Independent EU AI Act information resourceLegal text verified against EUR-Lex

31 steps · 7 phases

EU AI Act compliance checklist

Every step below names the provision it comes from and the date it has to be true by. The phases run in the order the work actually sequences, you cannot classify a system before you know what you hold, or what role you hold it in.

Classify a system first
Steps
31
Already in force
2
Next deadline
2 December 2026
Checked against source
18 August 2026

Where to start

With phase 1, always. Every obligation in the Regulation depends on facts about a specific system (its intended purpose, the role you hold for it, and whether it falls in an Annex III area) so nothing downstream can be assessed until the inventory exists.

Organisations that begin with the legal text rather than the inventory generally have to begin again. The inventory has no deadline of its own and blocks every phase after it, which makes it the only genuinely urgent item on this list.

What is already due

Three obligations on this checklist are in force now, not pending. AI literacy has applied since 2 February 2025, the first eight prohibitions since the same date, and the Article 50 transparency framework since 2 August 2026.

Checklist items by deadline
DueStatusStepProvision
2 February 2025In forceTake measures to support AI literacy, and record what you didArticle 4
2 August 2026In forceCheck Article 50 separately, in every tierArticle 50
2 December 2026UpcomingTest every system against all ten Article 5 prohibitionsArticle 5
2 December 2026UpcomingMark synthetic content in a machine-readable formatArticle 50(2)
2 December 2027UpcomingCheck the Annex III use-case routeArticle 6(2)
2 December 2027UpcomingEstablish a documented, continuous risk management systemArticle 9
2 December 2027UpcomingApply data governance to training, validation and testing dataArticle 10
2 December 2027UpcomingProduce technical documentation to the Annex IV specificationArticle 11
2 December 2027UpcomingEnable automatic logging over the system's lifetimeArticle 12
2 December 2027UpcomingWrite instructions for use that let a deployer meet its own dutiesArticle 13
2 December 2027UpcomingDesign human oversight into the system, not around itArticle 14
2 December 2027UpcomingSet and declare accuracy, robustness and cybersecurity levelsArticle 15
2 December 2027UpcomingPut a quality management system in placeArticle 17
2 December 2027UpcomingUse the system in accordance with its instructions, and assign competent human oversightArticle 26(1)-(2)
2 December 2027UpcomingMonitor operation, keep logs, and report serious incidentsArticle 26(5)-(6)
2 December 2027UpcomingInform affected peopleArticle 26(7), 26(11)
2 December 2027UpcomingComplete a fundamental rights impact assessment where requiredArticle 27
2 December 2027UpcomingDetermine the conformity assessment routeArticle 43
2 December 2027UpcomingDraw up the EU declaration of conformity and affix CE markingArticle 47
2 December 2027UpcomingRegister in the EU database before placing on the marketArticle 49
2 December 2027UpcomingAppoint an authorised representative in the UnionArticle 22
2 December 2027UpcomingRun post-market monitoring against a documented planArticle 72
2 December 2027UpcomingEstablish a serious incident reporting path that meets the deadlinesArticle 73
2 August 2028UpcomingCheck the Annex I product-safety routeArticle 6(1)
Phase 1

Establish what you hold

Every obligation in the Regulation depends on facts about a specific system, so nothing can be assessed until the inventory exists. This phase has no deadline of its own and blocks every phase after it.

  1. Build a register of every AI system you develop, buy, embed or reach through an API

    Include the intended purpose, the business process it sits in, whether output reaches people outside the organisation, and the vendor. Features added to tools already in use are the most commonly missed category, because no procurement decision marked their arrival.

    Owner
    Whoever owns technology risk, with procurement and engineering
    Due
    No fixed date

    Article 3(1)

  2. Fix your role for each system: provider, deployer, importer or distributor

    Duties attach to roles, not to company types, and one organisation is routinely several at once. A deployer becomes a provider if it puts its own name on a system, substantially modifies it, or changes its intended purpose, which is the single most common scoping mistake.

