EU AI Act for SMEs:
Compliant in 5 Steps.
The EU AI Act is in force. Prohibited practices effective February 2025. High-risk compliance by August 2026. This guide shows the way — clear, free, OCC.
Step 1: Classify: What Applies to Me?
Create an AI inventory. Check each system against EU AI Act Annex III. Rule out prohibited practices (Art. 5). The OCC assistant helps with classification.
- Create AI inventory (all AI systems in your organization)
- Check each system against Annex III
- Exclude prohibited practices (Art. 5)
Step 2: Assess: Risk Assessment
Apply NIST AI RMF MAP function. Establish risk tier: minimal / limited / high. Document impact assessment (Art. 9). OCC provides the framework free of charge.
- Apply NIST AI RMF MAP function
- Establish risk tier
- Document impact assessment (Art. 9)
Step 3: Act: High-Risk Systems
For high-risk AI: Risk Management System (Art. 9), Data Governance (Art. 10), Technical Documentation (Art. 11), Human Oversight (Art. 14). OCC explains every term in 4 reading levels.
- Build Risk Management System
- Document Data Governance
- Implement Human Oversight (Art. 14)
- Technical Documentation (Art. 11)
Step 4: Prove: Conformity Assessment
For high-risk systems: conduct conformity assessment (Art. 43), CE marking, EU database registration. For simpler systems: self-declaration.
- Choose conformity assessment procedure (Art. 43)
- Prepare CE marking
- Check EU database registration
Step 5: Ongoing: OCC as Companion
OCC updates with new EU AI Act delegated regulations, ISO 42001 revisions, NIST updates. No subscription, no login — always free.
- Bookmark OCC Glossary
- Use OCC assistant for ad-hoc questions
- Check Source Registry for new standards
Specific questions? Ask the OCC assistant.
The OCC assistant answers compliance questions grounded in EU AI Act, ISO 42001, GDPR. Anonymous, no login, EU-hosted.
Open AI assistant →