← Back to Blog
EU AI ActMarch 26, 2026Updated August 7, 20268 min read

EU AI Act Compliance Checklist — What Every AI Company Needs Now

The EU AI Act's transparency duties are in force. Its high-risk obligations were deferred. Use this checklist to understand which of the four risk tiers you sit in, what each one actually requires, and which of your obligations are live today rather than scheduled.

The Transparency Duties Are Not Coming. They Are Here.

If your company builds, deploys, or uses AI systems that touch EU residents — customers, employees, users — the EU AI Act is already law. The General Data Protection Regulation (GDPR) reshaped how the world handles personal data. The EU AI Act is doing the same for artificial intelligence, and the part that binds the widest set of companies is no longer a future date.

Since August 2, 2026, Article 50 has required that people be told when they are interacting with an AI system, and that synthetic audio, image, video and text be marked machine-readably as AI-generated. Systems already on the market before that date are exempt under Article 50(2) — but only until December 2, 2026, when that carve-out closes and a further set of prohibited practices attaches.

The high-risk regime moved in the other direction. The Digital Omnibus on AI pushed standalone Annex III systems out to December 2, 2027 and AI embedded in already-regulated products to August 2, 2028. That is runway, not a reprieve — the conformity work below takes longer than the extension did.

This checklist covers the full picture: who is affected, how to classify your systems, what each risk tier demands, and which obligations bind you today rather than eventually.

EU AI Act Timeline — What Applies, and When

The EU AI Act entered into force on August 1, 2024. Compliance obligations roll out in phases:

DateStatusWhat Applies
February 2, 2025In forceProhibited practices banned outright — social scoring, untargeted facial-image scraping, emotion inference at work and school, and real-time remote biometric ID in public spaces.
August 2, 2025In forceGeneral-purpose AI model obligations: technical documentation, training-data summary, copyright policy, and systemic-risk duties above the compute threshold.
August 2, 2026In forceTransparency duties: users must be told when they are interacting with an AI system, and synthetic audio, image, video and text must be machine-readably marked as AI-generated. Systems already on the market before this date are exempt under Art. 50(2) until December.
December 2, 2026UpcomingThe Art. 50(2) marking exemption ends: systems placed on the market before 2026-08-02 must now comply. New prohibited practices also attach, including AI-generated non-consensual intimate imagery and CSAM.
August 2, 2027UpcomingEvery member state must have at least one operational AI regulatory sandbox.
December 2, 2027DeferredStandalone high-risk systems — employment, credit, education, essential services, law enforcement — must meet the full Chapter III regime: risk management, data governance, logging, human oversight, conformity assessment.
August 2, 2028DeferredHigh-risk AI embedded in products already covered by EU product-safety law (machinery, medical devices, vehicles) must meet the Chapter III regime.

Read the status column before the date column. A deferred obligation and a live one look identical on a calendar, and that difference is the whole of what you owe right now. Conformity assessments, technical documentation, human oversight systems and registration are the heaviest lift — and they are the ones that moved.

Who Does the EU AI Act Affect?

Scope is broader than most founders expect. The Act applies to:

  • Providers — companies that develop or place AI systems on the EU market, regardless of where the provider is headquartered
  • Deployers — businesses that use AI systems in their operations within the EU
  • Importers and distributors — entities that bring non-EU AI systems into the EU market
  • Product manufacturers — companies embedding AI into regulated products (medical devices, machinery, vehicles)

The extraterritorial reach is GDPR-level. A US-based SaaS company with EU customers deploying a high-risk AI system must comply, even if it has no EU office.

Risk Classification — The Four Tiers

The Act organizes AI systems into four risk categories. Your compliance obligations depend entirely on which tier your system falls into.

Tier 1 — Unacceptable Risk (Prohibited)

These are banned outright as of February 2025:

  • Social scoring systems by public authorities
  • Real-time remote biometric identification in public spaces (with narrow exceptions)
  • Subliminal manipulation that bypasses conscious decision-making
  • AI that exploits vulnerabilities of specific groups (age, disability)
  • Predictive policing based solely on profiling

Action: If any feature of your product touches these categories, it must be removed.

Tier 2 — High-Risk AI Systems

This is where most compliance work lives. High-risk systems are defined in Annex III of the Act and include AI used in:

  • Biometric identification and categorization
  • Critical infrastructure (energy, water, transport)
  • Education (scoring, admissions, performance evaluation)
  • Employment (CV screening, promotion decisions, work monitoring)
  • Essential private and public services (credit scoring, insurance, social benefits)
  • Law enforcement, migration, asylum, and border control
  • Administration of justice

If your product touches any of these areas, you are almost certainly high-risk.

Tier 3 — Limited Risk

Chatbots, AI that generates synthetic content, systems that interact with humans directly. Key obligation: transparency. Users must know they are interacting with AI, and synthetic media must be marked machine-readably. This tier is in force — it has applied since August 2, 2026. If you assumed your compliance work started with the high-risk regime, this is the one you are already late on.

