More AI Act checklists have appeared this year than businesses that have done anything with them. That's a shame, because the essence fits on a beer mat and most of the work is an afternoon. Since 2 August 2026 the main obligations of the European AI Act apply, and they apply to virtually every business that uses AI — no exception for size, no transition period any more. Below: what you need to have on file demonstrably, what can wait a while, and where it goes wrong in practice.
Who does it apply to?
To you, probably. The regulation doesn't look at what kind of business you are but at what you do with AI. A chatbot on your website counts. Having text or images generated counts. A tool that sorts CVs or drafts quotes counts. Even an employee who signed up for a subscription on their own counts, because it happens within your organisation and under your responsibility.
For small businesses, lighter requirements and lower maximum fines apply on some points. That's a softening, not an exemption.
What you must be able to demonstrate
An overview of your AI tools
A list of every AI application running within your business: name, what it's for, who the provider is, what risk level it has and what data goes into it. A spreadsheet will do. The difficulty isn't in the format but in the completeness — nearly every business comes across tools during this inventory that management didn't know were in use.
Policy: who may do what
An internal document setting out how your organisation deals with AI. Who may use which tools, what data may and may not go into them, how you check the output before it goes out. Two pages that are right are worth more than twenty pulled off the internet.
Demonstrable AI literacy
Employees who work with AI must know what the risks are, and you have to be able to show it. An e-learning, a meeting record, an internal certificate — the proof can be light. For most small businesses an hour-and-a-half session with a short test is defensible.
Transparency towards customers
If someone is talking to a chatbot, it must be clear it isn't a person. If a text or image is made by AI, that should be recognisable. One line at the opening of the chat window or a short note on generated content usually covers this.
What isn't required yet
The heavier requirements for high-risk applications — recruitment and selection, lending, education, critical infrastructure — have shifted to 2 December 2027. If you fall into that category, you still have well over a year for conformity assessments, technical documentation and human oversight. If you don't, you don't have to do anything about that whole chapter. That saves considerably more than the average checklist suggests.
The Netherlands is also working on an AI sandbox: an environment where you can experiment without immediately risking sanctions. Interesting if you want to build something whose classification you're not yet sure of.
Where it breaks down in practice
The register is a snapshot
A list that was right in August isn't right any more in November. A tool gets added, someone tries something, a supplier builds AI into a package you already had. Without a fixed moment to update the register, it's fiction after six months. Put a recurring appointment on it — that's the whole solution.
The training is a tick-box
An hour and a half of general explanation about what a language model is clears the bar but changes nothing about how people work. Explanation about your own processes, with your own documents and your own mistakes, costs the same and actually delivers something.
Nobody looks at the supplier
You're responsible for what happens within your organisation, even when the AI sits in someone else's package. Ask your suppliers whether they comply with the regulation themselves and where the processing takes place. A supplier who's vague about that is the risk itself.
It stays on paper
Register done, policy done, training had — and after that nothing changes about how people work. Then you have a file for a regulator who probably never shows up, and nothing else. The obligations are the trigger; the gain is in what you set up afterwards.
And the fines?
They run up to amounts that are painful for a small business, with lower maximums for smaller organisations. But enforcement is only getting going and the chance of someone on your doorstep tomorrow is small. That's no reason to let it slide — the real risks are elsewhere. An employee pasting customer data into a free tool, a chatbot promising something you can't deliver, a generated text with an error in it going out under your name. You don't need a regulator to feel the pain of those.
Where do you start?
With the inventory, always. You can't write policy about tools you don't know are running. Ask around, look in the invoices, check the browser extensions. What comes out of that determines whether you have an afternoon's work or a project — and in most cases it's an afternoon.
Then policy, then the session with your team, then the transparency on your site. Four steps, half a day per step. And if it does turn out to be bigger: then you know that now, instead of at the moment someone asks about it.