Skip to content
19 items · Free checklist

EU Artificial Intelligence Act Compliance Checklist 2026

Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, cr

Maximum penalty: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities

Enforcement: August 2, 2026

Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.

Regulatory Requirements

1. AI Risk Classification

Classify each AI system you use or deploy as Minimal, Limited, High, or Unacceptable risk under EU AI Act Annex III. High-risk categories: biometric systems, critical infrastructure, education/vocational training, employment/HR, essential services (credit, insurance), law enforcement, migration/asylum, administration of justice. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).

Due: December 2, 2027

2. Transparency Disclosures

Inform users when they are interacting with AI (chatbots, generated content, AI-assisted decisions). Deepfake content must be labeled. AI chatbots must identify themselves. Cannot deploy AI that impersonates humans without disclosure.

Due: August 2, 2026

3. AI Acceptable Use Policy

Document how employees may and may not use AI tools within your organization. Required for deployers of high-risk systems. Must include authorized uses, restrictions, human oversight requirements, and escalation procedures.

Due: December 2, 2027

4. Employee AI Monitoring Notice

Notify employees if AI systems are used to monitor their work performance or productivity. Covers AI-assisted performance management, productivity scoring, and automated scheduling. Must be clear, written notice before deployment. Art. 26(7): before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers. As an Art. 26 high-risk deployer obligation this follows the Digital Omnibus deferral to 2 Dec 2027.

Due: December 2, 2027

5. Human Oversight Procedures

Implement procedures ensuring human review of high-risk AI decisions. Must document how humans can intervene, override, or halt the AI system. Human oversight must be technically possible and operationally implemented — a nominal checkbox does not suffice.

Due: December 2, 2027

6. Technical Documentation (Annex IV)

Providers of high-risk AI systems must maintain Annex IV technical documentation: system description, development methodology, training data summary, testing procedures, accuracy metrics, post-market monitoring plan.

Due: December 2, 2027

7. Record Keeping & Logging

Deployers of high-risk AI must keep logs for minimum 6 months. Providers must keep technical documentation for 10 years. Logs must enable reconstruction of circumstances leading to any incident.

Due: December 2, 2027

8. Conformity Assessment (High-Risk)

Providers of Annex III high-risk AI systems must conduct conformity assessment before placing on market. Most systems: self-assessment via internal checks. Biometric and critical infrastructure: third-party assessment required. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).

Due: December 2, 2027

9. Prohibited: Non-Consensual Intimate Imagery & CSAM-Generation AI

Digital Omnibus amendment (Regulation (EU) 2026/1744) added two new Art. 5(1) prohibited practices, effective 2 Dec 2026: (ba) placing on market, putting into service, or using AI systems that generate or manipulate realistic depictions of an identifiable person's intimate body parts or sexually explicit activity without that person's freely-given, specific, informed, unambiguous, and explicit consent (targets "nudifier" apps); (bb) AI systems designed to generate child sexual abuse material, subject to narrow law-enforcement/crime-prevention/compliance-red-teaming exceptions. Providers are banned if generation/manipulation is the intended purpose OR a reasonably foreseeable outcome absent adequate technical safeguards (data cleaning, refusal training, content filtering, abuse detection); deployers are banned only for actual use to generate prohibited material.

Due: December 2, 2026

10. GPAI Model Obligations

General Purpose AI (GPAI) model providers must publish technical documentation, maintain copyright compliance policy, and train providers who use their models. Systemic risk GPAI (>10^25 FLOPs training compute) have additional obligations: adversarial testing, serious incident reporting, cybersecurity measures.

Due: August 2, 2025

Implementation Steps

11. Add a disclosure when users interact with an AI chatbot (EU AI Act Art. 50)

12. Do not allow the chatbot to claim it is human when sincerely asked

13. Disclose when AI-generated content is presented (images, audio, video)

14. If the chatbot collects personal data: ensure GDPR/CCPA compliance

15. Do not train the chatbot on user conversations without explicit consent

16. Implement content filtering to prevent harmful outputs

17. Establish a human escalation path for users who want to speak to a person

18. Document all chatbot updates in your AI system changelog

19. Test the chatbot for biased or discriminatory responses before deployment