July 16, 2026 · 7 min read
The EU AI Act is in force. Obligations for high-risk AI systems are active, and fines can reach €30 million or 6% of global revenue. Yet most sales teams haven't started their compliance audit.
This checklist lets you assess your situation in 30 minutes. Twenty points. Five categories. A final score that tells you exactly where you stand.
If your CRM uses AI, you're in scope. The degree depends on how that AI makes decisions.
Our complete EU AI Act guide for sales teams explains the risk tiers in full. The short version: any system that scores prospects, predicts buying behavior, or automates decisions affecting individuals falls under the regulation.
The 5 concrete obligations identified for commercial teams: documentation, explainability, human oversight, data quality, governance. Each one has a direct operational translation in your day-to-day workflow.
Before acting, you need to know where you stand. That's what this audit delivers.
1. Have you inventoried every AI system used in your sales process? Pipeline scoring, chatbots, data enrichment, predictive analytics... anything making automated decisions or recommendations is in scope.
2. For each AI system, have you determined its EU AI Act risk level? High risk means decisions affecting access to services or significantly influencing individuals. Limited risk means human-facing interactions requiring transparency disclosures.
3. Are the automated decisions in your CRM mapped? Who decides what? Which algorithm ranks a prospect? Which rule removes an opportunity from the pipeline? If you can't answer these questions, you have a compliance gap.
4. Do you maintain a register of AI systems with deployment dates and vendors? This document is the foundation of any external audit. Without it, you're starting from zero when a regulator walks in.
5. Can your commercial scoring algorithms be explained in plain language to a prospect? "Your score is 34/100 because..." needs to be achievable. Not necessarily automated, but possible on request.
6. Do you inform prospects that they're being evaluated by an AI system? A mention in your terms, privacy policy, or a dedicated document: this is mandatory for limited and high-risk systems. General language doesn't count.
7. Can your sales team contest or correct an AI decision? Effective human oversight is a core pillar of the EU AI Act. If the CRM flags an opportunity as cold and no one can challenge that classification, you're non-compliant.
8. Is the decision criteria documentation for each AI system accessible internally? Not primarily for regulators. For your team. If they don't understand why the AI decides as it does, they can't supervise it effectively.
9. Have you documented the origin and composition of data used to train your AI models? Proprietary data? Third-party? Mixed? Traceability is explicitly required for high-risk systems.
10. Has a bias audit been conducted on your scoring data? Geographic, industry, or company-size biases... A model trained on your past deals mechanically reproduces your blind spots. That's both a regulatory and a commercial risk.
11. Is there a process for updating and validating training data? Data ages. A model trained in 2023 on pre-inflation data may generate misaligned scores today. The regulation requires active governance, not a one-time training event.
12. Do personal data used in your models comply with GDPR? EU AI Act and GDPR stack. If you use personal data to train a scoring model, both regulations apply simultaneously. They don't cancel each other out.
13. Is an AI owner formally designated by name in your organization? Not necessarily a dedicated role in an SMB, but someone must be named. Without a name, no accountability. Without accountability, no lasting compliance.
14. Are AI decision logs retained with a defined retention period? If a decision is contested, you need to reconstruct why the AI decided as it did on a specific date. Without structured logs, that's simply not possible.
15. Is there a contestation process for prospects or clients impacted by an AI decision? "I think your AI got my file wrong" needs a procedural response. This isn't an edge case: it's an explicit obligation for high-risk systems.
16. Have your third-party AI vendors provided EU AI Act compliance documentation? CRM publisher, enrichment tools, predictive analytics... You remain responsible for the AI systems you deploy. If your vendor can't provide specific documentation, that's your problem too.
17. Is your technical documentation for each AI system up to date and accessible? Architecture, data flows, decision logic, known limitations... If it's not written, it's not compliant.
18. Is a periodic review schedule for AI systems planned and calendared? Compliance isn't a one-time event. Models drift, regulations evolve, use cases change. An annual review is the minimum viable cadence.
19. Is an AI incident management process documented? What happens if your AI generates an erroneous decision causing harm? Who gets notified, within what timeframe, with what remediation path? This scenario needs preparation, not improvisation.
