EU AI Act Compliance Checklist for Mid-Sized Companies
Ready 4 AI Act Team ยท March 12, 2026 ยท Last updated July 31, 2026

EU AI Act Compliance Checklist for Mid-Sized Companies
Most mid-sized organisations do not have a dedicated AI compliance team. This checklist gives you the minimum credible programme to be defensible on August 2, 2026.
1. Governance
- Named AI compliance owner at leadership level
- AI use policy approved and communicated
- AI literacy training for all staff using AI systems
- AI topics on the risk register and reviewed quarterly
2. Inventory
- Central register of every AI system used or built
- For each: purpose, vendor, data used, decisions affected, users
- Register reviewed at least twice a year
3. Classification
- Each system classified: prohibited, high-risk, limited-risk, minimal-risk
- Rationale documented
- Prohibited use cases removed or blocked
4. High-risk controls (where applicable)
- Risk management process documented and lived
- Data governance controls in place
- Annex IV technical documentation started
- Human oversight designed and tested
- Logging enabled and retained
- Post-market monitoring plan
5. Transparency
- Users informed when interacting with an AI system
- AI-generated content clearly labelled
- Privacy notices updated
6. Vendors
- AI Act clauses added to standard contracts
- Vendor questionnaires updated
- Evidence collected for every high-risk supplier
7. Incident readiness
- Serious-incident reporting process defined
- Playbook for taking a non-compliant system off-line
- Escalation path to leadership and, if needed, authorities
Not sure where you stand? Run the free Ready 4 AI Act assessment โ you will get a personalised readiness report in minutes.
Reviewed by Ready 4 AI Act EU - Editorial team. This article is journalistic information, not legal advice.
Not sure where you stand?
Take the free readiness assessment and get a personalised report.
Start free assessment