An inventory that survives the year
Keep the AI system register as a data set with owner, role and tier per entry, so every annual run starts from the current list.
This free EU AI Act compliance checklist is for AI governance leads, compliance teams and product owners in organisations that build, buy or use AI in the EU, or whose AI output is used there. It runs the programme once a year: inventory and roles, prohibitions and classification, AI literacy and transparency, then only the provider, deployer and general-purpose AI model duties your answers switch on. The result is a signed classification register and a gap list dated against the high-risk deadlines.
Regulation (EU) 2024/1689, the AI Act, sorts AI by risk. A short list of practices is banned (Article 5). High-risk systems, meaning safety components of regulated products (Annex I) or uses listed in Annex III such as recruitment and credit scoring, carry most of the requirements. Chatbots and generative systems carry transparency duties (Article 50). The rest need only AI literacy (Article 4). General-purpose AI models have their own chapter (Articles 51 to 56).
Obligations attach to your role for each system, not to the organisation. An insurer can be the provider of a pricing model it built, the deployer of a recruitment tool it bought, and owe nothing specific for its spam filter. So the checklist records a role for every inventory entry before it classifies anything.
Who: develops an AI system, or has one developed, and places it on the market or puts it into service under its own name, paid or free.
High-risk duties: Articles 9 to 17, conformity assessment, registration and post-market monitoring.
Output: technical documentation, an EU declaration of conformity and CE marking.
Who: anyone using an AI system under its authority, except in a personal, non-professional activity.
High-risk duties: Article 26: use as instructed, human oversight, input data, monitoring, logs and notices.
Output: oversight assignments, retained logs and, for some deployers, a fundamental rights impact assessment (FRIA, Article 27).
Regulation (EU) 2026/1744, published on 24 July 2026, moved the high-risk rules in Chapter III, Sections 1 to 3, from 2 August 2026 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Article 50 kept its 2 August 2026 start. Article 4 now asks for measures to support AI literacy rather than a sufficient level of it. It also added two prohibitions, extended SME relief to small mid-cap enterprises (SMCs) and let a FRIA cross-refer to an existing DPIA.
This checklist covers the regulation itself. Certifying an AI management system has its own ISO 42001 checklist, and a GDPR Article 35 assessment its own DPIA checklist. Both feed this programme; neither replaces it.
Four phases apply to everyone; Phases 4 to 6 appear only where your answers call for them. Article numbers reflect the 2026 amendments.
The first task asks whether you provide a general-purpose AI model, which decides whether Phase 6 appears.
The sign-off asks whether you provide or deploy any high-risk system. The answers show or hide Phases 4 and 5.
Generative systems on the market before 2 August 2026 have until 2 December 2026 to mark their output (Art. 111(4)).
Shown only for providers of a high-risk system. Applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I).
Shown only for deployers of a high-risk system. The first task decides whether the FRIA task appears.
Shown only for GPAI model providers. Applies since 2 August 2025; earlier models have until 2 August 2027.
Runs every year, and early after a new AI purchase, a model change or a new use for an existing system.
The dates come from Articles 111 and 113 as amended by Regulation (EU) 2026/1744. Which ones bind you depends on your role and systems, so treat the timeline as a starting point, not legal advice.
Published in the Official Journal on 12 July 2024.
Articles 4 and 5 apply. Commission guidelines on prohibited practices and on the AI system definition followed on 4 and 6 February.
GPAI provider obligations apply, with the governance chapter and penalty rules.
Article 50 applies, national authorities begin supervising and enforcing, and the Commission can fine GPAI providers (Article 101).
AI that generates non-consensual intimate imagery of identifiable people, or child sexual abuse material, is banned. Older generative systems must mark output.
GPAI models placed on the market before 2 August 2025 must comply, and each Member State must have an AI regulatory sandbox running.
Chapter III, Sections 1 to 3, apply, including deployer duties and the FRIA. A system type already on the market is caught only if its design changes significantly.
The same sections apply to AI in products under Annex I legislation.
These must comply even if placed on the market earlier.
Some pieces are still moving. The Commission published draft high-risk classification guidelines on 19 May 2026 and had not adopted them at the time of review. CEN and CENELEC approved EN 18286:2026 in July 2026, but no AI Act standard had been cited in the Official Journal at the time of review, so none yet gives a presumption of conformity. This page summarises the regulation and is not legal advice.
Keep the AI system register as a data set with owner, role and tier per entry, so every annual run starts from the current list.
Conditional logic shows the provider, deployer, FRIA and GPAI tasks only where your answers call for them. A business that only buys AI never sees Article 9; a high-risk provider cannot skip it.
Classification sign-off, the FRIA and the annual report run as approvals assigned to the people named on the first task. The activity trail shows who decided what and when, and template versioning ties each year to the checklist it used.
CheckFlow is not a GRC platform, a notified body or a legal adviser, and it does not classify AI systems for you. It runs the cycle, deadlines and sign-offs around the judgements your team and advisers make. CheckFlow’s compliance checklist software shows the same approach across your wider compliance calendar.
If an AI assistant works in your checklists through the CheckFlow MCP server, list it in the inventory too: it acts through an API key bound to a named actor, and the activity trail records every change it makes. For the management system underneath, use the ISO 42001 AI Management System Checklist; for personal data, the GDPR Compliance Audit Checklist; and for AI vendors, the Vendor Risk Assessment Checklist.
From 2 December 2027 for Annex III uses and 2 August 2028 for AI in Annex I products. The Commission’s November 2025 Omnibus proposal would have tied the start to the availability of standards, with those dates as the latest; the adopted text simply fixes them. A system type already on the market is caught only after a significant design change, but systems intended for public authorities must comply by 2 August 2030.
No, it softened it. Providers and deployers must still take measures to support the AI literacy of people who operate or use AI on their behalf, but need not guarantee any particular level. The Commission’s Q&A says no certificate is needed; an internal record of training is enough. High-risk deployers still need trained people for human oversight (Article 26(2)).
For high-risk systems, in three cases under Article 25(1): you put your name or trademark on it, you substantially modify it, or you change an AI system’s intended purpose so it becomes high-risk. The original provider must then cooperate and share documentation. For GPAI models, the Commission’s guidelines treat a modifier as a provider when the modification uses more than a third of the original training compute.
Under Article 99, up to €35 million or 7% of worldwide annual turnover for a prohibited practice, €15 million or 3% for most other breaches, and €7.5 million or 1% for misleading information to authorities, whichever is higher. SMEs get the lower of the two, and the Omnibus extended that to SMCs for the last two tiers. The Commission fines GPAI providers up to €15 million or 3% (Article 101).
No. ISO/IEC 42001 is not a harmonised standard under the AI Act, so certification gives no presumption of conformity, though it is good evidence of governance. The standard written for the Act’s quality management requirement is EN 18286:2026, not yet cited in the Official Journal at the time of review.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.