EU AI Act Compliance Checklist Template

Most organisations run AI they never consciously bought: a screening feature in the recruitment platform, a chatbot on the website, a model wired into the product. The AI Act starts by asking you to name each one, your role for it and its risk tier.

This free EU AI Act compliance checklist is for AI governance leads, compliance teams and product owners in organisations that build, buy or use AI in the EU, or whose AI output is used there. It runs the programme once a year: inventory and roles, prohibitions and classification, AI literacy and transparency, then only the provider, deployer and general-purpose AI model duties your answers switch on. The result is a signed classification register and a gap list dated against the high-risk deadlines.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: October 2026

Your Role and Your Risk Tier Decide the Work

Regulation (EU) 2024/1689, the AI Act, sorts AI by risk. A short list of practices is banned (Article 5). High-risk systems, meaning safety components of regulated products (Annex I) or uses listed in Annex III such as recruitment and credit scoring, carry most of the requirements. Chatbots and generative systems carry transparency duties (Article 50). The rest need only AI literacy (Article 4). General-purpose AI models have their own chapter (Articles 51 to 56).

Obligations attach to your role for each system, not to the organisation. An insurer can be the provider of a pricing model it built, the deployer of a recruitment tool it bought, and owe nothing specific for its spam filter. So the checklist records a role for every inventory entry before it classifies anything.

Provider (Art. 3(3))

Builds the system or has it built

Who: develops an AI system, or has one developed, and places it on the market or puts it into service under its own name, paid or free.

High-risk duties: Articles 9 to 17, conformity assessment, registration and post-market monitoring.

Output: technical documentation, an EU declaration of conformity and CE marking.

Deployer (Art. 3(4))

Uses the system under its authority

Who: anyone using an AI system under its authority, except in a personal, non-professional activity.

High-risk duties: Article 26: use as instructed, human oversight, input data, monitoring, logs and notices.

Output: oversight assignments, retained logs and, for some deployers, a fundamental rights impact assessment (FRIA, Article 27).

Digital Omnibus on AI, in force 27 July 2026

The high-risk dates moved; transparency did not

Regulation (EU) 2026/1744, published on 24 July 2026, moved the high-risk rules in Chapter III, Sections 1 to 3, from 2 August 2026 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Article 50 kept its 2 August 2026 start. Article 4 now asks for measures to support AI literacy rather than a sufficient level of it. It also added two prohibitions, extended SME relief to small mid-cap enterprises (SMCs) and let a FRIA cross-refer to an existing DPIA.

This checklist covers the regulation itself. Certifying an AI management system has its own ISO 42001 checklist, and a GDPR Article 35 assessment its own DPIA checklist. Both feed this programme; neither replaces it.

What the EU AI Act Compliance Checklist Covers

Four phases apply to everyone; Phases 4 to 6 appear only where your answers call for them. Article numbers reflect the 2026 amendments.

Phase 1

Phase 1: Scope, Inventory & Roles

The first task asks whether you provide a general-purpose AI model, which decides whether Phase 6 appears.

  • Set the scope and name the AI governance lead — entities, review period, and the executive sponsor who signs off the year
  • Build the AI system inventory — systems in use, in development or being bought, including AI features inside existing SaaS tools
  • Test each entry against the AI system definition (Art. 3(1)) — using the Commission’s February 2025 guidelines
  • Record our role for each system — provider, deployer, importer, distributor or product manufacturer; non-EU organisations are in scope where output is used in the EU (Art. 2)
  • Check whether anything makes us a provider (Art. 25(1)) — our name on a high-risk system, a substantial modification, or a new high-risk purpose
Phase 2

Phase 2: Prohibitions & Risk Classification

The sign-off asks whether you provide or deploy any high-risk system. The answers show or hide Phases 4 and 5.

  • Screen every system against the Article 5 prohibitions — eight since 2 February 2025, two more from 2 December 2026; stop use and escalate any match
  • Check each system against Annex I (Art. 6(1)) — a safety component of, or itself, a product needing third-party conformity assessment
  • Check each system against the eight Annex III areas (Art. 6(2)) — from biometrics and employment to essential services, migration and justice
  • Document any Article 6(3) exemption claimed as provider — narrow or preparatory tasks only, never where the system profiles people; register it (Art. 49(2))
  • Flag systems with Article 50 transparency duties — chatbots and agents, generative output, emotion recognition and deepfakes
  • Sign off the classification register — approval by the AI governance lead, with tier, role and reasoning for each system
Phase 3

Phase 3: AI Literacy & Transparency

Generative systems on the market before 2 August 2026 have until 2 December 2026 to mark their output (Art. 111(4)).

