EU AI Act guide · updated 2 August 2026
The EU AI Act compliance checklist
Most AI Act “checklists” are a list of the regulation’s chapter headings. This one is ordered the way the work actually runs: inventory first, classification second, then obligations by role and tier— because until you know which tier each system is in and whether you are its provider or its deployer, you cannot know which of the Act’s obligations apply to you at all.
Phase 1 — Inventory (day 1)
- ✓List every AI system you build, sell or embed in your product.
- ✓List every AI system you deploy internally — including vendor tools for hiring, performance, credit, support and security.
- ✓For each: note your role (provider / deployer / both) — obligations differ sharply by role.
Phase 2 — Classification (week 1)
- ✓Screen each system against the Article 5 prohibitions — a prohibited practice cannot be remediated, only stopped.
- ✓Map each system against the eight Annex III high-risk categories.
- ✓For Annex III matches, check the Article 6(3) derogation — narrow procedural or preparatory tasks may fall out of high-risk (profiling never does).
- ✓Check Article 50 transparency triggers: chatbots, synthetic content, emotion recognition, biometric categorisation, deepfakes.
- ✓For general-purpose models you provide: Articles 53/55 duties.
- ✓Record every verdict with its article reference and date — the record is the deliverable.
Phase 3 — High-risk providers (weeks 1–4)
- ✓Risk-management system across the lifecycle (Art. 9).
- ✓Data-governance review of training/validation/test data (Art. 10).
- ✓Annex IV technical documentation — before market placement (Art. 11).
- ✓Automatic event logging (Art. 12) and instructions for use (Art. 13).
- ✓Human-oversight design (Art. 14); accuracy, robustness, cybersecurity (Art. 15).
- ✓Quality-management system (Art. 17), conformity assessment (Art. 43), EU declaration of conformity (Art. 47), CE marking (Art. 48), EU database registration (Art. 49).
Phase 3b — High-risk deployers (weeks 1–4)
- ✓Use per provider's instructions; assign trained, competent human oversight (Art. 26).
- ✓Control relevance and representativeness of input data you control.
- ✓Monitor operation; suspend and inform the provider on serious risk.
- ✓Retain system logs at least six months.
- ✓Inform workers and their representatives before workplace use.
- ✓Run a FRIA where Article 27 applies (public bodies, credit scoring, life/health insurance pricing).
Phase 4 — Everyone (ongoing)
- ✓AI-literacy measures for staff operating AI systems (Art. 4).
- ✓Article 50 disclosures shipped in-product where triggered.
- ✓Re-classify on every material system change; watch Commission guidelines and delegated acts.
- ✓Keep the inventory alive — new vendor tools enter it the week they're adopted.
Phases 1–2, automated: classify a system in 10 minutes
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →The order matters more than the completeness
A regulator’s first questions are “what systems do you run, what tier are they, and can you show your reasoning?” — the output of phases 1–2. A company that can answer those on paper, with article references and dates, buys itself goodwill and time for the heavier phase-3 work. A company that starts with a six-month documentation project and no inventory answers none of them. Classify everything first; remediate in order of exposure.
Frequently asked questions
→How long does EU AI Act compliance take?
It depends almost entirely on your risk tier. Classification of a system takes minutes with a structured assessment. A company whose systems land in the transparency tier can usually close its gaps — disclosure notices, content marking — in days. A high-risk provider needs weeks to assemble Annex IV documentation, oversight procedures and a conformity assessment, which is why a triaged 30-day plan matters more than a perfect one.
→Do we need a consultant, or can we do this ourselves?
The structuring work — inventory, classification, gap analysis, document drafting — is exactly what software does faster and more consistently than a billable-hours engagement. Where qualified counsel genuinely earns its fee is reviewing the output: confirming gray-area classifications and signing off high-risk conformity. Doing the structuring yourself typically cuts the counsel bill by an order of magnitude.
→What's the most commonly missed item?
Deployer obligations. Companies assume that buying AI from a vendor makes compliance the vendor's problem. Article 26 puts separate duties — trained human oversight, input-data control, monitoring, log retention, worker notification — on the company that uses a high-risk system.
→Does the checklist differ for non-EU companies?
The obligations are the same; only the trigger differs. Article 2 applies the Act to any provider placing systems on the EU market and to providers and deployers whose system output is used in the EU — where the company is established doesn't matter.
Where does your AI system actually stand?
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →Keep reading
AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.