EU AI Act

EU AI Act Compliance Checklist: 30 Items Before August 2026

Most EU AI Act guides tell you what the law says. This one tells you what to do, in order, so you don't miss a deadline or leave a gap that becomes a fine. Work through these 30 items before 2 August 2026 to cover the obligations that apply to most companies in scope.

← Back to EU AI Act Complete Guide

A compliance checklist is not a legal opinion, but it is the fastest way to identify gaps before engaging formal counsel or a compliance service provider. Work through these 30 items to understand your exposure. Items with an asterisk (*) require action before 2 August 2026 regardless of your system risk tier.

Part 1: AI inventory (items 1-8)

Foundation
  1. * Catalogue all AI systems in useList every AI system your company uses internally or provides to customers. Include AI embedded in third-party software you purchase.
  2. * Include third-party and API-based AIMap every AI API you call. You may have obligations as a downstream deployer even if you do not train your own models.
  3. * Document the purpose of each systemWhat does it do? What decision does it inform or make? Who does that decision affect?
  4. * Identify your role for each systemAre you the provider (developed it) or deployer (uses it in a product)? The Act assigns different obligations to each role.
  5. Identify EU-facing systemsWhich of your AI systems produce outputs consumed by EU residents? These are in scope.
  6. Record training data sourcesFor systems you developed: where did the training data come from? Licensed? Scraped? Generated?
  7. Document model architecture and version historyRequired for technical documentation. Keep a record of model architecture, training approaches, and versions.
  8. Assign an internal owner for each systemAssign a named individual responsible for each system's ongoing compliance status.

Part 2: Risk classification (items 9-14)

Classification
  1. * Check each system against the Article 5 prohibited listDoes any system manipulate users subliminally, enable social scoring, or perform real-time biometric ID for law enforcement? These must be removed from EU-facing products immediately.
  2. Apply the Annex III high-risk testDoes any system make or substantially influence decisions in: credit scoring, employment, education, critical infrastructure, access to essential services, migration, or law enforcement?
  3. Apply the Annex II safety-component testIs any AI component embedded in a product already governed by EU product safety law?
  4. * Identify GPAI models in your stackDo you provide or use a general-purpose AI model? GPAI obligations applied from 2 August 2025.
  5. * Identify Article 50 transparency obligationsDoes any customer-facing product use a chatbot, virtual assistant, or emotion-recognition system? Disclosure is required by 2 August 2026.
  6. Document your classification rationaleWrite a brief rationale for each system's risk classification. This is part of technical documentation.

Part 3: GPAI obligations (items 15-18)

GPAI
  1. Draft technical documentation per Article 53Includes model architecture, training methodology, training data description, capabilities, and limitations.
  2. Publish a training data transparency summaryA publicly available summary of what data the model was trained on, sufficient for downstream deployers to understand potential bias.
  3. Ensure EU copyright complianceVerify training data use complies with the EU Directive on Copyright in the Digital Single Market, including the text-and-data mining exception.
  4. Register the model in the EU AI databaseGPAI models must be registered before being made available. Models crossing the systemic risk threshold face additional adversarial testing requirements.

Part 4: Article 50 transparency (items 19-22)

Transparency
  1. * Add AI disclosure to all chatbots and virtual assistantsEvery conversational AI interface that EU users interact with must identify itself as AI in real time.
  2. * Label AI-generated images, video, and audioSynthetic media your product generates must be machine-readable marked as AI-generated.
  3. * Add disclosure to emotion-recognition systemsUsers must be notified that they are interacting with emotion-recognition or biometric categorization systems.
  4. Audit AI content pipelines for public-interest labelingAI-generated text about matters of public interest distributed at scale must carry machine-readable AI attribution.

Part 5: High-risk AI obligations (items 23-30)

High-risk
  1. Commission a conformity assessmentHigh-risk Annex III systems require a conformity assessment before deployment. Most categories allow self-assessment.
  2. Draft technical documentation per Annex IVA detailed technical file including system description, development process, training data, and accuracy metrics.
  3. Implement human oversight measuresHigh-risk systems must be designed so a human can understand and override the system output.
  4. Implement automatic loggingHigh-risk AI systems must generate and retain logs sufficient for post-hoc review by national authorities.
  5. Conduct bias and accuracy testing across subgroupsTest for performance differences across demographic groups and document the methodology and results.
  6. Register the system in the EU AI databaseHigh-risk Annex III systems must be registered before deployment.
  7. Appoint an EU representative if based outside the EUNon-EU providers of high-risk systems must designate an authorized representative established in the EU.
  8. Establish post-market monitoringImplement a process for ongoing monitoring of your high-risk system in production, including incident reporting.

Need help working through this for your specific systems? Better Societies runs a structured 6-week compliance engagement that takes you from inventory through to a signed compliance declaration. See the compliance offer.

Related reading

Frequently asked questions

What is the first step to EU AI Act compliance?

The first step is an AI inventory: catalogue every AI system your company uses or provides. Include third-party AI tools you integrate into your products.

Do I need a lawyer to do EU AI Act compliance?

Not for the initial inventory and classification steps. Legal counsel becomes important for drafting conformity declarations. Compliance service providers like Better Societies manage the full process for a fixed price.

What does EU AI Act compliance cost?

Costs vary by company size. A small company might complete compliance work for EUR 5,000 to EUR 15,000. Better Societies offers a fixed-price 6-week engagement for AI and fintech companies.

Get compliant in 6 weeks

Better Societies delivers a full EU AI Act compliance assessment, documentation package, and signed compliance declaration. Fixed price, no retainers.