Three months ago, the CEO of a garment factory in the Vale do Ave asked us: "You talk a lot about AI, but nobody explains what I need to document so I'm not caught off guard when the Competition Authority knocks on the door." It wasn't a compliance question — it was an operational risk question. He knew that ISO 27001 and the governance models he had did not cover AI. And he was right.

The EU AI Regulation (AI Act, Regulation (EU) 2024/1689) is not a corporate ethics document. It is a legal framework with teeth. The prohibitions have applied since February 2025, the general-purpose model rules since August 2025, and the documentation and audit obligations touch any company that develops, integrates or uses AI systems in critical processes. A Portuguese industrial SME that uses AI for demand forecasting, stock management, production planning or customer credit approval is already within the AI Act's perimeter. Not because it is large — but because it is using AI in contexts that affect rights, safety or compliance.

In 2025, only 11.5% of companies in Portugal with 10 or more employees used artificial intelligence technologies, according to the INE. But among large companies adoption rises to 49.1%, while for medium-sized ones (50-249 employees) it stands at 18.2%. The gap is clear: SMEs fall behind not because they don't want to, but because the cost of compliance seems prohibitive. Five years ago, we said AI was an IT matter. We were wrong. Today we see it is a matter for the CEO, the CFO and compliance. The documentation you have to keep is not an Excel file stored in the cloud — it is a risk map, a record of design decisions, a testing protocol, an archive of model versions, an audit of inputs and outputs. Without this, you have no proof that you controlled the risk. With it, you do.

AI Governance is not Data Governance

A common confusion: "We have a DPO, we have GDPR, we have data protection — that covers AI." It doesn't. GDPR tells you what to do with people's data. The AI Act tells you what to do with the system that makes decisions about people. They are different layers.

AI governance in an industrial SME means documenting three things: what the system does (input, logic, output) and who authorises each change; how and where the model was trained (data used, version, date, person responsible); how you test the risk (bias, discrimination, operational failure) and how often.

A textile factory in the Vale do Ave with 80 employees that uses AI to classify defects in knitwear is in a medium-risk scenario according to the AI Act. The system makes decisions that affect quality (operational risk) and, if poorly trained, can discriminate against certain types of looms or operators (rights risk). Documenting means: what is the training dataset? How many samples? From what period? Who verifies accuracy monthly? What happens when the model gets it wrong? Who decides whether the model comes out of production? Without these answers in writing, you have no compliance. With them, you have proof that you thought about the risk before the problem arrived.

AI documentation is not a compliance cost. It is an investment in resilient operations.

What is curious: most industrial SMEs already have fragments of this documentation — they are just scattered. IT knows what the model version is. The production manager knows the error rate. Sales know when the system fails. AI governance is bringing these fragments together into a single source of truth, assigning responsibilities, and updating it monthly. It is not complex. It is repetitive.

What to Document — Operational Checklist

We won't reproduce a compliance manual here — they already exist, published by the European Commission. But we will say what a real industrial SME needs to keep on file:

Artefact What it Includes Update Frequency
AI Systems Register Name, implementation date, model version, technical owner, date of last audit Monthly
Technical Description Input (raw data, source, frequency), processing (model, algorithm), output (decision or score), action Whenever the logic changes
Training Dataset Number of samples, period covered, origin, pre-processing, balancing, date of last review After each retraining
Accuracy and Bias Overall error rate, accuracy by sub-group (product, shift, region), risks detected Monthly
Testing Protocol Validation method (A/B, cross-validation, stress-test), testing frequency Whenever the model changes
Change Log Date, person responsible, reason, accuracy before and after each adjustment After each change
Incidents and Corrections Date, description, impact, root cause, corrective action, resolution date When they occur
Stakeholder Communication How and when customers, suppliers and employees were informed about AI decisions Whenever the policy changes

A company we saw recently had a demand forecasting model that ran every month. No one knew what the model version was, when it had last been retrained, or what the margin of error was. When we asked "what is the accuracy?", the answer was "it seems to work well". "Seems" is not documentation. Documentation is: "MAPE accuracy of 12.3% in January 2025, validated over 24 months of historical data, retrained on 15 January, person responsible: João Silva, next review: 15 April." This is what an auditor wants to see. This is what a court wants to see. This is what you yourself want to see when the model starts to fail and you have 48 hours to diagnose it.

The Real Risk is not Legal — It is Operational

When we talk to CFOs of industrial SMEs, the first concern is a regulatory fine. Understandable. But the real risk is operational: a model that fails silently for three months, affects margins, and no one detects it because there was no defined audit. We saw a food distribution company that used AI to optimise routes. The model had been trained with 2022-2023 data. No one retrained it when the customer network changed in 2024. The routes became sub-optimal, transport costs rose by 8%, and it was only detected in the quarterly margin analysis. Eight percentage points lost because there was no documented retraining protocol.

