What Happens in an AI Act and GDPR Audit for an SME

AI Readiness Assessment

What Happens in an AI Act and GDPR Audit for an SME

An AI Act and GDPR readiness audit maps your AI use, classifies the risk, and hands you a prioritised action plan. Here is what happens, phase by phase.

Eileen Weadick, PhD

Founder, Clear Gate Systems • 17 Jul 2026 • 7 min read

What Happens in an AI Act and GDPR Audit for an SME

An AI Act and GDPR readiness audit is a structured review that lists every AI system a business uses, sorts each one by its risk level under the EU AI Act and GDPR, checks those uses against what the law requires, and hands back a prioritised plan for closing the gaps.

EU AI Act compliance usually starts with a question most Irish SME owners cannot answer off the top of their head. What AI is actually running in my business, and on whose data? An AI Act and GDPR readiness audit exists to answer that. It is a structured diagnostic that turns scattered, side-door AI use into a documented inventory, a risk rating for each tool, and a plan you can work through. Parts of the Act are already live, including the AI literacy duty under Article 4 of the EU AI Act (Regulation (EU) 2024/1689), in force since 2 February 2025.[1] A readiness audit is how you find out where you stand.

Before commissioning any outside review, most businesses benefit from knowing where they actually stand, and that is what an AI Readiness Assessment maps.

What is an AI Act and GDPR readiness audit?

An AI Act and GDPR readiness audit is a single review that covers two rulebooks at once. The EU AI Act governs how AI systems are used, and GDPR governs the personal data those systems touch. Most AI a small business runs does both things at the same time, so reviewing them together saves effort.

Think of it as a health check. Nobody hands you a certificate at the end. What you get is an honest picture of what you are running, how risky each piece is, and what the law expects of you for each one. That is a different exercise from a business-capability AI readiness assessment, which looks at whether your data, people, and strategy are ready to adopt AI in the first place. This audit measures your legal exposure. The readiness assessment measures whether you are ready to adopt AI at all. Two different questions. It leans on the way the EU AI Act sorts AI use into risk tiers, and on the GDPR duties that apply the moment personal data is involved.

In summary

Ask for both rulebooks in one audit. The AI Act and GDPR overlap so heavily in a small business that reviewing them separately mostly just doubles the paperwork.

What happens in the first phase, the AI tool inventory?

The first phase builds one list of every AI system in use or planned across the whole business, including the tools bought as a feature inside something else and the ones staff started using without telling anyone. For each entry the audit records what it does, what data it touches, who owns it, and whether there is a contract behind it.

This sounds dull. It is the most valuable part. In most small firms AI has arrived through the side door. Someone in marketing drafts copy in ChatGPT, someone in operations has built a Zapier automation without telling anyone, HR is trialling a tool that scores staff productivity, and finance is testing an AI forecast add-in that nobody signed off on. Add the AI quietly embedded in software you already pay for, like Copilot inside Microsoft 365 or the assistant baked into your CRM, and a ten-person office can easily have a dozen AI systems running with no single person able to name them all. A business that is certain it "isn't really using AI yet" is exactly the business most likely to be surprised by how long that list turns out to be once someone actually asks the question. The inventory is the moment the fog becomes a spreadsheet. It is also the direct cousin of the GDPR record of processing activities that Article 30 already asks you to keep.[4]

In summary

Could you name every AI tool your team touched this week? The inventory phase exists precisely because almost nobody can.

How does an audit classify the risk of each AI system?

Once the list exists, the audit sorts each system by its risk level, because the EU AI Act asks very little of low-risk tools and quite a lot of high-risk ones. The Act sorts every AI system into one of four tiers, prohibited, high-risk, limited or transparency risk, or minimal risk.[1] Alongside that, the auditor flags the GDPR trigger points: special category data, decisions made about people automatically, and any monitoring of staff or customers.

Most owners find this part reassuring. The vast majority of everyday SME AI use lands in the minimal or transparency tier. A tool that drafts marketing copy is minimal. A website chatbot is transparency-tier, meaning you have to tell people they are talking to a machine. High-risk is a narrower band. It includes AI used for employment and the management of workers, so a system that monitors and scores staff performance is the kind of use that gets classified high-risk under Annex III of the Act.[1] Those high-risk employment obligations phase in from 2 December 2027 under Regulation (EU) 2026/1744, the Digital Omnibus on AI that entered into force in July 2026. That deferral covers standalone Annex III high-risk obligations only. It does not touch the AI literacy duty, the prohibited practices, or the transparency rules covered below, so the classification still needs doing now.[1] The risk rating also shifts depending on who is affected, and the duties get heavier once a customer is on the receiving end rather than your own staff. If a high-risk system does turn up, the audit will also check whether the business falls into the narrower set of cases, such as public sector bodies, providers of public services, or credit scoring and insurance risk systems, where a Fundamental Rights Impact Assessment is mandatory under Article 27. Most private sector SME uses of a high-risk tool fall outside this specific duty even where the system itself is classified high-risk.

In summary

Do not assume everything you run is high-risk. Classify first, because most small-business AI turns out to be minimal or transparency-tier, and that shrinks the job considerably.

What does the gap analysis actually check?

