Skip to content

How to comply with the AI Act without a consultant

Most SMBs' first reaction on learning about their AI Act obligations is to look for a consultant. It's a valid option — but not the only one, and in most cases not even the most efficient. Here's what's actually needed, task by task.

What an AI compliance consultant actually does

Before deciding whether you need one, it's worth unpacking what you're actually buying with that service. In most AI compliance projects for SMBs, the work comes down to five tasks: inventorying the AI systems the company uses, classifying them by AI Act risk level, producing the technical documentation each level requires, defining the human oversight procedure, and training the team on the usage policy.

None of those five tasks require a professional license or knowledge you can't acquire with a clear methodology. What you're really buying when you hire a consultant is time (someone else does it for you) and prior experience (they've done it before and know the common mistakes). If you have the time and a proven methodology, you can replace both.

What you can do yourself, task by task

Task What it requires What to use to do it yourself
Inventory AI systems List every system, vendor, use case and data it processes AI Systems Register Template
Classify risk Determine whether each system is banned, high-risk, limited-risk or minimal-risk AI Act Risk Classification Checklist
Technical documentation (Annex IV) Draft the documentation required for high-risk systems Technical Documentation Template
Human oversight Define who reviews the system's decisions and when they step in Human Oversight Procedure
Internal usage policy Clear rules for the team on what AI can be used and how AI Acceptable Use Policy
Train the team Make sure the people using or overseeing AI understand their obligations AI Literacy Training Deck

Notice each task has a concrete, verifiable artifact as its output — not "doing it right" in the abstract, but a document you can show in an audit. That's the difference between "trying to comply" and actually complying: the result can be shown.

Where outside help is still worth it (honestly)

Being self-sufficient on compliance doesn't mean doing everything without exception. There are three situations where hiring outside help still makes sense:

  • High-risk systems requiring third-party conformity assessment by law — some Annex III systems (medical devices, critical infrastructure) require notified bodies; that's not a discretionary decision.
  • Additional sector-specific regulation — banking, healthcare or the public sector usually have their own regulatory layers that overlap with the AI Act, where the margin for error is smaller.
  • Volume beyond your internal capacity — if you have 15+ AI systems across departments and no one coordinating them, the problem is no longer knowledge but capacity, and that's where dedicated help — internal or external — can pay off.

Outside those three cases, most SMBs with 1 to 5 limited- or minimal-risk AI systems can complete basic compliance on their own with a clear methodology and the right templates.

A 90-day plan to do it yourself

This is the order we recommend, based on the MVG Methodology (Minimum Viable Governance) used across the rest of the site:

Days 1–20: Inventory and classification

List every AI system your company uses — including third-party tools like ChatGPT or Copilot the team already uses without anyone formally approving it — and classify each by risk level. This step alone usually surfaces "shadow AI" systems no one had documented.

Days 21–50: Documentation and policies

For every limited- or high-risk system, produce the corresponding technical documentation and write (or adapt) your AI acceptable use policy. Define who oversees each system and how often.

Days 51–90: Training and monitoring

Train the team on the policy you've written, and set up the periodic review process — quarterly is reasonable for most SMBs — that keeps the inventory and classification up to date as the systems you use change.

If you'd rather have a plan already configured to your profile, size and deadline, the Implementation Roadmap generates the 6 phases and 36 prioritized tasks automatically.

Frequently asked questions

Is it legal to comply with the AI Act without hiring a consultant?

Yes. The AI Act doesn't require hiring any third party — it requires the organization to meet certain obligations (risk classification, technical documentation, human oversight, etc.), regardless of who carries them out. A consultant is a means, not a legal requirement.

Which part of compliance is hardest to do without outside help?

Conformity assessment for high-risk systems with critical safety implications (medical devices, essential infrastructure) usually requires notified bodies by law — that's not a choice between hiring a consultant or not. For the rest of the obligations — inventory, classification, documentation, internal policies — an SMB with a clear methodology can complete them on its own.

How long does it take to comply with the AI Act without a consultant?

It depends on the number of AI systems and their risk level, but for an SMB with 1-3 limited- or minimal-risk systems, a 90-day plan with the right templates is usually enough to get the inventory, classification and basic policies in order.

When should I reconsider hiring outside help?

When you have a high-risk Annex III system with no prior experience in regulatory technical documentation, when you operate in a sector with additional sector-specific regulation (healthcare, banking, critical infrastructure), or when the number of AI systems exceeds what an internal owner can manage part-time.

Practical takeaway

You don't need another consultancy to get started — you need to know exactly which obligations apply to you and a methodology to resolve them one by one. That's exactly what separates companies that depend on a third party for every decision from those that govern their own AI. Templates and methodology don't replace human judgment, but they do replace the need to pay for knowledge you can hold yourself.

AI Act Starter Kit The 3 essential checklists to know where you stand before committing to more: risk classification, regulatory deadlines and GPAI compliance. $29 VAT incl.
Buy →