33 numbered items ยท Last updated 7 July 2026

    The EU AI Act compliance checklist

    An EU AI Act compliance checklist is a working list of the concrete artefacts and controls a mid-sized company needs to be ready for the Act. Governance, inventory, competency, transparency and vendor items are "do now" - the Article 50 obligations have applied since 2 August 2026, and the marking grace period for pre-existing generative systems ends 2 December 2026. High-risk technical controls target the deferred 2 December 2027 (Annex III) and 2 August 2028 (Annex I) dates set by Regulation (EU) 2026/1744.

    Governance & accountability

    Governance means naming who is on the hook, in writing, before anything goes wrong. Regulators expect a person, not a team, to answer for AI risk.

    1. 1

      Name a single AI accountable owner at leadership level.

      Article 22 supervisory-authority interactions need one point of contact.

    2. 2

      Publish an internal AI usage policy covering permitted tools, data classes and disclosure.

      Baseline for Article 4 competency support and Article 50 transparency.

    3. 3

      Add AI risks to the enterprise risk register with quarterly review.

      Feeds the risk-management-system evidence high-risk providers must show (Art. 9).

    4. 4

      Approve an AI incident-response playbook (who decides to pull an AI tool).

      Post-market monitoring under Art. 72 assumes this exists.

    5. 5

      Board or ExCo receives an AI compliance report at least twice a year.

      Documents leadership oversight - the first thing an auditor asks for.

    AI inventory & risk classification

    You cannot comply with what you have not listed. An accurate inventory is the single highest-leverage artefact in an AI compliance programme.

    1. 6

      Central register of every AI system built, bought or embedded - including shadow-IT usage.

      Prerequisite for classification and vendor evidence.

    2. 7

      For each system record: purpose, vendor, data classes, decision impact, user population.

      Fields required for Annex IV documentation.

    3. 8

      Classify each system as prohibited, high-risk (Annex III / Annex I), limited-risk (Art. 50) or minimal.

      Determines every downstream duty.

    4. 9

      Document the classification rationale, and re-review whenever features change.

      Regulators reject 'trust us' - they want the reasoning.

    5. 10

      Flag any use touching HR, credit, education, biometrics, essential services or law enforcement.

      Automatic Annex III triggers.

    AI competency (Article 4)

    Article 4 as amended by Regulation (EU) 2026/1744 asks providers and deployers to take appropriate measures - they should support their staff to building up adequate AI competency, so people running or overseeing AI understand it well enough to do so safely as the technology moves.

    1. 11

      Baseline AI training rolled out to every employee using AI in their role.

      Article 4 as amended by the Omnibus.

    2. 12

      Advanced training for teams operating high-risk or customer-facing AI.

      Proportionality principle in Art. 4.

    3. 13

      Record who was trained, when, and on what content.

      Only evidence a regulator accepts.

    4. 14

      Refresh training after any material tool or policy change, not just annually.

      Competency has to keep pace with the tools in use.

    Transparency & Article 50 (in force since 2 Aug 2026)

    Article 50 transparency obligations have applied since 2 August 2026 - the Digital Omnibus did not defer them. Users must know when they are dealing with AI or AI-generated content.

    1. 15

      Chatbots and voice agents disclose that the user is interacting with AI.

      Art. 50(1).

    2. 16

      AI-generated images, audio, video and text are labelled as such at delivery.

      Art. 50(4) and deepfake regime.

    3. 17

      Emotion recognition and biometric categorisation notify affected persons.

      Art. 50(3).

    4. 18

      New AI-generating systems produce machine-readable watermarks.

      Art. 50(2); 4-month grace for pre-existing systems ends 2 Dec 2026.

    5. 19

      Web assistants and support flows carry an accessible 'this is AI' notice.

      Combines Art. 50(1) with usability expectations.

    High-risk technical controls (target 2 Dec 2027 / 2 Aug 2028)

    The Digital Omnibus moved Annex III to 2 December 2027 and Annex I to 2 August 2028. Twelve to eighteen months of implementation work is realistic - starting now is not early.

    1. 20

      Risk-management system covering the full lifecycle documented (Art. 9).

      Central artefact of the high-risk regime.

    2. 21

      Data governance controls: representative, relevant, error-free training and validation data (Art. 10).

      Bias and quality failures start here.

    3. 22

      Annex IV technical documentation opened and maintained (Art. 11).

      Without it there is no conformity assessment.

    4. 23

      Automatic event logs enabled and retained (Art. 12).

      Regulators want traceability, not screenshots.

    5. 24

      Human oversight designed into the workflow, not bolted on (Art. 14).

      'Human in the loop' has to be evidenced end-to-end.

    6. 25

      Accuracy, robustness and cybersecurity tests with pass/fail thresholds (Art. 15).

      Required in the technical file.

    7. 26

      Quality-management system covering design, testing, monitoring (Art. 17).

      Notified bodies check this first.

    8. 27

      Conformity assessment route selected and CE marking planned (Art. 43).

      Determines which Annex applies to your build.

    9. 28

      Post-market monitoring plan with defined signals and escalation (Art. 72).

      'Ship and forget' is no longer legal.

    10. 29

      Serious-incident reporting procedure with 15-day deadline mapped out (Art. 73).

      Missed reports carry their own fine.

    Vendors, contracts & data

    Most high-risk exposure sits with third parties. Contracts are the only lever a deployer has once a system is in production.

    1. 30

      AI Act clauses added to procurement and vendor contract templates.

      Deployer duties under Art. 26 depend on provider evidence.

    2. 31

      Provider evidence collected for every high-risk supplier: documentation, oversight design, incident history.

      Deployers inherit gaps.

    3. 32

      Data protection impact assessment (DPIA) refreshed to include AI-specific risks.

      GDPR Art. 35 dovetails with AI Act obligations.

    4. 33

      Records of processing updated for AI-based decisions.

      Regulators cross-check GDPR and AI Act registers.

    Get your personalised checklist

    Answer a few questions and receive a report ranking these items by relevance to your company's AI use.

    Start free assessment