    Owner
    Legal, on engineering's description of what was changed
    Due
    No fixed date

    Article 3(3)-(7)Article 25

  3. Confirm territorial scope for each system

    You are in scope if you place a system on the EU market wherever you are established, or if the output is used in the Union. Being outside the EU is not itself an exclusion. Military, defence, national security and purely personal non-professional use are excluded.

    Owner
    Legal
    Due
    No fixed date

    Article 2

Phase 2

Screen against the prohibitions

Article 5 is absolute: a prohibited practice cannot be made lawful by documentation, consent or safeguards. Screen for it before spending effort anywhere else, because a hit means the system cannot be placed on the market or used at all.

  1. Test every system against all ten Article 5 prohibitions

    Eight have been unlawful since 2 February 2025. Two more, non-consensual intimate imagery and child sexual abuse material, apply from 2 December 2026. Any material listing eight prohibitions describes the superseded text.

    Owner
    Legal, with the system owner
    Due
    2 December 2026

    Article 5Prohibited practices guide

  2. Where a carve-out is relied on, record which one and why it applies

    Several prohibitions have narrow statutory qualifications: notably real-time remote biometric identification for law enforcement. Relying on a carve-out is a documented legal position, not an assumption.

    Owner
    Legal
    Due
    No fixed date
    Applies if
    You rely on any Article 5 carve-out

    Article 5(2)-(7)

Phase 3

Classify each system

Classification decides which regime applies and therefore how much work follows. The two high-risk routes carry different deadlines, so the route matters as much as the conclusion.

  1. Check the Annex I product-safety route

    A system is high-risk if it is a safety component of a product covered by the Union harmonisation legislation in Annex I, or is itself such a product, and requires third-party conformity assessment under that legislation.

    Owner
    Product compliance
    Due
    2 August 2028

    Article 6(1)Annex I

  2. Check the Annex III use-case route

    Eight areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and the administration of justice. This route carries the earlier deadline.

    Owner
    Legal, with the business owner
    Due
    2 December 2027

    Article 6(2)Annex III

  3. If you rely on the Annex III derogation, document and register the assessment

    A system in an Annex III area is not high-risk if it does not pose a significant risk of harm, on the grounds listed in Article 6(3). Relying on this requires a documented assessment before placing on the market, and registration in the EU database.

    Owner
    Provider
    Due
    No fixed date
    Applies if
    You conclude an Annex III system is not high-risk

    Article 6(3)-(4)Article 49(2)

  4. Check Article 50 separately, in every tier

    Transparency duties attach regardless of risk tier wherever a system interacts with people, generates synthetic audio, image, video or text, produces deep fakes, or infers emotion or biometric categories. A minimal-risk system can still owe them.

    Owner
    Product, with legal
    Due
    2 August 2026

    Article 50Article 50 guide

  5. If you place a general-purpose AI model on the market, assess systemic risk

    General-purpose AI models are regulated in their own right under Chapter V, separately from systems built on them. Assess whether the model meets the systemic-risk threshold, and notify the Commission if it does.

    Owner
    Model provider
    Due
    No fixed date
    Applies if
    You place a general-purpose AI model on the EU market

    Article 51Article 52

Phase 4

Build the high-risk requirements

This is the heavy phase and the reason the deferral to December 2027 is a schedule change rather than a reprieve. Each requirement produces evidence that a conformity assessment will look for.

  1. Establish a documented, continuous risk management system

    Not a one-off assessment: a process that runs across the lifecycle, identifying and evaluating known and reasonably foreseeable risks, and adopting mitigation measures. It has to be documented and maintained.

    Owner
    Provider
    Due
    2 December 2027

    Article 9

  2. Apply data governance to training, validation and testing data

    Covers design choices, collection and origin, preparation, assumptions, availability and suitability, and examination for bias. Article 10(5) permits processing special categories strictly for bias detection and correction, subject to safeguards, and Article 4a broadened that basis.

