Where do you really stand?

Before anything else, you need to distinguish two very different situations. If your SME uses off-the-shelf AI tools (ChatGPT, Microsoft Copilot, HR software with AI, a CRM with automated recommendations), your obligations relate mainly to the GDPR and to the policy governing the use of those tools. If your SME develops or sells AI solutions to other organisations, your obligations are more extensive and you need to consider how you are classified under the EU AI Act.

In the first situation, which covers the vast majority of French SMEs, compliance is achievable and does not require significant legal resources. Here are the concrete steps.

Step 1: An inventory of your AI tools (half a day)

List all the digital tools your SME uses and identify those with an AI component: recruitment software with CV screening, customer service tools with a chatbot, a CRM with lead scoring, accounting tools with anomaly detection, marketing platforms with personalisation. For each tool: which provider, what personal data is processed, what decisions are influenced.

Step 2: An internal AI use policy (one day)

Write a simple policy (one to two pages) that defines which AI tools are authorised in the company, what staff can and cannot enter into them (no customer data without agreement, no sensitive HR data, no confidential business data), and what to do if a problem arises. This policy protects the company legally and creates a culture of AI responsibility.

Step 3: Updating the GDPR record

Add the AI processing activities identified in Step 1 to your record of processing activities (mandatory under the GDPR if you have more than 250 employees, recommended for all SMEs). For each processing activity: purpose, legal basis, categories of data, retention period, and any transfers to third countries.