Blog → EU AI Act for SMBs
EU AI Act & NIST AI RMF for SMBs
By Mathew Gale · Bug-bounty operator · Updated 2026-07-22
Most AI compliance content is written for enterprises with a legal team. If you're a 20-person company shipping AI, here's what actually applies to you — and the three things you need to do.
Are you even in scope?
The EU AI Act tiers risk. As a small company, you're likely limited-risk or minimal-risk unless you build something in a high-risk category (e.g., hiring, credit scoring, critical infrastructure). Quick test:
- Does your AI make decisions about people's rights/access? → likely high-risk
- Does it interact with humans (chatbot, bot)? → likely limited-risk (transparency duty)
- Is it an internal tool with no external users? → likely minimal-risk
Most SMB AI products land in limited-risk: you owe users transparency, not a full conformity assessment.
The 3 things you actually do
1. Document your AI use. What it does, what data it touches, what guardrails exist. A one-page internal memo beats a 40-page policy you'll never read.
2. Run a security audit. The Act expects you to manage AI risk. A GaleOps
$6K audit produces the evidence: what you tested, what broke, what you fixed.
3. Keep the evidence. When a customer or regulator asks "is your AI secure?", you send the report. The red-team engagement adds
EU AI Act + NIST AI RMF mapping for board-ready proof.
NIST AI RMF in 4 plain functions
- Govern — someone owns AI risk (even if it's just you).
- Map — you know what your AI does and where it can go wrong.
- Measure — you test it (that's the audit).
- Manage — you fix findings and keep proof.
That's the loop our audit → guardrail → red-team services walk you through. You don't need a framework certification; you need to show the loop ran.
How GaleOps makes it painless
We're not a compliance consultancy charging enterprise rates. We're operators who break AI systems — and our deliverables happen to be the artifacts the Act wants: a mapped audit report, a remediation record, and (for red team) a board-ready compliance summary.
Start with the $149 24-hour snapshot
Get a fast written report you can hand to legal. Then escalate to the $6K audit or $12K red team if you need more depth.
Start with the Audit →
$149 Snapshot (24h) →
The snapshot is the only paid entry-level report in the AI-security space — others only offer free scans.
Related: OWASP LLM Top 10 for Business Owners · $12K Red Team