    Owner
    Data and ML engineering, with privacy
    Due
    2 December 2027

    Article 10GDPR interplay

  3. Produce technical documentation to the Annex IV specification

    It must exist before the system is placed on the market and be kept current. Annex IV sets the minimum contents; this is the document a market surveillance authority asks for first.

    Owner
    Provider
    Due
    2 December 2027

    Article 11Annex IV

  4. Enable automatic logging over the system's lifetime

    Logs must allow traceability appropriate to the intended purpose. Retention is at least six months unless other Union or national law requires longer.

    Owner
    Engineering
    Due
    2 December 2027

    Article 12

  5. Write instructions for use that let a deployer meet its own duties

    Including the intended purpose, accuracy and robustness levels, known limitations, foreseeable misuse, the human oversight measures required, and expected lifetime and maintenance.

    Owner
    Provider
    Due
    2 December 2027

    Article 13

  6. Design human oversight into the system, not around it

    The person overseeing must be able to understand capacities and limits, monitor for anomalies, resist automation bias, correctly interpret output, decide not to use it, and intervene or stop. A review step that cannot actually override the system does not satisfy this.

    Owner
    Product and engineering
    Due
    2 December 2027

    Article 14Human oversight guide

  7. Set and declare accuracy, robustness and cybersecurity levels

    Declared metrics go in the instructions for use. Robustness covers resilience to errors and inconsistencies; cybersecurity covers attempts to alter use, behaviour or performance, including data poisoning and adversarial examples.

    Owner
    Engineering and security
    Due
    2 December 2027

    Article 15

  8. Put a quality management system in place

    A documented system covering regulatory compliance strategy, design and verification procedures, data management, the risk management system, post-market monitoring, incident reporting and accountability.

    Owner
    Provider
    Due
    2 December 2027

    Article 17

Phase 5

Meet the deployer duties

Most organisations deploy far more systems than they provide, and deployer duties are frequently missed because the provider's documentation is mistaken for the whole obligation.

  1. Use the system in accordance with its instructions, and assign competent human oversight

    Oversight must be assigned to named people with the competence, training and authority to exercise it, and the authority matters as much as the training.

    Owner
    Deployer
    Due
    2 December 2027

    Article 26(1)-(2)

  2. Monitor operation, keep logs, and report serious incidents

    Suspend use and inform the provider where you have reason to consider that use in accordance with the instructions may present a risk. Keep logs for at least six months.

    Owner
    Deployer
    Due
    2 December 2027

    Article 26(5)-(6)Article 73

  3. Inform affected people

    Workers and their representatives must be informed before a high-risk system is put into use in the workplace. People subject to a decision informed by an Annex III system must be told the system was used.

    Owner
    HR and the business owner
    Due
    2 December 2027

    Article 26(7), 26(11)

  4. Complete a fundamental rights impact assessment where required

    Required for deployers that are public bodies, or private entities providing public services, and for certain creditworthiness and life or health insurance pricing uses.

    Owner
    Deployer, with legal
    Due
    2 December 2027
    Applies if
    You are a public body, provide public services, or score credit or insurance risk

    Article 27

Phase 6

Clear the route to market

The gate between a compliant build and lawful placing on the market. Which route applies depends on the classification route and on whether harmonised standards were applied.

  1. Determine the conformity assessment route

    Annex VI internal control, or Annex VII involving a notified body. For most Annex III systems internal control is available where harmonised standards were applied in full; biometrics is the notable exception.

    Owner
    Provider
    Due
    2 December 2027

    Article 43Conformity assessment guide

  2. Draw up the EU declaration of conformity and affix CE marking

    The declaration is kept for ten years after placing on the market and made available to authorities on request.

    Owner
    Provider
    Due
    2 December 2027

    Article 47Article 48Annex V

  3. Register in the EU database before placing on the market

    Applies to providers of Annex III high-risk systems, to those relying on the Article 6(3) derogation, and to certain public-authority deployers.

    Owner
    Provider
    Due
    2 December 2027

    Article 49Article 71

  4. Appoint an authorised representative in the Union

    Required for providers established outside the Union, by written mandate, before placing a high-risk system on the market.