Tier 4 — Minimal Risk

Most AI applications fall here — spam filters, AI in video games, recommendation systems with no significant individual impact. No mandatory obligations, but voluntary codes of practice are encouraged.

General Purpose AI (GPAI) Models — A Separate Track

If you train or fine-tune a foundation model (anything with 10²⁵ FLOPs or more training compute), you fall under the GPAI rules that took effect August 2025:

  • Publish technical documentation
  • Provide model cards to downstream deployers
  • Comply with EU copyright law (training data transparency)
  • If your model is designated as systemic risk: adversarial testing, incident reporting to EU AI Office, cybersecurity measures

High-Risk AI Compliance Requirements — The Full List

If you operate a standalone high-risk AI system, these requirements apply from December 2, 2027:

1. Risk Management System

A documented, continuous process covering identification and analysis of known and foreseeable risks, estimation and evaluation of risks that may emerge during use, evaluation of risks based on post-market monitoring data, and adoption of risk mitigation measures.

2. Data and Data Governance

Training, validation, and testing datasets must be subject to appropriate data governance practices, be relevant and representative, address potential biases, and be documented with data lineage and transformation records.

3. Technical Documentation

Must be created before market placement and kept up to date. Includes system description, design specifications, training methodology, performance metrics, and known limitations.

4. Record-Keeping and Logging

High-risk AI systems must automatically log dates and times of operation, reference databases, input data that led to specific outputs, and results of human verification. Logs must be retained for defined periods.

5. Transparency and User Information

Deployers must provide users with a clear description of system capabilities and limitations, accuracy levels, human oversight procedures, and data subjects' rights and redress mechanisms.

6. Human Oversight

Systems must be designed so a human can fully understand the system's capabilities, monitor for anomalies, intervene or shut down the system, and the system does not override human decisions automatically.

7. Accuracy, Robustness, and Cybersecurity

Document accuracy metrics, demonstrate robustness against errors and adversarial manipulation, implement cybersecurity measures proportionate to the risk.

8. Conformity Assessment

Before market placement, undergo a conformity assessment. Most Annex III systems: self-assessment permitted. Biometric identification: third-party notified body assessment required. Result: EU Declaration of Conformity + CE marking.

9. Registration in EU Database

High-risk AI systems must be registered in the EUAI Database before market placement with a unique identification number and full technical documentation reference.

10. Post-Market Monitoring

Ongoing obligation — not a one-time check. Active collection and review of real-world performance data, systematic monitoring plan, serious incident reporting to national authorities, corrective action when systems underperform.

The EU AI Act Compliance Checklist — Print This

Use this as your sprint board. The transparency items are due now; the rest are the conformity work you have runway on:

Classification

  • Mapped all AI systems against Annex III categories
  • Determined GPAI applicability (training compute, downstream deployment)
  • Documented risk tier for each system with legal justification

Documentation

  • Technical documentation complete for each high-risk system
  • Data governance policy documented with lineage records
  • Risk management system established and documented
  • Transparency notices drafted for users and affected individuals

Technical Controls

  • Logging and record-keeping system operational
  • Human oversight mechanism designed and tested
  • Accuracy and robustness metrics benchmarked
  • Cybersecurity assessment completed

Legal and Regulatory

  • Conformity assessment pathway confirmed (self vs. notified body)
  • EU Declaration of Conformity drafted
  • CE marking process initiated (if applicable)
  • EUAI Database registration completed
  • Post-market monitoring plan written

Governance

  • AI governance owner designated (equivalent to a DPO for AI)
  • Employee training on prohibited practices completed
  • Third-party supplier AI assessments in procurement contracts
  • Incident response plan for AI failures documented

The Cost of Getting This Wrong

The EU AI Act creates a three-tier penalty structure:

  • Prohibited practices violations: Up to €35M or 7% of global turnover
  • High-risk requirements violations: Up to €15M or 3% of global turnover
  • Incorrect or misleading information to authorities: Up to €7.5M or 1% of global turnover

National market surveillance authorities will have significant enforcement powers, including the right to demand access to training data, algorithms, and testing documentation.

Sources

  • EU AI Act — Regulation (EU) 2024/1689, Official Journal of the EU, July 12, 2024
  • EU AI Office — High-Level Summary of the AI Act (2024)
  • European Commission — AI Act Implementation Timeline, October 2024
  • EU AI Office — GPAI Code of Practice Draft Guidelines (2025)
  • Conformity Assessment Guidance — EU AI Act Article 43 and Annex VII
  • Digital Omnibus on AI — amending Regulation (EU) 2024/1689 (2026); deferred the Annex III and Annex I high-risk obligations

DingDawg builds automated AI compliance infrastructure. This post is informational and does not constitute legal advice. Consult qualified EU legal counsel for your specific situation.

Get Your Automated EU AI Act Compliance Report

See exactly where you stand across all risk tiers. Prioritized remediation list. Documented evidence trail. In hours, not months.

Get Your Compliance Report →