  • Map who operates or uses AI on our behalf (Art. 4) — staff, contractors and service providers
  • Deliver AI literacy measures matched to each role — reflecting technical knowledge, context and the people affected; keep an internal record
  • Tell people when they are interacting with AI (Art. 50(1)) — a provider duty for chatbots and voice agents, unless it is obvious
  • Mark synthetic audio, image, video and text output (Art. 50(2)) — providers, in a machine-readable form detectable as AI-generated
  • Give the deployer notices under Art. 50(3) and 50(4) — emotion recognition, biometric categorisation, deepfakes, and public-interest text without editorial review
  • Record our position on the transparency Code of Practice — final June 2026, voluntary, assessed as adequate by the Commission
Phase 4

Phase 4: High-Risk Provider Duties

Shown only for providers of a high-risk system. Applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I).

  • Run a risk management system across the lifecycle (Art. 9) — foreseeable risks and misuse, residual risk, testing
  • Govern training, validation and test data (Art. 10) — representativeness and bias checks; special category data only under Art. 4a
  • Draw up the technical documentation and instructions for use (Arts. 11, 13) — Annex IV content, kept 10 years (Art. 18); SMEs and SMCs may use a simplified form
  • Build in logging, human oversight and accuracy controls (Arts. 12, 14, 15) — event logs, oversight a deployer can exercise, robustness and cybersecurity
  • Operate a quality management system (Art. 17) — proportionate to size; EN 18286:2026 is the European standard written for it
  • Complete conformity assessment, declaration, CE marking and registration — internal control for Annex III points 2–8 (Art. 43(2)), then Arts. 47–49
  • Monitor after market and report serious incidents (Arts. 72, 73) — within 15 days, 10 for a death, 2 for widespread or critical infrastructure incidents
Phase 5

Phase 5: Deployer Duties & FRIA

Shown only for deployers of a high-risk system. The first task decides whether the FRIA task appears.

  • Check whether Article 27 requires a FRIA — public bodies, private providers of public services, and credit scoring or life and health insurance pricing
  • Use each system as instructed and assign human oversight (Art. 26(1)–(2)) — named people with the competence and authority to intervene
  • Monitor operation and keep logs for at least six months (Art. 26(5)–(6)) — suspend use and tell the provider and authority if a system presents a risk
  • Inform workers’ representatives and affected people (Art. 26(7), (11)) — before workplace use, and when a system helps decide about someone
  • Complete the FRIA before first use and notify the authority (Art. 27) — cross-refer to the DPIA where it covers a point; approval by the AI governance lead
Phase 6

Phase 6: General-Purpose AI Models

Shown only for GPAI model providers. Applies since 2 August 2025; earlier models have until 2 August 2027.

  • Confirm the model is a GPAI model and that we are its provider — the July 2025 guidelines use training compute above 1023 FLOP as an indicator
  • Draw up model documentation for the AI Office and downstream providers — Annexes XI and XII (Art. 53(1)(a)–(b)); limited open-source exemption
  • Adopt a copyright policy and publish the training content summary — respecting text and data mining opt-outs; summary on the AI Office template (Art. 53(1)(c)–(d))
  • Assess systemic risk and notify within two weeks (Arts. 51, 52) — presumed above 1025 FLOP, bringing the Art. 55 duties
  • Record our position on the General-Purpose AI Code of Practice — published 10 July 2025: transparency, copyright, safety and security
Phase 7

Phase 7: Remediate, Report & Review

Runs every year, and early after a new AI purchase, a model change or a new use for an existing system.

  • Log every gap with an owner and a due date — working back from 2 December 2027 or 2 August 2028, not from the next review
  • Check guidance and standards issued since the last review — the final Article 6 guidelines, standards cited in the Official Journal, AI Office templates
  • Report the programme to the executive sponsor — inventory changes, tiers, gaps and incidents; approval by the executive sponsor
  • Archive the evidence and schedule the next review — and route new AI purchases through Phase 2 before signature

EU AI Act Dates After the Digital Omnibus

The dates come from Articles 111 and 113 as amended by Regulation (EU) 2026/1744. Which ones bind you depends on your role and systems, so treat the timeline as a starting point, not legal advice.

1 August 2024

Entry into force

Published in the Official Journal on 12 July 2024.

2 February 2025

Prohibitions and AI literacy

Articles 4 and 5 apply. Commission guidelines on prohibited practices and on the AI system definition followed on 4 and 6 February.

