Notes
EU AI Act compliance and AI tooling at SME scale
Two things happened at once. Your product acquired a feature that calls a third-party model, because a customer asked and it took a fortnight. And the regulatory picture around that feature changed twice while nobody in the company was watching.
These notes are about eu ai act compliance for a company with no legal department, where the person who has to work out what applies is the same person who shipped the feature.
What eu ai act compliance actually requires of a small SaaS company
Less than the coverage suggests, and sooner than most people think.
The obligations that bite for a typical B2B SaaS product are transparency and literacy, and both are already in force. The high-risk regime that generated most of the anxiety has been deferred, and for most products it never applied in the first place.
That inversion is the single most useful thing to understand. Companies spent 2025 preparing for the wrong deadline.
Not legal advice
These notes describe how to approach the problem operationally. They cite official sources and they are not a substitute for advice on your specific product, particularly if you operate in a sector where a use case could fall into the high-risk categories.
Where a date or an obligation matters commercially, read the regulation itself or take advice. The timeline has already moved once and the mechanism by which it moved, a simplification regulation amending the original, means it can move again.
The part that is just information security
The reassuring finding, once you get into it, is how much of the compliance burden is work you have already done or should be doing anyway.
An inventory of AI systems is an asset register with different columns. The supplier assessment for a model provider is a supplier assessment. Documenting what data goes to which provider is a data flow record. Change control over a feature that calls a model is change management.
If you hold ISO 27001, a substantial part of the evidence already exists and needs re-labelling rather than creating. If you do not, the AI Act work is a reasonable first step toward it.
The timeline moved, which is the lesson
The high-risk obligations everybody prepared for were deferred by more than a year, by a regulation amending the original regulation, months before they were due to apply. Meanwhile the transparency duties that do affect ordinary software came into force on schedule and with far less coverage.
Two things follow for a small company. Do not build a compliance programme around a date, because the date is a moving target and the mechanism for moving it now exists and has been used. And do not assume the loudest obligation is yours, because the high-risk regime was never going to apply to most B2B software and a great deal of effort went into preparing for it anyway.
What survives a timeline change is the inventory. Knowing which of your features use AI, which provider sits behind each, what data reaches them and why, is useful under any version of the rules and is the first thing a customer asks for. Build that, and the classification exercise becomes an afternoon whenever the rules settle.
Reading order
The Act note first, because it establishes what applies and when. The inventory note second, because it is the artefact everything else depends on and it is the thing a customer will eventually ask to see.
The third note is unrelated to regulation: it is about using AI tools yourself when you are the entire security function, where they help and where they produce confident nonsense about your own environment.