All articles
6 min read

12 Customer Questions About the AI Act — A Checklist for SMEs

B2B customers are starting to ask about the AI Act and GDPR. Here are 12 ready-made answers for RFI + a list of simple 'proofs' and no-code mini-automation in Google and Zapier/Make. Shorten your sales cycle.

Cover illustration for article: 12 Customer Questions About the AI Act — A Checklist for SMEs

Key takeaways

  • Have one folder for 'AI Compliance' with a register, factsheet, and policies.
  • Respond briefly: what, on what basis, where data is, and how long.
  • Include simple 'proof': a sheet, screenshot, or one-page procedure.
  • Automate updates and RFI packaging in Zapier/Make.
  • Regularly (monthly/quarterly) review the register and permissions.

Customers are asking for details about the AI Act and GDPR. If you don’t respond quickly and consistently, sales can slow down. Here are 12 questions that are currently being asked in RFIs (Request for Information) and ready-made answers with 'proofs' that can be done without code in Google and Zapier/Make.

How to Use This Checklist and What to Prepare in 1 Hour

The AI Act is a set of European rules for artificial intelligence. It outlines who is responsible for what and what obligations exist based on risk. GDPR is about protecting personal data. Customers often combine these topics in one RFI — provide them with a cohesive package.

Create an 'RFI-AI Package' in Google Drive. This consists of a few simple documents that you fill out once and then just update. No technical implementations or coding required.

  • Folder: AI Compliance (shared, access limited to authorized personnel).
  • Google Sheets: AI Systems Register (process, tool, provider, data, risk, review status).
  • Google Docs: AI Factsheet (1 page: summary of AI use, data, providers, contact).
  • Google Docs: AI Usage Policy (2 pages: allowed/prohibited, access, reviews).
  • Google Docs: Incident Procedure 72h (1 page: steps, contact, checklist).
  • Zapier/Make (no-code automation tools that connect apps): reminders for reviews, generating RFI packages from templates, archiving in PDF.

12 Customer Questions and Brief, Safe Answers

Tailor the content to your business. Each answer also includes 'proof' — a simple confirmation in the form of a file or screenshot. These attachments help reassure compliance on the client's side.

  • 1) What AI systems do you use and for what purposes? — We have an up-to-date register of AI systems (process, provider, type of data). We mainly use it for writing support, text analysis, and sales. — Proof: 'AI Systems'
  • 2) Do any of your systems fall under 'high risk' in the AI Act? — We use a simple risk assessment (impact × data). Currently, we do not use high-risk systems; if that changes, we will agree on a compliance plan before it
  • 3) What data (including personal data) goes into AI, and do you minimize it? — We only input necessary data. Personal data is anonymized/pseudonymized (identifiers are removed or replaced). — Proof: 'Data Map' table
  • 4) On what basis do you process data under GDPR and what is your role? — Roles and bases are defined in the contract. When we act on behalf of the client, we are a data processor and enter into a DPA (Data Processing A
  • 5) Where is the data stored, and does it leave the EEA? — We prefer processing within the EU/EEA (European Union and associated countries). If a transfer outside the EEA is necessary, we use SCC (Standard Contractual Cla
  • 6) Do your data train supplier models? — We set 'zero data retention' (the supplier does not use data for training) or ensure this in the contract. We regularly check account settings. — Proof: Screenshot of settings

Simple No-Code Automation to Ensure Nothing Gets Lost

Zapier/Make are 'connectors' for applications — you set rules like: if a new entry appears in a sheet, create a document and send a notification. This way, responses and proofs are always fresh, and the RFI package is generated in minutes.

  • Google Form 'New AI Tool' → Sheets: logs a record and assigns an owner for review.
  • New record in 'Register' → Docs from template: creates a 1-page Factsheet and links it in the sheet.
  • Button 'RFI Package' → PDF generator: combines Factsheet, Register excerpt, Policy, and Procedure into one file.
  • Monthly schedule → reminders: review permissions, logs, and retention periods.
  • Quarterly exercise 30 min: '72h incident' — checklist and record results in the sheet.

A single source of truth, brief answers, and small automations — this is usually enough to remove compliance blocks and speed up contract signing. Want to go through this checklist live and set up your RFI-AI package in 2 hours? Reach out — we can do it together.

Frequently asked questions

If we don’t use AI, do we still need to respond to RFIs?

Yes. Simply state that you do not use AI in the processes covered by the contract and include the AI Usage Policy (with a list of prohibited tools). This often resolves the issue.

Do SMEs need a lawyer for the AI Act and GDPR?

Not for response templates and registers. For contracts (DPA, SCC) and exceptions — it’s worth consulting a lawyer. A minimum review once a year is a good practice.

Does the AI Act only apply to companies building models?

No. It also applies to users (so-called deployers). Some obligations include transparency, risk control, and documentation. Our checklist covers these expectations in RFIs.

What do clients usually expect 'right away'?

Typically: an AI systems register, confirmation of 'no training/zero data retention', a list of subcontractors, and a brief 72h incident procedure. All with the date of the last review.

Let's talk
about your project

The consultation is free and no-strings-attached. We'll review your needs and I'll suggest concrete solutions.

Send a message

Briefly describe your problem — I'll get back to you with concrete suggestions.