Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Readiness review · by article

EU AI Act compliance checklist

Organised by article rather than by theme, because that is how an assessor will read it. Work down the list for each system separately: the answer differs per system, and a company-level answer is not an answer.

Arts. 4, 9–18, 26–27, 43–50, 72–73

Before the checklist: four gating questions

  1. Is it an AI system? Article 3(1). The inference test →
  2. Are you in scope, and in which role? Articles 2 and 25. Roles →
  3. Which tier? Articles 5, 6, Annexes I and III, Article 50. Run the classifier →
  4. Which date? Annex III 2 Dec 2027; Annex I 2 Aug 2028; Articles 4, 49, 50 already live.

Everything below assumes those are answered and recorded.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Live now, every organisation, every tier

ArticleObligationThe artefact that proves it
Art. 4AI literacy for staff dealing with AI systems, at every risk tierA training record with dates and coverage. Detail →
Art. 5No prohibited practices; documented position on the two new prohibitions before 2 Dec 2026A dated determination naming the safeguards. Detail →
Art. 50(1)People told they are interacting with an AI systemScreenshot of the disclosure at first interaction
Art. 50(2)Machine-readable marking of synthetic output, existing systems by 2 Dec 2026Provenance metadata implementation. Detail →
Art. 50(3)–(4)Disclosure of emotion recognition, biometric categorisation and deep fakesThe disclosure itself, in the interface
Art. 49Registration in the EU database, including for derogation claimsRegistration record. Detail →
Arts. 51–55GPAI model provider obligations, if you train or fine-tune models you place on the marketModel documentation, copyright policy, training-data summary. Detail →

High-risk providers, from 2 December 2027

ArticleObligationThe artefact
Art. 6(4)Documented classification assessment, before market placementDated assessment incl. profiling analysis. Detail →
Art. 9Lifecycle risk management incl. foreseeable misuse; residual risk acceptedPer-system risk file with a named acceptance. Detail →
Art. 10Data governance: origin, preparation, assumptions, bias examination, gapsData lineage per data set. Detail →
Art. 11 / Annex IVTechnical documentation, nine prescribed headings, kept up to dateThe technical file. Detail →
Art. 12Automatic event logging over the system lifetimeLog specification and samples. Detail →
Art. 13Instructions for use with the prescribed contentsThe instructions themselves
Art. 14Human oversight designed in; five capabilities enabledOversight design, role authority, override records. Detail →
Art. 15Declared accuracy, robustness, redundancy, feedback-loop control, five named attack classesTest results and threat model. Detail →
Art. 17Quality management system, thirteen enumerated elementsWritten policies, procedures and instructions. Detail →
Art. 18Retain documentation for ten yearsAn archive someone can retrieve from in 2037
Art. 19Retain logs under your control, minimum six monthsRetention policy and evidence
Arts. 43–48Conformity assessment, EU declaration, CE markingSigned declaration; marking. Detail →
Art. 72Post-market monitoring system and plan, plan inside Annex IVThe plan plus live monitoring output. Detail →
Art. 73Serious incident reporting: 15 / 10 / 2 daysA rehearsed procedure. Detail →

High-risk deployers: a shorter list

ArticleObligation
Art. 26(1)Use the system in accordance with the instructions for use
Art. 26(2)Assign human oversight to people with the necessary competence, training, authority and support
Art. 26(4)Ensure input data is relevant and sufficiently representative, to the extent you control it
Art. 26(5)Monitor operation; inform the provider and authority where the system may present a risk; suspend use
Art. 26(6)Retain logs under your control, minimum six months
Art. 26(7)Inform workers’ representatives and affected workers before putting a high-risk system into service at the workplace
Art. 27Fundamental rights impact assessment, public bodies, private entities providing public services, and deployers of Annex III 5(b) and 5(c). FRIA vs DPIA →
Art. 49Public authority deployers register themselves and their use of the system

The four most commonly missed

  1. Article 4 AI literacy. Live since February 2025, every tier, and almost never documented.
  2. The Article 6(4) assessment. Must exist before market placement. Reconstructing it later is not compliance with 6(4).
  3. Article 26(7). Employers must inform workers before deployment, not after.
  4. Article 18 retention. Ten years is longer than most cloud log policies, most vendor contracts, and most people’s tenure.

Status labels on this page

Verified fact: Every article reference and obligation above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The 'artefact that proves it' column and the four commonly-missed items.

Unsettled: Harmonised standards remain in development, which affects how several obligations will be evidenced in practice.

Next step

A checklist tells you what is missing

It does not produce the artefacts. The organisations that close these gaps efficiently built a management system that generates the evidence as a by-product of operating, rather than assembling documents ahead of an audit.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What is an EU AI Act compliance checklist?

A structured review of the obligations that apply to a specific AI system, organised by article. For a high-risk system the core set is Articles 9 to 15 on risk management, data governance, technical documentation, logging, transparency to deployers, human oversight and accuracy, plus Article 17 quality management, Articles 43 to 48 conformity assessment and CE marking, Article 49 registration, and Articles 72 and 73 post-market monitoring and incident reporting. Deployers have a separate and shorter set under Article 26 and, for some, Article 27.

What should be on an EU AI Act checklist that usually is not?

Four items are commonly missed: Article 4 AI literacy, which applies to every provider and deployer at every risk tier and has applied since 2 February 2025; the Article 6(4) documented classification assessment, which must exist before the system is placed on the market; Article 26(7), which requires employers to inform workers' representatives before putting a high-risk system into service at the workplace; and the Article 18 ten-year retention duty for the technical documentation.

Does a checklist prove compliance?

No. Compliance is demonstrated by artefacts: the risk file, the Annex IV technical documentation, the quality management system documentation, the conformity assessment and declaration, the registration, and post-market monitoring records. A checklist tells you which artefacts must exist and whether they do. It is a navigation tool, not evidence.