The EU AI Act is no longer a future obligation. It entered into force in August 2024. The prohibited practices provisions applied from February 2025. General-purpose AI rules have been in effect since August 2025. High-risk AI system requirements apply fully from August 2026.
If you are building or deploying AI systems that serve EU users, you are in scope. Here is what you need to do.
Key Dates and Scope
| Milestone | Date | |-----------|------| | Regulation in force | 1 August 2024 | | Prohibited practices (Article 5) | 2 February 2025 | | GPAI model rules (Articles 51–56) | 2 August 2025 | | High-risk AI systems (Annexes II–III) | 2 August 2026 |
Who is in scope: Providers (organizations that develop and place AI systems on the market) and deployers (organizations that use AI systems under their own responsibility) in the EU, or those whose AI systems are used in the EU regardless of location.
Step 1: Classify Your AI Systems
Before anything else, you need to know which risk category each of your AI systems falls into.
Unacceptable Risk (Article 5 — Prohibited)
Stop using these immediately:
- Biometric categorization systems using sensitive characteristics (race, political opinions, etc.)
- Subliminal manipulation techniques that bypass conscious decisions
- Real-time remote biometric identification in public spaces (with narrow exceptions)
- AI that exploits vulnerabilities of specific groups
- Social scoring by public authorities
High Risk (Annex III — Significant obligations)
This is where most compliance work concentrates. High-risk AI includes systems used in:
- Biometrics — remote identification, categorization, emotion recognition
- Critical infrastructure — transport, water, energy management
- Education — admissions, assessment, monitoring students
- Employment — recruitment, performance evaluation, task allocation
- Essential services — credit scoring, insurance risk, social benefits
- Law enforcement — risk assessment, polygraph, evidence evaluation
- Migration — border control, visa processing, asylum assessment
- Justice — legal aid, dispute resolution influencing court decisions
Practical test: If your AI system makes or materially influences decisions about people in any of the above domains, assume high risk until a qualified assessment says otherwise.
Limited Risk
Chatbots, AI-generated content, deepfakes — primarily transparency obligations (Articles 50, 52). Users must be informed they are interacting with AI.
Minimal Risk
Everything else. Voluntary codes of conduct are encouraged but not required.
Step 2: For High-Risk AI — Your Obligations
If you have high-risk AI systems, Articles 9–15 apply. Here is what each requires:
Article 9 — Risk Management System
You must establish, implement, document, and maintain a risk management system that:
- Identifies foreseeable risks and reasonably foreseeable misuse scenarios
- Estimates and evaluates those risks
- Evaluates risks from post-market monitoring data
- Adopts suitable risk management measures
Checklist:
- [ ] Documented risk management process (not just a template — an active process)
- [ ] Named risk manager or risk committee for each high-risk system
- [ ] Risk log updated at each model version change
- [ ] Residual risk acceptance sign-off documented
Article 10 — Data and Data Governance
Training, validation, and test datasets must be subject to data governance practices. Specifically:
- Dataset design choices documented
- Possible biases examined and mitigated
- Training data must be representative of the intended use context
Checklist:
- [ ] Training dataset card (origin, collection method, preprocessing)
- [ ] Bias evaluation documented for each relevant demographic group
- [ ] Validation set documented separately from training set
- [ ] Data quality criteria defined and verified
Article 11 — Technical Documentation
You must prepare comprehensive technical documentation before placing the system on the market or putting it into service.
Checklist:
- [ ] System description and intended purpose
- [ ] System design, architecture, and development choices
- [ ] Training methodology and techniques
- [ ] Validation and testing procedures and results
- [ ] Accuracy, robustness, and cybersecurity measures
- [ ] Changes to the system over its lifecycle
- [ ] List of harmonized standards applied
Article 12 — Record-Keeping (Logging)
High-risk AI systems must automatically log events at a level that enables post-hoc traceability.
Checklist:
- [ ] Automated logging of inputs and outputs (at appropriate granularity)
- [ ] Logging of decisions and the data influencing them
- [ ] Retention period defined and documented (default: 6 months for deployers)
- [ ] Logs protected against unauthorized modification
Article 13 — Transparency and Information to Deployers
Providers must supply deployers with comprehensive instructions for use.
Checklist:
- [ ] Provider identity and contact information
- [ ] Capabilities and limitations of the system
- [ ] Performance metrics and any known biases
- [ ] Hardware and software requirements
- [ ] Instructions for human oversight
- [ ] Expected lifetime and maintenance requirements
Article 14 — Human Oversight
High-risk AI systems must be designed to allow natural persons to effectively oversee them.
Checklist:
- [ ] Documented human-in-the-loop procedures where required
- [ ] Override mechanism: humans can intervene, correct, or shut down
- [ ] Training for human overseers documented
- [ ] For fully automated decisions: review and appeal pathway defined
Article 15 — Accuracy, Robustness, and Cybersecurity
Systems must achieve appropriate levels of accuracy and be resilient to errors and attacks.
Checklist:
- [ ] Accuracy metrics defined and measured against validation set
- [ ] Robustness testing: performance under edge cases and distributional shift
- [ ] Adversarial testing documented (particularly for high-stakes applications)
- [ ] Incident response plan for AI system failures
Step 3: Registration (Article 71)
High-risk AI systems must be registered in the EU AI database before market placement.
- Self-registration through the Commission's portal
- Required fields: provider identity, system description, intended purpose, risk classification, applicable standards
Timeline: From August 2026 for high-risk systems under Annex III.
Step 4: Ongoing Monitoring (Article 72)
Post-market monitoring is not optional for high-risk AI. You need:
- A plan for collecting and reviewing post-market data
- Serious incident reporting to national authorities within 15 days of becoming aware
- Regular review of the risk management system based on monitoring data
Practical First Steps This Quarter
If you have not started your EU AI Act compliance program:
-
Run an AI inventory — You cannot classify what you have not found. Use automated discovery to surface all AI systems operating in your organization.
-
Risk-classify everything — Apply the Annex III screening criteria to your full inventory. Get a definitive list of high-risk systems.
-
Gap-assess your high-risk systems against Articles 9–15 — For each high-risk system, run through the checklists above. Prioritize based on gaps.
-
Assign owners — Every high-risk AI system needs a named owner responsible for compliance documentation.
-
Build continuous evidence collection — Manual evidence gathering at audit time is unsustainable. Invest in tooling that captures governance events, approvals, and risk assessments automatically.
The EU AI Act is complex, but compliance is achievable with systematic effort. The organizations that will struggle are those who treat it as a one-time documentation exercise rather than an operational capability they build and maintain.
Disclaimer: This checklist is for informational purposes and does not constitute legal advice. Engage qualified legal counsel for your specific situation.