    Owner
    Provider
    Due
    2 December 2027
    Applies if
    You are established outside the EU

    Article 22

Phase 7

Operate, monitor and keep it current

Compliance is a standing condition, not a launch milestone. These obligations run for as long as the system is on the market.

  1. Run post-market monitoring against a documented plan

    Proportionate to the nature and risks of the system: collect, document and analyse performance data across the lifetime, and feed it back into the risk management system.

    Owner
    Provider
    Due
    2 December 2027

    Article 72

  2. Establish a serious incident reporting path that meets the deadlines

    Report to the market surveillance authority of the Member State where the incident occurred. The deadlines are short and vary with the nature of the incident, so the path has to exist before it is needed.

    Owner
    Provider, with incident response
    Due
    2 December 2027

    Article 73

  3. Mark synthetic content in a machine-readable format

    Providers of generative systems must mark output as artificially generated or manipulated. Systems already on the market when the transparency rules began have until 2 December 2026 to comply.

    Owner
    Provider
    Due
    2 December 2026
    Applies if
    Your system generates synthetic audio, image, video or text

    Article 50(2)

  4. Take measures to support AI literacy, and record what you did

    Applies to every provider and deployer regardless of risk tier, and has since 2 February 2025. The Digital Omnibus softened this from ensuring a level of literacy to taking measures to support it, which changes what you should be recording, not whether you owe it.

    Owner
    HR and the business owner
    Due
    2 February 2025

    Article 4AI Literacy Program

  5. Re-check guidance published before 27 July 2026

    Regulation (EU) 2026/1744 changed deadlines, added two prohibitions, softened Article 4 and created new AI Office enforcement powers. Deadlines and prohibition counts in older material are likely to be wrong.

    Owner
    Whoever maintains your compliance documentation
    Due
    No fixed date

    Digital Omnibus changes

Work this as a document, not a web page

A checklist is only useful once each line has an owner and a date against it. We will send this as a working document you can assign and track, with the provision links intact.

Frequently asked questions

What is on an EU AI Act compliance checklist?

Seven phases in the order the work sequences: build an inventory of your AI systems and fix your role for each, screen against the ten Article 5 prohibitions, classify each system against both high-risk routes and the Article 50 transparency duties, build the Chapter III requirements for anything high-risk, meet the separate deployer duties, clear conformity assessment and registration, then operate post-market monitoring and incident reporting. AI literacy under Article 4 applies throughout, regardless of tier.

Where do I start with EU AI Act compliance?

With an inventory. Every obligation depends on facts about a specific system (its intended purpose, the role you hold for it, and whether it falls in an Annex III area) so scope cannot be assessed until you know what you hold. Organisations that start with the legal text rather than the inventory generally have to start again.

Do I need a checklist if none of my systems are high-risk?

Yes, for three reasons. The Article 5 prohibitions apply in every tier. The Article 50 transparency duties apply in every tier, and catch any system that interacts with people or generates synthetic content. And the Article 4 AI literacy duty applies to every provider and deployer regardless of risk. You also need documented reasoning for the conclusion that a system is not high-risk.

When does EU AI Act compliance need to be finished?

It depends which obligation. Prohibited practices and AI literacy have applied since 2 February 2025, general-purpose AI model obligations since 2 August 2025, and the transparency framework since 2 August 2026. Two further prohibitions and the legacy synthetic-content marking deadline fall on 2 December 2026. High-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products.

Who is responsible for EU AI Act compliance?

The Regulation places obligations on the organisation as an operator rather than on a named officer, so accountability follows your existing governance. In practice the inventory sits with technology risk, classification with legal, the Chapter III requirements with engineering and product, and the deployer duties with the business owner using the system.

Is a checklist enough to demonstrate compliance?

No. A checklist organises the work and shows what has been considered; it is not itself evidence. What a market surveillance authority asks for is the artefacts: the technical documentation to Annex IV, the risk management records, the logs, the declaration of conformity and the post-market monitoring data.