Regulation EU 2024/1689, Post-Omnibus Edition

EU AI Act Compliance Checklist: 10 Key Areas

A structured compliance checklist covering every major workstream under the EU AI Act, from initial AI inventory through GPAI obligations and post-market monitoring.

→ Not sure how this affects your AI system?

Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.

Run the classifier →
Compliance requires 3–9 months for high-risk AI systems. The Annex III high-risk deadline moved to 2 December 2027 under the May 2026 Omnibus deal, but obligations such as Article 50 transparency and Article 49 registration still apply from 2 August 2026, begin now. Start with the checklist, identify gaps, and act.

Area 1: AI System Inventory and Classification

  • Catalogue all AI systems used or provided across the organisation, including third-party tools and embedded AI
  • Identify the intended purpose, operational context, and primary users of each system
  • Apply the Article 5 prohibited practice checklist to every system, if any falls within a prohibition, halt deployment immediately
  • Apply the Annex III classification criteria to each system to determine high-risk status
  • Apply the Article 6(3) exception test where Annex III classification is uncertain
  • Identify GPAI models in your AI portfolio (provided or integrated)
  • Document all classification decisions with supporting reasoning

Area 2: Risk Management System (Article 9)

  • Establish a documented risk management system covering the full AI system lifecycle
  • Identify and catalogue risks to health, safety, and fundamental rights posed by each high-risk system
  • Perform risk estimation and evaluation with documented methodology
  • Define and implement risk mitigation measures proportionate to identified risks
  • Assess residual risks after mitigation and document conclusions
  • Establish a process for updating the risk management system as the system evolves
  • Assign named responsibility for risk management system maintenance

Area 3: Technical Documentation (Article 11 + Annex IV)

  • General description of the AI system including intended purpose and version history
  • Detailed description of system elements, design process, and design specifications
  • Description of monitoring, functioning, and control of the system
  • Description of changes made to the system through its lifecycle
  • Technical capabilities, limitations, and known risks to health, safety, or fundamental rights
  • Training methodology and training data characteristics documentation
  • Testing and validation procedures and results including performance benchmarks
  • Cybersecurity measures implemented
  • EU Declaration of Conformity (signed by authorised representative)
  • Post-market monitoring plan

Area 4: Data Governance (Article 10)

  • Document training, validation, and testing dataset sources, collection methodology, and governance
  • Assess datasets for relevance, representativeness, and completeness relative to intended purpose
  • Identify and document known biases or limitations in training data
  • Establish data governance policies for ongoing data management
  • Where personal data is used, coordinate GDPR compliance with AI Act data requirements
  • Document data annotation methodologies and quality controls

Area 5: Human Oversight (Article 14)

  • Design human oversight into the AI system architecture, not just as a procedural overlay
  • Identify specific oversight functions: monitoring, understanding output, intervention, override, shutdown
  • Designate named roles with documented authority to intervene in system operation
  • Implement measures preventing automation bias in oversight personnel
  • Test and validate that oversight mechanisms function as designed under production conditions
  • Document human oversight provisions in instructions for use

Area 6: Transparency and Instructions for Use (Article 13)

  • Prepare instructions for use for deployers in accessible, clear language
  • Instructions must cover: provider identity; capabilities and limitations; performance metrics; intended purpose; foreseeable misuse; monitoring requirements; human oversight requirements; maintenance requirements
  • Ensure limited-risk transparency obligations are met for chatbots, deepfakes, and emotion recognition tools

Area 7: Logging and Record-Keeping (Article 12)

  • Implement automatic logging capabilities in the AI system (must function without manual activation)
  • Ensure logs capture sufficient information to enable traceability of decisions
  • Define log retention periods (minimum 6 months; check sector-specific requirements)
  • Implement log access controls and integrity protections

Area 8: Conformity Assessment and Registration (Article 43)

  • Conduct conformity assessment against Chapter III requirements (self-assessment for most Annex III; notified body for biometric systems)
  • Prepare EU Declaration of Conformity
  • Apply CE marking where applicable (Annex I regulated product AI)
  • Register the system in the EU AI public database before deployment

Area 9: Post-Market Monitoring (Article 72)

  • Establish a post-market monitoring system with defined metrics and review frequency
  • Establish incident reporting procedures to national competent authorities (Art. 73)
  • Implement processes for updating documentation and technical measures when issues are identified
  • Assign named responsibility for ongoing post-market monitoring

Area 10: GPAI Compliance (Articles 51–56)

  • Determine whether any AI models you provide qualify as GPAI
  • Prepare GPAI technical documentation covering model architecture, training, and data sources
  • Prepare information package for downstream providers enabling their compliance
  • Establish and publish copyright compliance policy covering training data and TDM practices
  • Publish training data summary per Article 53(1)(d)
  • Assess whether any model exceeds the 10²⁵ FLOPs systemic risk threshold
  • If systemic risk: adversarial testing, AI Office incident reporting, cybersecurity measures

Get the Complete 58-Point Checklist

The full 58-point compliance checklist, in the Checklist Pack ($149), maps every obligation to its legal basis, includes completion checkboxes and evidence guidance, and is formatted for audit and regulatory submissions.

Free Resource

Where Does Your AI Stand Against the New Phased Timeline?
Find Out in 5 Minutes

Download our EU AI Act 5-Point Express Compliance Check, a structured self-assessment covering risk classification, Annex III applicability, documentation gaps, and board-level exposure. Delivered as a PDF immediately after submit.

No spam. No marketing lists. PDF delivered immediately after submit. Privacy Policy

✓   Your checklist is downloading now. Check your inbox for a copy.