What's happening
Since Article 50 of the AI Act took effect on August 2 (we covered it here before the deadline and here right after), something we anticipated has started to materialise: large companies aren't just complying themselves, they're also reviewing their supply chain. Banks, insurers, public administrations and large corporations have started sending questionnaires and evidence requests to the SMEs they work with, asking how they use artificial intelligence and whether they can prove it in writing.
This isn't an isolated anomaly: it's the typical behaviour of any new regulatory framework with real penalties. Large companies manage their own risk by pushing part of the requirement down to their service providers — just as has happened for years with data protection (GDPR) or cybersecurity.
Why it's landing on you even if you don't sell "AI"
The most common mistake is assuming the AI Act only affects companies that develop or sell AI systems. It doesn't. The regulation distinguishes between providers (who develop the system) and deployers (who use it in their operations), and both have obligations.
If your company pays for a ChatGPT subscription, has Copilot enabled in Microsoft 365, uses a customer-service chatbot, or has any AI-powered tool built into its CRM or website, you're a deployer under the regulation. And if that tool interacts with customers or generates content, the Article 50 transparency obligations we covered in earlier articles come into play.
The real gap: high adoption, low governance
The reason this kind of request is catching so many SMEs off guard is a well-documented gap: AI adoption among Spanish SMEs is among the highest in Europe, but governance hasn't kept pace. According to IONOS/YouGov data, 41% of Spanish SMEs already use AI daily, leading adoption in Europe, and according to Adigital, 89% of Spanish companies expect to gain efficiency from AI. But trade press such as La Ecuación Digital has documented that much of that adoption is advancing without the minimum governance the regulation now requires: no inventory of tools in use, no internal policy, no one designated as responsible.
That exact gap is what a bank's or large client's questionnaire suddenly exposes.
What they're actually asking for
The format varies by company, but most of these requests revolve around the same things:
- Inventory of AI tools in use — which systems you use, for which processes, and since when.
- Evidence of customer-facing transparency — if a chatbot or AI-generated content reaches end users, proof it's identified as such (Article 50).
- A minimum internal responsible-AI-use policy — it doesn't need to be a 40-page document, but it does need to be formal and dated.
- A designated owner — a contact person for AI compliance matters, even if it's the same person already handling GDPR.
- A record of when you started evaluating this — the date matters: it demonstrates diligence even if the process isn't finished.
They're not asking for perfection, they're asking for evidence you're managing the risk. A bank doesn't expect an 8-person SME to have the same compliance apparatus as a bank. It expects to see that the topic is on the table, documented, and owned by someone.
What to do this week if you got the email
- Don't ignore it or leave it for "when there's time." These questionnaires usually have a response deadline, and not responding can affect the business relationship, not just legal compliance.
- Do the inventory in 48 hours. List which AI tools your company uses today: customer-service chat, content generation, Copilot, AI-powered CRM, anything. Be thorough, not just the obvious ones.
- Write a one-page policy. Which tools are allowed, for what uses, who's responsible, and how AI-generated content is labelled for the public.
- Respond to the questionnaire with what you have, dated. An honest, in-progress answer beats silence or a generic response with no substance.
- Keep everything. The email you received, your response, the date of the inventory and the policy. That documentation is your evidence if AESIA or the client itself asks again.
How to avoid being caught off guard next time
If this time it was a client that made you react, next time it could be an AESIA inspection, another client's audit, or due diligence during a financing round. Having the inventory and policy ready in advance — even before anyone asks — turns a stressful situation into a five-minute formality.
Conclusion
The AI Act has stopped being an abstract worry about distant fines: it's already moving down the supply chain, from large company to SME supplier, in the form of very concrete questionnaires. Companies that respond with a minimum governance baseline — inventory, policy, owner — not only avoid friction with important clients, they also arrive better prepared for the day AESIA inspects them directly.
At Dataverse Solutions we help SMEs put that compliance baseline together in days, not months, so a client's or AESIA's email stops being an emergency.