2 August 2025

GPAI models, governance and penalties

GPAI provider obligations apply, with the governance chapter and penalty rules.

2 August 2026

General date of application

Article 50 applies, national authorities begin supervising and enforcing, and the Commission can fine GPAI providers (Article 101).

2 December 2026

New prohibitions; marking grace period ends

AI that generates non-consensual intimate imagery of identifiable people, or child sexual abuse material, is banned. Older generative systems must mark output.

2 August 2027

Earlier GPAI models; sandboxes

GPAI models placed on the market before 2 August 2025 must comply, and each Member State must have an AI regulatory sandbox running.

2 December 2027

Annex III high-risk systems

Chapter III, Sections 1 to 3, apply, including deployer duties and the FRIA. A system type already on the market is caught only if its design changes significantly.

2 August 2028

Annex I high-risk systems

The same sections apply to AI in products under Annex I legislation.

2 August 2030

High-risk systems used by public authorities

These must comply even if placed on the market earlier.

Some pieces are still moving. The Commission published draft high-risk classification guidelines on 19 May 2026 and had not adopted them at the time of review. CEN and CENELEC approved EN 18286:2026 in July 2026, but no AI Act standard had been cited in the Official Journal at the time of review, so none yet gives a presumption of conformity. This page summarises the regulation and is not legal advice.

Why Run Your AI Act Programme in CheckFlow?

1

An inventory that survives the year

Keep the AI system register as a data set with owner, role and tier per entry, so every annual run starts from the current list.

2

Branches for provider, deployer and GPAI

Conditional logic shows the provider, deployer, FRIA and GPAI tasks only where your answers call for them. A business that only buys AI never sees Article 9; a high-risk provider cannot skip it.

3

Decisions with a name and a date

Classification sign-off, the FRIA and the annual report run as approvals assigned to the people named on the first task. The activity trail shows who decided what and when, and template versioning ties each year to the checklist it used.

CheckFlow is not a GRC platform, a notified body or a legal adviser, and it does not classify AI systems for you. It runs the cycle, deadlines and sign-offs around the judgements your team and advisers make. CheckFlow’s compliance checklist software shows the same approach across your wider compliance calendar.

If an AI assistant works in your checklists through the CheckFlow MCP server, list it in the inventory too: it acts through an API key bound to a named actor, and the activity trail records every change it makes. For the management system underneath, use the ISO 42001 AI Management System Checklist; for personal data, the GDPR Compliance Audit Checklist; and for AI vendors, the Vendor Risk Assessment Checklist.

Frequently Asked Questions

When do the EU AI Act high-risk obligations apply?

+

From 2 December 2027 for Annex III uses and 2 August 2028 for AI in Annex I products. The Commission’s November 2025 Omnibus proposal would have tied the start to the availability of standards, with those dates as the latest; the adopted text simply fixes them. A system type already on the market is caught only after a significant design change, but systems intended for public authorities must comply by 2 August 2030.

Did the Digital Omnibus remove the AI literacy requirement?

+

No, it softened it. Providers and deployers must still take measures to support the AI literacy of people who operate or use AI on their behalf, but need not guarantee any particular level. The Commission’s Q&A says no certificate is needed; an internal record of training is enough. High-risk deployers still need trained people for human oversight (Article 26(2)).

Do we become the provider if we rebrand or modify someone else’s AI system?

+

For high-risk systems, in three cases under Article 25(1): you put your name or trademark on it, you substantially modify it, or you change an AI system’s intended purpose so it becomes high-risk. The original provider must then cooperate and share documentation. For GPAI models, the Commission’s guidelines treat a modifier as a provider when the modification uses more than a third of the original training compute.

What are the fines under the EU AI Act?

+

Under Article 99, up to €35 million or 7% of worldwide annual turnover for a prohibited practice, €15 million or 3% for most other breaches, and €7.5 million or 1% for misleading information to authorities, whichever is higher. SMEs get the lower of the two, and the Omnibus extended that to SMCs for the last two tiers. The Commission fines GPAI providers up to €15 million or 3% (Article 101).

Does ISO 42001 certification prove EU AI Act compliance?

+

No. ISO/IEC 42001 is not a harmonised standard under the AI Act, so certification gives no presumption of conformity, though it is good evidence of governance. The standard written for the Act’s quality management requirement is EN 18286:2026, not yet cited in the Official Journal at the time of review.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Every AI System Named, Classified and Signed Off

Free trial — no credit card required.