EU AI Act Compliance Checklist: Classify Your AI Systems and Close the Gaps
The EU AI Act (Regulation 2024/1689) regulates AI by risk class: prohibited practices, high-risk systems with extensive obligations, systems with transparency duties, and minimal-risk systems. It binds providers and deployers alike, and its reach includes non-EU companies whose AI is placed on the EU market or whose outputs are used there. Obligations phase in on a fixed schedule — prohibitions are already effective, with high-risk requirements following.
For most companies the practical work is not exotic: know which AI systems you actually run, determine your role and risk class for each, and build the documentation and oversight the class requires. Deployers of everyday AI have lighter duties than providers of high-risk systems, but 'lighter' is not 'none' — and HR, credit, and safety-related use cases land in high-risk faster than teams expect. The checklist below structures the program.
Your checklist
- 1Inventory all AI systems: catalogue AI in products, internal tools and vendor software — including embedded AI features in SaaS you deploy — with owner, purpose and affected persons.
- 2Screen for prohibited practices: check the inventory against the AI Act's banned practices (e.g., certain manipulation, social scoring, and specific biometric uses) and stop anything that matches — these prohibitions already apply.
- 3Classify risk per system: determine which systems are high-risk under the Act's use-case annexes (e.g., employment, credit, essential services) and which carry transparency duties, and record the reasoning.
- 4Determine your role: establish per system whether you are provider, deployer, importer or distributor — obligations differ fundamentally, and modifying or rebranding a system can shift you into the provider role.
- 5Meet transparency duties: label AI interactions and AI-generated or manipulated content where required, so users know they are dealing with AI.
- 6Build high-risk compliance files: for high-risk systems, ensure risk management, data-governance measures, technical documentation, logging and human oversight exist and are current.
- 7Fix vendor contracts: require AI Act conformity, documentation and cooperation duties from AI suppliers, so you can meet your deployer obligations.
- 8Train staff for AI literacy: the Act expects organizations to ensure adequate AI competence among people operating AI systems on their behalf.
- 9Set up ongoing governance: assign ownership, monitor systems in operation, handle incidents, and re-classify whenever use cases or models change.
Frequently asked questions
How do I know if one of our AI systems is 'high-risk'?
High-risk status follows mainly from the use case: the Act lists areas such as employment and worker management, credit scoring, education, essential public and private services, and safety components of regulated products. A system used for CV screening or loan decisions is a classic high-risk candidate. The classification and its reasoning should be documented per system.
What are our duties if we merely deploy third-party AI?
Deployers of high-risk systems must use them according to the provider's instructions, ensure competent human oversight, control relevant input data, monitor operation, retain logs, and in certain cases inform affected persons or conduct a fundamental-rights impact assessment. For non-high-risk AI, transparency and AI-literacy duties can still apply.
By when do we need to be compliant?
The AI Act entered into force in 2024 and applies in stages: prohibitions and AI-literacy duties came first, governance rules for general-purpose AI models followed, and the bulk of high-risk obligations apply from August 2026, with some product-related cases later. Classifying your systems now tells you which deadlines are actually yours.