Ga naar inhoud

AI governance ·

AI Act high-risk: checklist for SMEs with AI applications

August 2026. The EU AI Act classifies high-risk AI systems (HR, credit, critical infrastructure). SMEs with AI in product or internal processes must demonstrate conformity, logging and human oversight — separate from ISO 27001.

High-risk checklist

  1. Classification: does your system fall under high-risk annex?
  2. Risk management: bias, data quality, security, chain;
  3. Technical documentation: architecture, training data, limits;
  4. Human oversight: who can intervene, when?
  5. Post-market monitoring: incidents, updates, complaints.

Link to ISO 42001, GDPR and ISMS. AI Act and GDPR overlap on personal data — one register.

In 2026 customers ask AI Act status alongside security certs. Record classification and roadmap in management review.

Deep dive in the knowledge base

Plan an AI governance intake

Connect ISO 42001 and the AI Act to your existing governance.

Plan intake

← Back to overview