33 numbered items ยท Last updated 7 July 2026
The EU AI Act compliance checklist
An EU AI Act compliance checklist is a working list of the concrete artefacts and controls a mid-sized company needs to be ready for the Act. Governance, inventory, competency, transparency and vendor items are "do now" - the Article 50 obligations have applied since 2 August 2026, and the marking grace period for pre-existing generative systems ends 2 December 2026. High-risk technical controls target the deferred 2 December 2027 (Annex III) and 2 August 2028 (Annex I) dates set by Regulation (EU) 2026/1744.
Governance & accountability
Governance means naming who is on the hook, in writing, before anything goes wrong. Regulators expect a person, not a team, to answer for AI risk.
- 1
Name a single AI accountable owner at leadership level.
Article 22 supervisory-authority interactions need one point of contact.
- 2
Publish an internal AI usage policy covering permitted tools, data classes and disclosure.
Baseline for Article 4 competency support and Article 50 transparency.
- 3
Add AI risks to the enterprise risk register with quarterly review.
Feeds the risk-management-system evidence high-risk providers must show (Art. 9).
- 4
Approve an AI incident-response playbook (who decides to pull an AI tool).
Post-market monitoring under Art. 72 assumes this exists.
- 5
Board or ExCo receives an AI compliance report at least twice a year.
Documents leadership oversight - the first thing an auditor asks for.
AI inventory & risk classification
You cannot comply with what you have not listed. An accurate inventory is the single highest-leverage artefact in an AI compliance programme.
- 6
Central register of every AI system built, bought or embedded - including shadow-IT usage.
Prerequisite for classification and vendor evidence.
- 7
For each system record: purpose, vendor, data classes, decision impact, user population.
Fields required for Annex IV documentation.
- 8
Classify each system as prohibited, high-risk (Annex III / Annex I), limited-risk (Art. 50) or minimal.
Determines every downstream duty.
- 9
Document the classification rationale, and re-review whenever features change.
Regulators reject 'trust us' - they want the reasoning.
- 10
Flag any use touching HR, credit, education, biometrics, essential services or law enforcement.
Automatic Annex III triggers.
AI competency (Article 4)
Article 4 as amended by Regulation (EU) 2026/1744 asks providers and deployers to take appropriate measures - they should support their staff to building up adequate AI competency, so people running or overseeing AI understand it well enough to do so safely as the technology moves.
- 11
Baseline AI training rolled out to every employee using AI in their role.
Article 4 as amended by the Omnibus.
- 12
Advanced training for teams operating high-risk or customer-facing AI.
Proportionality principle in Art. 4.
- 13
Record who was trained, when, and on what content.
Only evidence a regulator accepts.
- 14
Refresh training after any material tool or policy change, not just annually.
Competency has to keep pace with the tools in use.
Transparency & Article 50 (in force since 2 Aug 2026)
Article 50 transparency obligations have applied since 2 August 2026 - the Digital Omnibus did not defer them. Users must know when they are dealing with AI or AI-generated content.
- 15
Chatbots and voice agents disclose that the user is interacting with AI.
Art. 50(1).
- 16
AI-generated images, audio, video and text are labelled as such at delivery.
Art. 50(4) and deepfake regime.
- 17
Emotion recognition and biometric categorisation notify affected persons.
Art. 50(3).
- 18
New AI-generating systems produce machine-readable watermarks.
Art. 50(2); 4-month grace for pre-existing systems ends 2 Dec 2026.
- 19
Web assistants and support flows carry an accessible 'this is AI' notice.
Combines Art. 50(1) with usability expectations.
High-risk technical controls (target 2 Dec 2027 / 2 Aug 2028)
The Digital Omnibus moved Annex III to 2 December 2027 and Annex I to 2 August 2028. Twelve to eighteen months of implementation work is realistic - starting now is not early.
- 20
Risk-management system covering the full lifecycle documented (Art. 9).
Central artefact of the high-risk regime.
- 21
Data governance controls: representative, relevant, error-free training and validation data (Art. 10).
Bias and quality failures start here.
- 22
Annex IV technical documentation opened and maintained (Art. 11).
Without it there is no conformity assessment.
- 23
Automatic event logs enabled and retained (Art. 12).
Regulators want traceability, not screenshots.
- 24
Human oversight designed into the workflow, not bolted on (Art. 14).
'Human in the loop' has to be evidenced end-to-end.
- 25
Accuracy, robustness and cybersecurity tests with pass/fail thresholds (Art. 15).
Required in the technical file.
- 26
Quality-management system covering design, testing, monitoring (Art. 17).
Notified bodies check this first.
- 27
Conformity assessment route selected and CE marking planned (Art. 43).
Determines which Annex applies to your build.
- 28
Post-market monitoring plan with defined signals and escalation (Art. 72).
'Ship and forget' is no longer legal.
- 29
Serious-incident reporting procedure with 15-day deadline mapped out (Art. 73).
Missed reports carry their own fine.
Vendors, contracts & data
Most high-risk exposure sits with third parties. Contracts are the only lever a deployer has once a system is in production.
- 30
AI Act clauses added to procurement and vendor contract templates.
Deployer duties under Art. 26 depend on provider evidence.
- 31
Provider evidence collected for every high-risk supplier: documentation, oversight design, incident history.
Deployers inherit gaps.
- 32
Data protection impact assessment (DPIA) refreshed to include AI-specific risks.
GDPR Art. 35 dovetails with AI Act obligations.
- 33
Records of processing updated for AI-based decisions.
Regulators cross-check GDPR and AI Act registers.
Get your personalised checklist
Answer a few questions and receive a report ranking these items by relevance to your company's AI use.
Start free assessment