A practical step-by-step EU AI Act compliance checklist with sector-specific guidance. Assess your AI systems against scope, risk classification, prohibited practices, GPAI obligations, and high-risk AI requirements. Updated for 2026 omnibus deadlines.

How to assess your EU AI Act compliance: 10 steps

Interactive tool: Use the AI Act Compliance Checker to get a personalised checklist and compliance score for your specific role and AI system type.

This checklist is designed for legal, compliance, and technology teams conducting an initial AI Act assessment. Work through the steps in sequence — each builds on the previous.

The checklist applies to all organisations that develop, deploy, import, or distribute AI systems in the EU. It covers all risk tiers, from prohibited practice checks through full high-risk conformity.

Step 1 — Build your AI inventory

Start here: without a complete AI inventory, nothing else is possible. Create a register of every AI system your organisation touches:

For each: document the system name, function, data inputs and outputs, use context, decision impact, and affected population. Flag systems where you are uncertain of classification — these need legal review.

Step 2 — Check prohibited practices first

Priority check: are any systems already illegal? Assess each system against Art. 5 before any risk tier classification. If any system:

Decommission or fundamentally redesign immediately. These prohibitions apply since 2 February 2025.

Step 3 — GPAI model check

If your organisation develops and releases a foundation model or large-scale AI model, GPAI obligations under Chapter 5 apply. Check:

If yes → GPAI provider obligations since 2 August 2025. If training compute exceeds 10²⁵ FLOPs → systemic risk obligations.

Steps 4–10 — High-risk AI compliance programme

For each system not excluded by Step 2 and not covered by Step 3, classify against Annex III and Annex I. Then follow Steps 4–10 as a programme track, targeting the 2 December 2027 deadline for Annex III systems and 2 August 2028 for Annex I embedded systems.

Do not wait until 2027. A realistic compliance programme for one high-risk AI system takes 12–24 months. Begin the gap assessment and QMS design in 2026 to avoid a last-minute crunch — and to avoid the capacity bottleneck at notified bodies as December 2027 approaches.

Cross-regulation mapping

If your organisation is also subject to DORA or NIS2, your AI Act compliance programme can be integrated with existing ICT risk management, incident response, and third-party governance frameworks. See our AI Act vs DORA vs NIS2 convergence guide → for dual-mapping templates.

Sector-specific compliance considerations

Financial services (DORA overlap)

Financial entities subject to DORA already operate ICT risk management and third-party oversight frameworks. For AI Act compliance:

Healthcare and medical devices (MDR/IVDR overlap)

AI embedded in medical devices or in vitro diagnostic devices is classified as Annex I high-risk (deadline: 2 August 2028). Key considerations:

HR and recruitment AI

AI systems used for recruitment, CV screening, candidate ranking, performance management, or termination decisions fall under Annex III — employment and worker management (Art. 6(2)(d), deadline: 2 December 2027).

Key compliance priorities:

  1. Bias and discrimination risk is the primary regulatory concern. Data governance (Art. 10) must address historical bias in training data. Document bias mitigation measures and testing results.
  2. Transparency to candidates — deployers must inform candidates when AI significantly affects hiring decisions. Consider proactive disclosure policies beyond the minimum requirement.
  3. Fundamental Rights Impact Assessment (FRIA) — Art. 27 requires this for public sector deployers; strongly recommended for all HR AI regardless of sector.
  4. Human oversight: No AI system may make final binding employment decisions without human review. Document the decision workflow and the human reviewer's authority to override.

Frequently Asked Questions

Your AI system is in scope if it is an AI system under Art. 3(1) — a machine-based system that infers outputs such as predictions, recommendations, decisions, or content — and it is placed on the EU market or used in the EU. Purely research models not deployed externally are out of scope.

The first step is AI system inventory: catalogue all AI systems your organisation develops, deploys, imports, or distributes. For each system, document what it does, who the provider is, how it is used, and the affected population. Without a complete inventory, risk classification cannot begin.

For a standalone Annex III high-risk AI system, a realistic compliance programme takes 12–24 months: 3–6 months for gap assessment and QMS design, 6–12 months for technical documentation, data governance, and conformity assessment, and 3–6 months for EU database registration and CE marking. Start no later than early 2026 to meet the December 2027 deadline.

A provider is any entity that develops an AI system and places it on the EU market or puts it into service. A deployer is any entity that uses a high-risk AI system under its authority for a professional activity. A financial institution that purchases an AI credit-scoring tool from a vendor is the deployer; the vendor is the provider. Both have distinct obligations — providers bear the primary conformity burden; deployers bear oversight, monitoring, and transparency obligations.

Yes, in part. An AI system 'put into service' covers internal deployment where the system affects people — HR decisions, employee monitoring, internal credit assessment. An AI used solely for backend technical computation with no human-facing output may fall outside scope, but this requires documented legal analysis. Art. 4 (AI literacy) applies to all providers and deployers regardless of scope.

Take compliance further with the AI Act Academy

Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.