Compyl
GRC Your Way

EU AI Act Compliance Checklist: 10 Steps for 2026

Last updated: August 27, 2026

EU AI Act compliance comes down to ten steps: inventory your AI systems, decide whether you are a provider or a deployer for each one, screen everything against the Article 5 prohibitions, classify systems against Annex I and Annex III, deliver AI literacy training, meet the Article 50 transparency duties, build a risk management process for high-risk systems, fix data governance and technical documentation, design human oversight and logging, and re-paper your vendor contracts. Article 5, AI literacy, general purpose AI rules and the transparency obligations are already in force. The standalone high-risk requirements now bite on December 2, 2027.

This post is part of our AI governance guide. For background on what the law asks of GRC teams, see our overview of EU AI Act compliance.

Key takeaways

  • Start with an inventory. Every other step depends on knowing which AI systems exist and who owns them.
  • Your role matters as much as the system. Provider obligations are far heavier than deployer obligations.
  • Article 5 screening is urgent, not future work. Prohibitions have applied since February 2, 2025 and carry the highest fines.
  • Article 50 transparency duties apply from August 2, 2026 and are the cheapest gap to close.
  • The Digital Omnibus moved standalone Annex III high-risk obligations to December 2, 2027 and Annex I embedded AI to August 2, 2028. It bought time, not a reprieve.
  • Most of the work is evidence: dated assessments, decision records and supplier documentation that survive a regulator’s request.

What does EU AI Act compliance actually require?

The AI Act is a product safety law wearing the clothes of a digital regulation. It does not ask whether your AI is good. It asks whether you can show that a specific system, in a specific use, was assessed, controlled, documented and supervised by a named human. That framing explains why the checklist below is dominated by records rather than model engineering.

Obligations attach to the role you play and the risk tier of the system. A company can be a deployer of one system and the provider of another, sometimes for the same underlying model. Our guide on who the EU AI Act applies to covers the scope and role questions in more detail.

The EU AI Act compliance checklist

1. Build a live AI system inventory

List every AI system built, bought or embedded in a product you sell, including features inside SaaS tools your teams already use. Capture the owner, the purpose, the data it touches, the population affected and the supplier. An inventory that is refreshed quarterly and tied to procurement is worth far more than a one-time spreadsheet, because shadow AI is where unassessed risk accumulates.

2. Determine your role for each system

Provider, deployer, importer, distributor or authorised representative. The obligations differ sharply, and the role can flip: substantially modifying a third-party high-risk system, or putting your own name on it, can make you the provider with the full documentation and conformity assessment burden.

3. Screen everything against Article 5

The prohibited practices include social scoring, untargeted scraping of facial images to build recognition databases, emotion inference in the workplace and in education outside narrow safety and medical exceptions, and manipulative or exploitative techniques that cause significant harm. This screen is the highest priority item on the list because prohibitions have applied since February 2, 2025 and carry the top penalty tier. See our breakdown of EU AI Act penalties for what that exposure looks like.

4. Classify against Annex I and Annex III

Annex I covers AI embedded in products already regulated under EU product safety law. Annex III covers standalone use cases such as biometrics, critical infrastructure, education, employment and worker management, access to essential services including credit scoring and insurance pricing, law enforcement, migration and the administration of justice. Document the reasoning for each classification, including the ones you decide are not high risk, and have an accountable owner sign it. Our guide to the EU AI Act high-risk categories walks through the Annex III list.

5. Deliver AI literacy

Article 4 requires providers and deployers to take measures ensuring a sufficient level of AI literacy among staff and others operating AI systems on their behalf, taking into account their technical knowledge and the context of use. This has applied since February 2, 2025. Role-based training with attendance records is the practical answer, not a single all-hands session.

6. Close the Article 50 transparency gaps

From August 2, 2026, people must be told when they are interacting with an AI system unless it is obvious, synthetic audio, image, video and text must be marked in a machine readable format, deepfakes must be disclosed, and emotion recognition or biometric categorisation must be disclosed to the people subject to it. These are usually interface and metadata changes rather than architectural ones, which makes them the fastest wins on the list.

