A compliance checklist is not a legal opinion, but it is the fastest way to identify gaps before engaging formal counsel or a compliance service provider. Work through these 30 items to understand your exposure. Items with an asterisk (*) require action before 2 August 2026 regardless of your system risk tier.
Part 1: AI inventory (items 1-8)
- * Catalogue all AI systems in useList every AI system your company uses internally or provides to customers. Include AI embedded in third-party software you purchase.
- * Include third-party and API-based AIMap every AI API you call. You may have obligations as a downstream deployer even if you do not train your own models.
- * Document the purpose of each systemWhat does it do? What decision does it inform or make? Who does that decision affect?
- * Identify your role for each systemAre you the provider (developed it) or deployer (uses it in a product)? The Act assigns different obligations to each role.
- Identify EU-facing systemsWhich of your AI systems produce outputs consumed by EU residents? These are in scope.
- Record training data sourcesFor systems you developed: where did the training data come from? Licensed? Scraped? Generated?
- Document model architecture and version historyRequired for technical documentation. Keep a record of model architecture, training approaches, and versions.
- Assign an internal owner for each systemAssign a named individual responsible for each system's ongoing compliance status.
Part 2: Risk classification (items 9-14)
- * Check each system against the Article 5 prohibited listDoes any system manipulate users subliminally, enable social scoring, or perform real-time biometric ID for law enforcement? These must be removed from EU-facing products immediately.
- Apply the Annex III high-risk testDoes any system make or substantially influence decisions in: credit scoring, employment, education, critical infrastructure, access to essential services, migration, or law enforcement?
- Apply the Annex II safety-component testIs any AI component embedded in a product already governed by EU product safety law?
- * Identify GPAI models in your stackDo you provide or use a general-purpose AI model? GPAI obligations applied from 2 August 2025.
- * Identify Article 50 transparency obligationsDoes any customer-facing product use a chatbot, virtual assistant, or emotion-recognition system? Disclosure is required by 2 August 2026.
- Document your classification rationaleWrite a brief rationale for each system's risk classification. This is part of technical documentation.
Part 3: GPAI obligations (items 15-18)
- Draft technical documentation per Article 53Includes model architecture, training methodology, training data description, capabilities, and limitations.
- Publish a training data transparency summaryA publicly available summary of what data the model was trained on, sufficient for downstream deployers to understand potential bias.
- Ensure EU copyright complianceVerify training data use complies with the EU Directive on Copyright in the Digital Single Market, including the text-and-data mining exception.
- Register the model in the EU AI databaseGPAI models must be registered before being made available. Models crossing the systemic risk threshold face additional adversarial testing requirements.
Part 4: Article 50 transparency (items 19-22)
- * Add AI disclosure to all chatbots and virtual assistantsEvery conversational AI interface that EU users interact with must identify itself as AI in real time.
- * Label AI-generated images, video, and audioSynthetic media your product generates must be machine-readable marked as AI-generated.
- * Add disclosure to emotion-recognition systemsUsers must be notified that they are interacting with emotion-recognition or biometric categorization systems.
- Audit AI content pipelines for public-interest labelingAI-generated text about matters of public interest distributed at scale must carry machine-readable AI attribution.
Part 5: High-risk AI obligations (items 23-30)
- Commission a conformity assessmentHigh-risk Annex III systems require a conformity assessment before deployment. Most categories allow self-assessment.
- Draft technical documentation per Annex IVA detailed technical file including system description, development process, training data, and accuracy metrics.
- Implement human oversight measuresHigh-risk systems must be designed so a human can understand and override the system output.
- Implement automatic loggingHigh-risk AI systems must generate and retain logs sufficient for post-hoc review by national authorities.
- Conduct bias and accuracy testing across subgroupsTest for performance differences across demographic groups and document the methodology and results.
- Register the system in the EU AI databaseHigh-risk Annex III systems must be registered before deployment.
- Appoint an EU representative if based outside the EUNon-EU providers of high-risk systems must designate an authorized representative established in the EU.
- Establish post-market monitoringImplement a process for ongoing monitoring of your high-risk system in production, including incident reporting.
Need help working through this for your specific systems? Better Societies runs a structured 6-week compliance engagement that takes you from inventory through to a signed compliance declaration. See the compliance offer.