August 2026. The EU AI Act classifies high-risk AI systems (HR, credit, critical infrastructure). SMEs with AI in product or internal processes must demonstrate conformity, logging and human oversight — separate from ISO 27001.
High-risk checklist
- Classification: does your system fall under high-risk annex?
- Risk management: bias, data quality, security, chain;
- Technical documentation: architecture, training data, limits;
- Human oversight: who can intervene, when?
- Post-market monitoring: incidents, updates, complaints.
Link to ISO 42001, GDPR and ISMS. AI Act and GDPR overlap on personal data — one register.
In 2026 customers ask AI Act status alongside security certs. Record classification and roadmap in management review.