7. Stand up risk management for high-risk systems

High-risk systems need a continuous risk management process that runs across the lifecycle: identify foreseeable risks to health, safety and fundamental rights, estimate them under intended use and reasonably foreseeable misuse, adopt mitigations, and test against defined metrics before deployment and after changes. Continuous is the operative word. A single pre-launch assessment does not satisfy it.

8. Fix data governance and technical documentation

Training, validation and testing data need governance covering provenance, collection, preparation, assumptions, bias examination and mitigation, and gaps that could affect the intended purpose. Technical documentation must be complete before the system goes on the market and kept current, and it is what a notified body or authority will ask for first.

9. Design human oversight and logging

Oversight has to be effective, meaning the named person can understand the system’s limits, interpret its output, decide not to use it and stop it. Automation bias is explicitly a design consideration. Alongside this, high-risk systems must log events automatically over their lifetime so that a decision can be reconstructed later. Retention and access rules should be set now, not after an incident.

10. Re-paper vendor and supplier contracts

If someone else’s model sits inside your product or process, their documentation gaps become yours. Update procurement questionnaires and contracts to require intended purpose statements, technical documentation, data governance evidence, incident notification, and cooperation with authorities. Add a clause covering material model changes, because a silent upgrade can invalidate your testing.

Which deadlines does this checklist have to hit?

DateWhat appliesChecklist steps
February 2, 2025Prohibited practices (Article 5) and AI literacy (Article 4)1, 3, 5
August 2, 2025General purpose AI model obligations, governance structures and the penalty framework2, 10
August 2, 2026Transparency obligations (Article 50) and Commission enforcement powers over general purpose AI models6, 10
December 2, 2027Standalone high-risk systems under Annex III, deferred by the Digital Omnibus4, 7, 8, 9
August 2, 2028AI embedded in regulated products under Annex I4, 7, 8, 9

The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on July 27, 2026 and moved the high-risk dates. For the full sequence and what changed, see our EU AI Act compliance timeline.

What does good evidence look like?

Regulators will not accept a policy document as proof that a control operates. For each system, aim to hold a dated classification memo with a named approver, a risk assessment that shows what was tested and what changed as a result, oversight records showing humans actually intervened, supplier documentation on file, and a log retention configuration you can demonstrate. If any of those live only in someone’s inbox, treat that as a finding.

The overlap between this checklist and a formal AI management system is close to total. Running one certifiable framework rather than a separate control set per regulation is what keeps this sustainable as more AI rules arrive. Our guide to ISO 42001 covers what the standard requires, and Compyl automates the collection of the evidence behind it so your AI Act readiness is a by-product of how the program already runs.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. It reaches providers placing AI systems on the EU market regardless of where they are established, and providers and deployers outside the EU where the output produced by the system is used in the EU.

Do I need a conformity assessment?

Only for high-risk systems. Most Annex III systems allow an internal conformity assessment by the provider, while certain biometric use cases and Annex I products require involvement from a notified body. Deployers do not run conformity assessments, though some public bodies and providers of certain services must complete a fundamental rights impact assessment.

Did the Digital Omnibus remove any obligations?

It deferred application dates for high-risk systems and adjusted parts of the framework, but the substantive requirements and the fine levels are materially unchanged. Treat the extra time as schedule relief, not scope relief.

What if we only use AI tools we bought?

You are a deployer, which is a lighter but real set of obligations: use the system according to its intended purpose and instructions, assign competent human oversight, keep logs where you control them, inform affected workers where relevant, and cooperate with authorities. You also inherit the Article 5 prohibition and Article 50 transparency duties.

How long does EU AI Act readiness take?

For an organisation with a handful of deployed systems and no high-risk exposure, the inventory, screening, literacy and transparency work is typically a matter of weeks. For a provider of a high-risk system, the documentation, testing and conformity work is usually measured in quarters, which is why the December 2027 date is tighter than it looks.

Can ISO 42001 certification prove EU AI Act compliance?

Not on its own. Certification is not a legal presumption of conformity, and harmonised standards under the Act are still being finalised. It does, however, cover most of the governance, risk and documentation machinery the Act expects, so it substantially shortens the remaining gap.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies