Blog
Practical guides, real-world feedback and best practices to accelerate your digital transformation.
Our experts share real-world insights: generative AI integration, business process automation and no-code development. Every article is designed to give you actionable takeaways, tailored to SMBs and mid-market companies.
Blog
Stay up to date with our latest news and practical advice.
A conformity assessment under the AI Act is a formal procedure set out in Article 43, and it only applies to providers of high-risk AI systems. If your company uses ChatGPT, Copilot or a CRM with an AI feature bolted on, you are almost certainly outside its scope. What you do need to run is a compliance self-assessment: establish your role, classify your systems, document your decisions.
Mapping your AI systems means listing, in a single table, every artificial intelligence tool in use across the company, with its vendor, its purpose, the data it processes and the person accountable for it. In a company of 30 to 100 employees, that work takes half a day to two days, not six weeks.
An AI policy is the internal document that sets out what your teams may do with artificial intelligence: which tools are approved, which data may go into them, who checks what before anything goes out. You will find a complete template below, published in full, ready to copy and adapt. No form, no email required.
An AI information notice is the public document explaining how your AI systems process personal data. It answers the GDPR, not Article 50 of the AI Act, which requires disclosure at the moment of interaction. You need both.
The AI Act and the GDPR do not address the same thing: the GDPR protects personal data, while the AI Act governs artificial intelligence systems. Both apply at the same time as soon as your AI touches customer, employee or prospect data. For an SME, the real question is not which one to follow, but how to fit both into a single compliance effort.
AI Act sanctions can reach 35 million euros or 7 % of worldwide annual turnover for the most serious breaches. But for a small business the rule flips: the fine is capped at the lower of the fixed amount and the percentage, not the higher one. In practice, a compliant small organisation risks almost nothing, and a negligent one is mostly exposed to the middle tier of 15 million euros or 3 %.
A high-risk AI system is one that Article 6 of Regulation EU 2024/1689 places under the AI Act's heaviest obligations. It opens two classification routes: Annex I products and Annex III use cases, whose obligations apply from 2 December 2027.
Since 2 February 2025, eight uses of artificial intelligence have been outright banned across the European Union. Article 5 of Regulation EU 2024/1689 classifies them as unacceptable risk: there is no compliance path, only stopping the use. Here is the exact list and what it means in practice for a small business or a nonprofit.
Since 27 July 2026, Article 4 of the AI Act no longer requires companies to reach a specific level of AI literacy. The Digital Omnibus replaced that binding obligation with simple encouragement. Training your teams is still strongly advised, and it remains required for high-risk uses. Here is what changed, what remains, and what you should actually do.
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Complete no-code guide 2025/2026: tools, techniques, best practices. Learn to build applications without coding with GrowthPerf.