In 7 Days: AI Factsheet Compliant with the AI Act for SMEs
In a week, you'll prepare two simple documents about using AI: a 1-page AI Factsheet and an AI Systems Register. No lawyer or coding needed. These will simplify audits, tenders, and improve visibility in AI Overviews.

Key takeaways
- Two documents in 7 days: AI Factsheet (1 page) and AI Systems Register (spreadsheet).
- Use familiar tools: Google Docs/Sheets or Microsoft 365 — no coding required.
- Write simply: purpose, data, limits, human oversight, contact for process owner.
- Regularly update (quarterly or after changes). Link in proposals and policies.
- Better transparency = faster audits and a greater chance for AI Overviews (AEO/GEO).
Clients and platforms are increasingly asking how you use AI and where your data comes from. The good news is that in just a week, you can prepare two short documents that clearly show this. Below is a simple plan, ready fields, and examples. No lawyer or coding needed — just standard office tools.
What and Why: Simple Language, Clear Rules
The AI Act is a European law about artificial intelligence. In practice, it means more transparency: you need to explain clearly what AI is used for and what its limitations are. The GPAI Code (a code of good practices for general-purpose AI systems) reinforces these expectations.
An AI Factsheet is a one-page description of your AI usage in plain language. The AI Systems Register is a spreadsheet listing processes, data, limits, and contact information for the process owner (the responsible person). This is not legal advice — it's a practical package to 'show how you operate'.
An additional benefit: AI responses in search engines (like Google AI Overviews) prefer clear sources and content provenance (where something comes from). Transparent documents increase the chance that AI will summarize your offerings well.
7-Day Plan (No Coding Required)
You only need an hour a day. Work in Google Docs/Sheets or Microsoft 365. If you prefer, use Notion or Airtable.
- Day 1 — Make a list of where you use AI: customer service, sales, marketing, HR, accounting.
- Day 2 — Choose a format and location: a folder named ‘Compliance/AI’. Create files: ‘AI Factsheet’ (doc) and ‘AI Systems Register’ (spreadsheet).
- Day 3 — Write version 1 of the AI Factsheet: in language your clients will understand. No jargon.
- Day 4 — Build the skeleton of the register: columns for data, limits, and process owner.
- Day 5 — Fill in 2–3 key processes. Add simple limits (boundaries of use) and who approves exceptions.
- Day 6 — Review with process owners. Add a ‘human in the loop’ (the person who checks AI results). Set review frequency (e.g., quarterly).','Day 7 — Publish: link in proposals, policies, and responses to RFPs (RequestsFor
What Fields to Fill: Ready to Copy
AI Factsheet (1 page, plain language): below are suggested sections with brief examples.
AI Systems Register (spreadsheet): enter each AI process as a single row. Keep it short and to the point.
- Purpose of using AI — e.g., ‘faster responses to customer emails’.
- Scope and description of operation — what AI does step by step in 1–2 sentences.
- What data — e.g., email content, FAQs. No sensitive details.
- Data sources — where they come from (e.g., our FAQ database, public websites).
- Tools — e.g., Microsoft Copilot 365, ChatGPT, your own model.
- Human in the loop — who checks important responses before sending? (name/role) — for the Factsheet; For the register: Process owner — name and contact (email).
Maintenance, Publication, and Quick Benefits
Maintenance: update after any change in tools, data, or rules. At least once a quarter. Add this to your onboarding checklist and change process checklist.
Publication: link the Factsheet in proposals, responses to RFPs, and policies on your website. Keep operational details in the register — available for client or platform requests.
Benefits: faster tenders (buyers know what to check), reduced risk (limits and owners are clear), better visibility in AI Overviews due to a simple, straightforward narrative about sources and quality control.
- Where to paste the link: footer of ‘AI Policies’, ‘About Us’ page, offer description, responses to RFPs.
- Set an SLA for updates: e.g., 5 business days from process change.
Instead of lengthy regulations, prepare two concise documents in a week. This is enough to demonstrate maturity in AI usage and address most purchasing questions. If you'd like, I can review your drafts and suggest additions — schedule a short, no-obligation consultation.
Frequently asked questions
Are the AI Factsheet and Register required by the AI Act?
The AI Act requires transparency and documentation of certain things, but it doesn't impose a specific template. These two documents will help meet client and platform expectations and organize processes. This is not legal advice.
What if we only use ready-made tools (e.g., Copilot, ChatGPT)?
That is also considered AI usage in your company. List the processes where you use them, what data is involved, and who approves the results. Simple limits (what not to do) are key.
Do I need to label AI-generated content?
In many situations in the EU, clear labeling of AI-generated content is required. In the Factsheet, indicate how you do this (e.g., a note in the footer). Discuss details with a lawyer or Data Protection Officer.
How often should I update the documents?
After any significant change in tools, data, or rules. If nothing changes — quarterly. Assign a document owner and a simple review process.
Will this help with AI Overviews (AEO/GEO)?
Yes, because a clear description of sources, purpose, and quality control helps AI models understand your offerings and cite reliable excerpts.