Which EU AI Act obligations apply to an SME as a deployer?
Short answer
A quick answer first, then the fuller context below.
Which EU AI Act obligations apply to an SME as a deployer depends on the role, use case and risk level, but support schemes do not remove the duty to comply. Start with role mapping, usage records, human oversight and supplier evidence.
What this points to
This usually points to AI governance consulting
If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.
Detailed answer
The fuller context, trade-offs and practical steps behind the short answer.
Frequently asked questions
Direct follow-up answers written for searchers, buyers and internal decision makers.
Does an SME avoid EU AI Act duties by buying a third-party tool?
No. A supplier may carry provider obligations, but the SME can still have deployer duties for how the tool is used in its own workflow.
What is the first document an SME should create?
Create an AI use-case register that records the owner, supplier, purpose, data, risk level, oversight step and review date for each material AI system.
Do support schemes and sandboxes remove the need to comply?
No. They can help SMEs interpret and implement the rules, but they do not remove accountability for safe and lawful deployment.
Which teams should own this work?
Ownership should sit with the process owner, supported by compliance, data protection, security and senior management where the risk is material.
Need help implementing this?
If this question points to a live process, policy or supplier decision, the next step is usually to turn the answer into a controlled plan. These services are the most relevant starting points.
AI governance consulting
Create policies, approval routes, ownership and controls that teams can actually use day to day.
AI governance consultingSecure AI implementation
Put privacy, supplier review, data boundaries, testing and staff guidance into the implementation plan from the start.
secure AI implementationAI Risk & Efficiency Audit
Map real workflows, AI use, data exposure, opportunity value and governance controls before buying or building more tools.
book the AI Risk & Efficiency Audit