All insights AI

EU AI Act Checklist for Maltese SMEs: 10 Practical Steps

A 10-step EU AI Act checklist for Maltese SMEs: inventory your AI, set a policy, train staff, meet the transparency rules and prepare for December 2027.

Lloyd Bonello Co-founder, Business Development 6 min read
EU AI Act Checklist for Maltese SMEs: 10 Practical Steps
On this page
  1. Why does an SME need an AI Act checklist at all?
  2. The 10-step EU AI Act checklist
  3. How long does this take for a typical SME?
  4. How do you build compliance into new AI projects?
  5. FAQs

Most Maltese SMEs will never build an AI model. But almost all of them now use AI, in chatbots, accounting software, recruitment tools or simply staff using an AI assistant. That makes you a deployer under the EU AI Act. This checklist turns the rules into ten practical steps you can work through in a few weeks. It is general guidance, not legal advice; for high-risk uses, involve your legal adviser.

Why does an SME need an AI Act checklist at all?

Because the obligations follow the use, not the size of the company. The AI Act has applied in stages since 2024, and while the high-risk rules were pushed back by the 2026 Omnibus, other duties are already live. Malta now has an active regulator: the Malta Digital Innovation Authority (MDIA) leads market surveillance, and the Information and Data Protection Commissioner (IDPC) covers sensitive areas such as biometrics, according to a Chambers and Partners summary of the Maltese legal notices.

There is also a commercial reason. Eurostat found that among EU enterprises that considered AI but did not adopt it, just over half cited a lack of clarity about legal consequences as a barrier. A clear, documented approach removes that excuse and reassures clients who ask how you use AI.

The 10-step EU AI Act checklist

1. List every AI system you use

Include the obvious (ChatGPT, Claude, Copilot, Gemini) and the hidden: AI features inside your CRM, accounting package, recruitment platform, customer service software or marketing tools. For each, note the supplier, the purpose, who uses it and what data goes in. A spreadsheet is fine.

2. Decide whether you are a provider or a deployer for each

If you use a tool under the supplier’s name, you are usually a deployer. If you build an AI system and offer it to others under your own name, or significantly modify one, you may be a provider with heavier duties. Software houses and agencies should check this carefully.

3. Sort each use by risk level

  • Prohibited: manipulative or exploitative practices, social scoring and similar. Stop immediately if anything comes close.
  • High risk: uses listed in Annex III, such as recruitment and staff management, creditworthiness, education and access to essential services. Rules apply from 2 December 2027.
  • Transparency: chatbots, AI-generated or manipulated content, emotion recognition.
  • Minimal: most internal productivity uses, such as drafting emails or summarising documents.

4. Write a short AI use policy

One or two pages is enough for most SMEs. Cover approved tools, what data may never be entered (for example client personal data in personal accounts), when a human must check outputs, and who to ask. Update it when you add tools.

5. Put AI literacy training in place and record it

Article 4 has applied since 2 February 2025. The Omnibus softened it to an obligation to support the development of staff AI literacy, and documenting your training is advisable. A practical approach: a one-hour session for everyone on how AI works, where it fails and your policy, plus deeper sessions for heavy users. Keep attendance records.

6. Label your chatbots and AI-facing touchpoints

From 2 August 2026, people must be told when they are interacting with an AI system unless it is obvious. If your website, WhatsApp line or phone system uses an AI assistant, add a clear, early disclosure such as “You are chatting with our AI assistant” and offer a route to a person.

7. Review how you publish AI-generated content

Deepfakes must be disclosed, and so must AI-generated text published to inform the public on matters of public interest, unless it has been through human editorial review, according to Jones Walker’s summary of Article 50. For most marketing teams, the practical rule is: a human reviews and takes responsibility for everything published, and realistic synthetic images or video of real people are clearly labelled.

8. Ask your suppliers the right questions

For each important AI tool, ask the supplier: What risk category do you consider this? Where is our data processed and stored? Is it used for training? What logging and human override features exist? How will you support our obligations from 2027? Keep the answers with your inventory.

9. Connect AI governance to your GDPR processes

The AI Act sits alongside GDPR, not instead of it. Any AI that processes personal data needs a lawful basis, appropriate transparency to data subjects and, where the risk is high, a data protection impact assessment. If you already have a GDPR register, add an AI column rather than starting a separate system.

10. Prepare early for high-risk uses

If step 3 flagged any high-risk uses, start now. Deployers of high-risk systems will need to use them according to the provider’s instructions, assign trained people to human oversight, monitor operation, keep logs and, in some cases, inform affected people. Build these into the process design, not as an afterthought.

How long does this take for a typical SME?

In our experience, a business of 10 to 50 people can complete steps 1 to 7 in two to four weeks of part-time effort. Steps 8 to 10 depend on how many suppliers you rely on and whether any high-risk uses exist. The work is mostly organisation, not technology.

How do you build compliance into new AI projects?

The cheapest compliance is designed in. When we build automations or document processing systems, we log what the AI did, keep a human approval step where decisions matter, restrict data access to what the task needs and document it all. That serves the AI Act, GDPR and, frankly, good operations.

If you are considering funding for an AI project, note that Malta’s Digitalise Your SME AI top-up requires an ethical AI report after completion, so good governance helps there too. See our funding support page.

Frequently asked questions

Is using ChatGPT or Claude at work covered by the AI Act?

Yes, but usually as minimal risk. The main duties are AI literacy for staff and, if outputs are published or used to interact with the public, the relevant transparency rules. Data protection law also applies to any personal data entered.

Do I need to appoint an AI officer?

The AI Act does not require SMEs to appoint a dedicated AI officer. It is sensible to name one person responsible for the AI inventory, policy and training, often alongside data protection duties.

What are the fines for small businesses?

Fines depend on the breach. For Article 50 transparency breaches the ceiling is up to €15 million or 3% of worldwide annual turnover, and for SMEs the lower of the two applies. National penalties under Maltese regulations are also in place.

When do the high-risk rules apply?

Following the 2026 AI Omnibus, high-risk obligations for stand-alone systems such as recruitment or credit scoring tools apply from 2 December 2027, and for AI embedded in regulated products from 2 August 2028.

Want a second pair of eyes on your AI inventory, or help building compliant automations? Book a free discovery call with Haystack.

Free discovery call

Want this applied to your business?

Thirty minutes with our team. We look at how you work today and tell you honestly where AI and automation would pay off.

Next available

30 minutes · Google Meet · Malta time

START A PROJECT

Tell us what is slowing your business down. We will show you what to build, how long it takes and what it costs.

Free 30 minute discovery callReply within 1 business day