20. Can you present a complete compliance dossier to an external auditor within 72 hours? The ultimate test. A regulator can request access quickly. If assembling the dossier would take weeks, you're not ready.
Count the number of "yes" answers:
| Score | Situation | Recommended Action |
|---|---|---|
| 18-20 | Compliant, ready for external audit | Maintenance and regulatory monitoring |
| 14-17 | Solid foundation, minor gaps | Plan corrections within 60 days |
| 10-13 | Significant regulatory exposure | Immediate priority action plan |
| Under 10 | Critical regulatory risk | Urgent mobilization, expert guidance recommended |
Most organizations using a CRM with AI pipeline scoring land between 8 and 12. Not because they're negligent, but because sales tools were built for performance, not regulatory compliance. That's a structural gap, not a character flaw.
Three points crystallize most of the compliance deficit.
AI decision traceability (points 3, 14, 20). Traditional CRMs log human actions but rarely capture algorithmic decisions with their full context. Why was this prospect scored this way at this moment, using which input data? The information often doesn't exist at all. This is precisely what traditional CRMs were never designed to produce.
Effective human oversight (points 7, 13, 15). Override theoretically exists. In practice, if the AI flags an opportunity as cold and the entire pipeline is organized around that judgment, no one contests it. Governance on paper is worthless without real process and a culture of questioning AI outputs.
Vendor documentation (point 16). Major CRM publishers issue general EU AI Act commitments. That's not sufficient. You need documentation specific to the AI modules you actually use, including the training data and the decision criteria applied within each one.
We built SymbiozAI with 17 active AI agents, 57 epics delivered, 195 sprints shipped. Every agent is documented: role, data consumed, decision logic, known limits.
Compliance wasn't added retroactively. It's in the architecture from day one.
Concrete examples:
Native explainability. Deal momentum is a transparent rule, not an opaque model. Threshold: 21 days without activity or fewer than 3 touchpoints triggers an attention flag. Every salesperson understands why an opportunity shifts status. They can contest it, correct it, override it. That's effective human oversight in practice, not on paper.
Zero manual entry. The EU AI Act requires training data quality. When all data enters via automatic synchronization, the risk of corrupted or human-entry-biased data disappears structurally. No phantom data, no garbage-in-garbage-out scoring.
Explainable DISC profiling. The 4 profiles (D/I/S/C) are explained to the team and serve as guidance, not oracles. The human adapts the approach based on context, the AI suggests the initial framing. The decision remains human.
At €650/month burn rate, there's no room for approximation. Every component must be justifiable. EU AI Act compliance is a competitive advantage when it's in the product from the start. It becomes a cost when bolted on afterward.
Does the EU AI Act apply to SMBs using a CRM with AI?
Yes, if the CRM makes automated decisions impacting individuals. Transparency obligations apply from the first AI system, regardless of company size. Full documentation obligations apply primarily to high-risk systems, but the baseline transparency requirements touch everyone.
Isn't my CRM vendor responsible instead of me?
No. You're considered a "deployer" of the AI system under the EU AI Act. As such, you have your own obligations: supervise usage, inform affected individuals, maintain decision logs. Responsibility is shared between publisher and deployer. It's not delegated entirely to one party.
Does a score of 10/20 mean I need to stop using AI CRM?
No. It means you have 10 gaps to close. Most are documentary and organizational, not technical. Designating an AI owner, documenting existing systems, establishing logging processes... these are days or weeks of work, not months of redesign.
How long does it take to reach compliance starting from scratch?
Between 4 and 12 weeks depending on your stack complexity. Inventory and initial documentation move fast, 1 to 2 weeks. Bias audits and governance process setup take longer. Specialized guidance significantly compresses that timeline.
EU AI Act compliance isn't an IT project. It's an organizational project with a technical dimension. These 20 points cover both. Start with the inventory of AI systems currently in use. It's the only way to know where you truly stand.
And if your CRM can't answer most of these points, the question isn't "how do I comply" but "is this tool built for what comes next."
Join the beta and connect your AI agent to the headless AI CRM.