Well-executed AI governance reduces this risk. Had there been a monthly audit schedule (5 hours), they would have detected the degradation in three weeks, not three months. The cost of documentation is low. The cost of silent failure is high.

There is also a risk no one talks about: the concentration of knowledge. The model was developed by an external consultant, or by a junior who left the company. Suddenly, no one knows how the model works, or how to retrain it. Documentation means that any competent IT person can understand the system in half an hour, and keep it running without depending on any one person. This is critical in an SME where turnover is real and knowledge is the most fragile asset.

How to Start — Without Bureaucracy

A CEO of an industrial SME is right to be sceptical about complex frameworks. AI governance does not need a new department. It needs three simple things.

First, an inventory. How many AI systems do you have in operation? Forecasting? Classification? Scoring? Optimisation? Make a list. If you have fewer than five, you're lucky — it's all manual. If you have more than ten, you have a governance problem that needs solving. This takes an afternoon.

Second, an owner per system. It's not the IT director. It's someone who understands the business — a production manager, a planning lead, a sales rep. Their responsibility is: "I know what this system does, I know when it fails, I have the documentation up to date." A 30-minute monthly meeting with IT to review accuracy, incidents, and changes. That's it. This is what works in an SME because there is no room for silos.

Third, a source of truth. A Google Sheets, an Excel, or a documentation module in the ERP — it doesn't matter. What matters is: it's up to date, it's centralised, it's accessible. Each system has one line: name, version, person responsible, date of last audit, accuracy, open incidents. One hour of updating per month, at most. Then, when the authority knocks on the door (or when there's an incident), you have the answer ready.

Over 35 years working with industrial SMEs, we have learned that the bureaucracy that works is the one that is simple, repetitive, and has a clear owner. AI governance is this. It's not a project — it's a routine. A routine that costs 4-6 hours a month, protects 8 percentage points of margin, and lets you sleep easy when the regulator calls.

The AI Act will evolve. It will probably become stricter. The fines will increase when the first enforcement cases reach the EU (in 2026 or 2027, we reckon). But the documentation you do today will not become obsolete. It will become more relevant. Because the foundation — knowing what your system does, how it fails, and who is responsible — is immutable.

The question the Vale do Ave CEO asked three months ago was simple: "Nobody explains what I have to document." Now he knows. The next question is: "When do we start?" The answer is: Monday, 2 p.m., with a list of systems and a blank Google Sheets.

Frequently asked questions

Does the AI Act also apply to Portuguese industrial SMEs?

Yes. The AI Act applies to any company that develops, integrates or uses AI systems in critical processes, regardless of size. An SME that uses AI for demand forecasting, stock management, production planning or credit approval is within the perimeter of the regulation. The prohibitions have applied since February 2025 and the documentation rules since August 2025.

Does compliance with GDPR and ISO 27001 also cover the AI Act?

No. GDPR regulates what to do with people's data. The AI Act regulates what to do with the system that makes decisions about people. They are different layers. An SME may have a DPO and robust data protection, but that does not cover the AI governance obligations required by the regulation.

What exactly does an industrial SME need to document about AI?

Three main elements: what the system does (input, logic, output) and who authorises changes; how and where the model was trained (data, version, date, person responsible); how it tests risk (bias, discrimination, operational failure) and how often. This includes systems registers, technical descriptions, training datasets, accuracy, testing protocols, changes and incidents.

How often should AI documentation be updated?

It depends on the artefact. The systems register and accuracy and bias metrics should be updated monthly. The technical description, whenever the logic changes. The change log after each adjustment. The testing protocol whenever the model changes. Incidents and stakeholder communications as they occur.

What is the real risk of not documenting AI in an industrial SME?

The operational risk is greater than the legal one. A model that fails silently for months affects margins and no one detects it without a defined audit. Without documentation, you have no proof that you controlled the risk. With it, you have a rapid diagnosis when the model starts to fail and the capacity to respond within 48 hours.

Does an industrial SME already have fragments of the necessary AI documentation?

Yes, in most cases. IT knows the model version, the production manager knows the error rate, sales know when it fails. AI governance is bringing these fragments together into a single source of truth, assigning responsibilities and updating monthly. It is not complex, it is repetitive.

What is the difference between "it seems to work well" and real documentation?

Real documentation is specific: "MAPE accuracy of 12.3% in January 2025, validated over 24 months of historical data, retrained on 15 January, person responsible: João Silva, next review: 15 April." This is what an auditor, a court and you yourself want to see when diagnosing problems. "Seems to work" is not proof of compliance.