Most AI compliance and AI governance software is built for large enterprises with dedicated risk teams. For an SME that's a deployer - using AI tools rather than building them - the need is narrower and more practical: a way to inventory your AI, classify each use case, and keep the deployer documentation current. This guide covers what to look for, what's enterprise overkill, and why GDPR integration usually decides it. For the wider context, see the EU AI Act compliance pillar.
- For a deployer, the core need is inventory, classification and documentation - not model-risk tooling built for AI providers.
- GDPR integration is the deciding factor: most AI use is also personal-data processing.
- Watch for enterprise tools priced and scoped for AI builders, not AI users.
What Should AI Compliance Software Do for a Deployer?
Which features actually matter?
| Capability | Why it matters |
|---|---|
| AI system inventory | Find and track every AI tool, including Shadow AI |
| Risk classification per use case | The <a href="/en/resources/eu-ai-act-risk-classification" data-kind="site">class</a> drives the obligations |
| Deployer documentation (Art. 4/26/50) | The records you must produce |
| GDPR integration (ROPA, DPIA/FRIA) | Most AI use is also personal data |
| Review reminders | Documentation decays without prompts |
The most useful behaviour is the same as for GDPR tooling: the system telling you what's missing or stale - an unclassified use, or a high-risk use with no documented DPIA or missing the FRIA required under Art. 27.
What to Avoid
How do I spot the wrong tool?
- Provider-grade model-risk tooling. Built for companies that train AI - overkill and mispriced for a deployer.
- AI Act only, no GDPR. Separate tools for AI and data protection produce records that don't reconcile in an audit.
- Static template packs. Files behind a login aren't a governance system; they don't flag what's stale.
- No expert review path. Software documents; it doesn't sign off. A route to a certified DPO matters for legal exposure.
Why GDPR Integration Decides It
Why is this the key question for an SME?
Because for a deployer the AI Act and GDPR are mostly the same work seen twice. The AI inventory extends your ROPA; the FRIA supplements your DPIA; AI literacy combines with GDPR training. A tool that handles only the AI side leaves you maintaining two systems that drift apart - exactly the contradiction an auditor looks for. See integrated GDPR + AI Act compliance for why one workflow wins.
Where ETHYX Fits
What does ETHYX offer a deployer?
ETHYX covers AI inventory, risk classification and deployer documentation in the same workflow as GDPR, with a certified external DPO (CIPP/E) for review. Pricing starts at €149/month for the platform; the Expert plan at €299/month adds the named DPO and EU AI Act deployer documentation - built for AI users, not AI builders.