The gap analysis compares what you are doing against what the law asks, one system at a time, and writes down every place the two do not match. For a typical Irish SME the gaps cluster in a handful of predictable spots.

The common ones look like this. There is no record of any AI literacy measures under Article 4, which has applied since February 2025. A website chatbot gives no disclosure that a customer is dealing with AI, which the Act's Article 50 transparency rules require from 2 August 2026, with non-compliance carrying fines of up to 15 million euro or 3 percent of global turnover, whichever is higher (lower for SMEs).[1] A tool processes staff or customer personal data and no data protection impact assessment was ever done, even though GDPR Article 35 makes a DPIA mandatory for processing likely to be high risk, and treats new technology as a trigger.[3] Often there is no data processing agreement with the vendor, no named owner for the tool, and no human check on an automated decision. The DPC sets out a clear six-step method for a DPIA, moving through identifying whether one is needed, describing the project's characteristics including its data flows, identifying the risks, identifying solutions, signing off, and integrating the result back into the project.[3] A good audit runs that same discipline across your AI, and where a residual risk stays high, the law requires you to consult the DPC before going ahead.[3]

In summary

The gap analysis is where vague worry becomes a specific to-do list. Every gap it names is something concrete you can assign, cost, and close.

What do you get at the end of the audit?

At the end you get a prioritised action plan. It is a written, ordered list of what to fix, in what sequence, with the highest-risk and cheapest-to-fix items placed first. That plan is the whole point of paying for an audit, and it is what separates a useful engagement from an interesting conversation.

A good action plan reads like a project you can run. Each item names the system, the gap, the fix, and who should own it. It puts a website chatbot disclosure near the top, because that is high visibility and takes an afternoon. It might put a full DPIA for a staff-monitoring tool a little lower, because that is more work, and schedule it properly. The DPC treats a written DPIA record as good practice and something a regulator may later ask to see, and points out that failing to carry out a DPIA where one was required is itself a breach.[3] Some of the plan will call for policy and governance to be built rather than just fixed, which is where an AI governance blueprint comes in. The plan should hand you something you can execute, ideally with support, rather than a report that gathers dust on a shelf.

In summary

Judge an audit by its deliverable. The thing to hold out for is an ordered, costed action plan your team could start working through immediately.

How do you tell a real AI Act and GDPR audit from a compliance-score tool?

You tell them apart by the deliverable. Search for AI compliance help and the first page fills with software that promises an instant compliance score from a questionnaire. A score is a starting point, not an audit. It tells you a number; it does not map your actual tools, weigh your real risks, or hand you an owned plan.

Say a platform gives you a green score. Ask it three things. Did it find the ChatGPT account marketing uses on a personal login, did it read your vendor contracts, and did it produce a plan with named owners and dates? A checkbox tool answers a generic questionnaire and grades your answers. A genuine readiness audit is built from your business: the tools you run, the workflows they sit inside, the contracts behind them, and the people actually clicking the buttons, learned through real conversations rather than a form. That business-specific starting point is exactly why the inventory and the intake matter so much. The audit is only as good as how well it understands what you really do.

In summary

A number on a dashboard is not the same as knowing what you run and what to do about it. Buy the second one.

If this raises questions about your own AI use, get in touch. We can look at what you already have running and work out the right next step together, whether that is a full AI Readiness Assessment or something smaller to start with. A first conversation costs nothing.

FAQ

People also ask

How much does an AI compliance audit cost in Ireland?
Pricing depends on how many AI tools you run and how complex your data is, so most providers scope it after a short conversation. As a benchmark, a structured AI readiness diagnostic for an Irish SME typically starts in the low thousands of euro. Ask for a fixed scope and a written action plan as the deliverable before you commit.
Do small businesses need an EU AI Act audit?
There is no legal requirement to commission an external audit, but every business that uses AI already has obligations under the EU AI Act, including AI literacy under Article 4, which has applied since February 2025. An audit is simply the fastest way to find out which obligations apply to your specific tools. Most small firms find the exercise smaller than they feared.
What is the difference between a DPIA and an AI Act audit?
A data protection impact assessment (DPIA) is a GDPR process that assesses the privacy risk of a specific data-processing activity, required under Article 35 where the risk is high. An AI Act audit is broader, reviewing all your AI systems against the EU AI Act's risk tiers and duties. A combined readiness audit runs both together, because an AI tool that handles personal data usually needs both looked at.
Is an AI readiness audit the same as an AI readiness assessment?
They overlap but answer different questions. A compliance readiness audit checks your AI use against the EU AI Act and GDPR and produces a remediation plan. A business-capability readiness assessment looks at whether your data, people, and strategy are ready to adopt AI at all. Some engagements cover both in one piece of work.
Who should carry out an AI compliance audit?
The audit can be run internally if you have the AI and data protection knowledge in-house, or by an external specialist who reviews your tools, contracts, and workflows and builds the plan with you. The GDPR side, the DPIA, remains the data controller's responsibility even when the work is delegated. External help is common where no one internally has the spare capacity or the regulatory detail.

Clear Gate Systems helps Irish SMEs build AI capability safely, with AI governance and EU AI Act compliance built in automatically. This article is for informational purposes only and does not constitute legal advice. Clients requiring legal interpretation of the EU AI Act or other regulation should engage a qualified legal practitioner.