outputs that reach EU residents, the Act applies with extraterritorial reach: the same logic as GDPR. You do not need to be headquartered in Brussels to be in scope.
This checklist is a practical readiness pass for businesses up to £20M revenue that are already using AI (ChatGPT, Copilot, Claude, hiring tools, chatbots) but do not have a CISO or dedicated governance team.
Not legal advice. Use this to structure a conversation with qualified counsel and to decide what evidence you need before August.
Step 1: Inventory every AI use case (not every tool)
A spreadsheet of SaaS subscriptions is not governance. For each use case, capture:
- What decision or workflow it affects
- Who owns it (business + technical)
- What data classes it touches
- Whether a human reviews output before action
If you cannot list ten use cases in thirty minutes, adoption width has outrun visibility. That is the primary risk.
See also: Compliance & governance focus
Step 2: Classify risk tier per use case
Map each use case to the EU AI Act risk framework:
| Tier | Examples for SMEs |
|---|---|
| Prohibited | Social scoring, manipulative practices: stop and get advice |
| High-risk | Hiring/screening, credit, essential services: full documentation path |
| Limited | Chatbots, emotion recognition (where permitted): transparency duties |
| Minimal | Internal spam filters, simple automation: lighter touch |
Recruitment agencies and professional services firms often discover high-risk uses they treated as "just ChatGPT."
Step 3: Check transparency obligations (August 2026)
For limited-risk systems (many customer-facing chatbots), deployers must ensure users know they are interacting with AI. That is operational: website copy, call scripts, email footers, not a legal memo in a drawer.
Step 4: GDPR overlap: do not silo
Almost every AI use case touching personal data needs a UK GDPR lens:
- Lawful basis documented
- DPIA where high risk to individuals
- Data processing agreements with vendors
- Retention and deletion paths
ISO 42001 and commercial "AI quality marks" can help structure your programme, but they are not substitutes for EU AI Act conformity on their own.
Step 5: Evidence pack minimum
Before August, aim to hold:
- AI use-case register with owners and review dates
- Risk classification memo per material use case
- Human oversight record: who signs off what
- Vendor due diligence for third-party AI tools
- Incident / escalation path if AI output causes harm
Competitors sell scoping reviews for around £500 and sprints from £2,500–£10,000. The economics favour fixing governance before retrofit pressure; retrofit commonly runs 3–5× the cost of design-in.
Step 6: Decide your path
| Situation | Sensible next step |
|---|---|
| Few tools, low risk | Register + quarterly review |
| Active AI in hiring, credit, or customer decisions | Readiness sprint + legal review |
| Board asking before August | Fixed-price sprint with 30-day action plan |
| Ongoing shadow AI growth | Monthly governance monitoring |
For software delivery under real operational constraints, Localhost Ltd runs Build, Managed Service, and Rescue engagements. For a practical readiness pass, keep this checklist and take the evidence pack to qualified counsel.
