EU AI Act compliance checklist
Organised by article rather than by theme, because that is how an assessor will read it. Work down the list for each system separately: the answer differs per system, and a company-level answer is not an answer.
Before the checklist: four gating questions
- Is it an AI system? Article 3(1). The inference test →
- Are you in scope, and in which role? Articles 2 and 25. Roles →
- Which tier? Articles 5, 6, Annexes I and III, Article 50. Run the classifier →
- Which date? Annex III 2 Dec 2027; Annex I 2 Aug 2028; Articles 4, 49, 50 already live.
Everything below assumes those are answered and recorded.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Live now, every organisation, every tier
| Article | Obligation | The artefact that proves it |
|---|---|---|
| Art. 4 | AI literacy for staff dealing with AI systems, at every risk tier | A training record with dates and coverage. Detail → |
| Art. 5 | No prohibited practices; documented position on the two new prohibitions before 2 Dec 2026 | A dated determination naming the safeguards. Detail → |
| Art. 50(1) | People told they are interacting with an AI system | Screenshot of the disclosure at first interaction |
| Art. 50(2) | Machine-readable marking of synthetic output, existing systems by 2 Dec 2026 | Provenance metadata implementation. Detail → |
| Art. 50(3)–(4) | Disclosure of emotion recognition, biometric categorisation and deep fakes | The disclosure itself, in the interface |
| Art. 49 | Registration in the EU database, including for derogation claims | Registration record. Detail → |
| Arts. 51–55 | GPAI model provider obligations, if you train or fine-tune models you place on the market | Model documentation, copyright policy, training-data summary. Detail → |
High-risk providers, from 2 December 2027
| Article | Obligation | The artefact |
|---|---|---|
| Art. 6(4) | Documented classification assessment, before market placement | Dated assessment incl. profiling analysis. Detail → |
| Art. 9 | Lifecycle risk management incl. foreseeable misuse; residual risk accepted | Per-system risk file with a named acceptance. Detail → |
| Art. 10 | Data governance: origin, preparation, assumptions, bias examination, gaps | Data lineage per data set. Detail → |
| Art. 11 / Annex IV | Technical documentation, nine prescribed headings, kept up to date | The technical file. Detail → |
| Art. 12 | Automatic event logging over the system lifetime | Log specification and samples. Detail → |
| Art. 13 | Instructions for use with the prescribed contents | The instructions themselves |
| Art. 14 | Human oversight designed in; five capabilities enabled | Oversight design, role authority, override records. Detail → |
| Art. 15 | Declared accuracy, robustness, redundancy, feedback-loop control, five named attack classes | Test results and threat model. Detail → |
| Art. 17 | Quality management system, thirteen enumerated elements | Written policies, procedures and instructions. Detail → |
| Art. 18 | Retain documentation for ten years | An archive someone can retrieve from in 2037 |
| Art. 19 | Retain logs under your control, minimum six months | Retention policy and evidence |
| Arts. 43–48 | Conformity assessment, EU declaration, CE marking | Signed declaration; marking. Detail → |
| Art. 72 | Post-market monitoring system and plan, plan inside Annex IV | The plan plus live monitoring output. Detail → |
| Art. 73 | Serious incident reporting: 15 / 10 / 2 days | A rehearsed procedure. Detail → |
High-risk deployers: a shorter list
| Article | Obligation |
|---|---|
| Art. 26(1) | Use the system in accordance with the instructions for use |
| Art. 26(2) | Assign human oversight to people with the necessary competence, training, authority and support |
| Art. 26(4) | Ensure input data is relevant and sufficiently representative, to the extent you control it |
| Art. 26(5) | Monitor operation; inform the provider and authority where the system may present a risk; suspend use |
| Art. 26(6) | Retain logs under your control, minimum six months |
| Art. 26(7) | Inform workers’ representatives and affected workers before putting a high-risk system into service at the workplace |
| Art. 27 | Fundamental rights impact assessment, public bodies, private entities providing public services, and deployers of Annex III 5(b) and 5(c). FRIA vs DPIA → |
| Art. 49 | Public authority deployers register themselves and their use of the system |
The four most commonly missed
- Article 4 AI literacy. Live since February 2025, every tier, and almost never documented.
- The Article 6(4) assessment. Must exist before market placement. Reconstructing it later is not compliance with 6(4).
- Article 26(7). Employers must inform workers before deployment, not after.
- Article 18 retention. Ten years is longer than most cloud log policies, most vendor contracts, and most people’s tenure.
Status labels on this page
Verified fact: Every article reference and obligation above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The 'artefact that proves it' column and the four commonly-missed items.
Unsettled: Harmonised standards remain in development, which affects how several obligations will be evidenced in practice.
A checklist tells you what is missing
It does not produce the artefacts. The organisations that close these gaps efficiently built a management system that generates the evidence as a by-product of operating, rather than assembling documents ahead of an audit.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What is an EU AI Act compliance checklist?
A structured review of the obligations that apply to a specific AI system, organised by article. For a high-risk system the core set is Articles 9 to 15 on risk management, data governance, technical documentation, logging, transparency to deployers, human oversight and accuracy, plus Article 17 quality management, Articles 43 to 48 conformity assessment and CE marking, Article 49 registration, and Articles 72 and 73 post-market monitoring and incident reporting. Deployers have a separate and shorter set under Article 26 and, for some, Article 27.
What should be on an EU AI Act checklist that usually is not?
Four items are commonly missed: Article 4 AI literacy, which applies to every provider and deployer at every risk tier and has applied since 2 February 2025; the Article 6(4) documented classification assessment, which must exist before the system is placed on the market; Article 26(7), which requires employers to inform workers' representatives before putting a high-risk system into service at the workplace; and the Article 18 ten-year retention duty for the technical documentation.
Does a checklist prove compliance?
No. Compliance is demonstrated by artefacts: the risk file, the Annex IV technical documentation, the quality management system documentation, the conformity assessment and declaration, the registration, and post-market monitoring records. A checklist tells you which artefacts must exist and whether they do. It is a navigation tool, not evidence.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Art. 11 / Annex IV
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- FRIA template (Art. 27)
- When Annex III does not apply →