EU Artificial Intelligence Act Compliance Checklist 2026
Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, cr…
Maximum penalty: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities
Enforcement: August 2, 2026
Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.
Regulatory Requirements
1. AI Risk Classification
Classify each AI system you use or deploy as Minimal, Limited, High, or Unacceptable risk under EU AI Act Annex III. High-risk categories: biometric systems, critical infrastructure, education/vocational training, employment/HR, essential services (credit, insurance), law enforcement, migration/asylum, administration of justice. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).
Due: December 2, 2027
2. Transparency Disclosures
Inform users when they are interacting with AI (chatbots, generated content, AI-assisted decisions). Deepfake content must be labeled. AI chatbots must identify themselves. Cannot deploy AI that impersonates humans without disclosure.
Due: August 2, 2026
3. AI Acceptable Use Policy
Document how employees may and may not use AI tools within your organization. Required for deployers of high-risk systems. Must include authorized uses, restrictions, human oversight requirements, and escalation procedures.
Due: December 2, 2027
4. Employee AI Monitoring Notice
Notify employees if AI systems are used to monitor their work performance or productivity. Covers AI-assisted performance management, productivity scoring, and automated scheduling. Must be clear, written notice before deployment. Art. 26(7): before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers. As an Art. 26 high-risk deployer obligation this follows the Digital Omnibus deferral to 2 Dec 2027.
Due: December 2, 2027
5. Human Oversight Procedures
Implement procedures ensuring human review of high-risk AI decisions. Must document how humans can intervene, override, or halt the AI system. Human oversight must be technically possible and operationally implemented — a nominal checkbox does not suffice.
Due: December 2, 2027
6. Technical Documentation (Annex IV)
Providers of high-risk AI systems must maintain Annex IV technical documentation: system description, development methodology, training data summary, testing procedures, accuracy metrics, post-market monitoring plan.
Due: December 2, 2027
7. Record Keeping & Logging
Deployers of high-risk AI must keep logs for minimum 6 months. Providers must keep technical documentation for 10 years. Logs must enable reconstruction of circumstances leading to any incident.
Due: December 2, 2027
8. Conformity Assessment (High-Risk)
Providers of Annex III high-risk AI systems must conduct conformity assessment before placing on market. Most systems: self-assessment via internal checks. Biometric and critical infrastructure: third-party assessment required. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).
Due: December 2, 2027
9. Prohibited: Non-Consensual Intimate Imagery & CSAM-Generation AI
Digital Omnibus amendment (Regulation (EU) 2026/1744) added two new Art. 5(1) prohibited practices, effective 2 Dec 2026: (ba) placing on market, putting into service, or using AI systems that generate or manipulate realistic depictions of an identifiable person's intimate body parts or sexually explicit activity without that person's freely-given, specific, informed, unambiguous, and explicit consent (targets "nudifier" apps); (bb) AI systems designed to generate child sexual abuse material, subject to narrow law-enforcement/crime-prevention/compliance-red-teaming exceptions. Providers are banned if generation/manipulation is the intended purpose OR a reasonably foreseeable outcome absent adequate technical safeguards (data cleaning, refusal training, content filtering, abuse detection); deployers are banned only for actual use to generate prohibited material.
Due: December 2, 2026
10. GPAI Model Obligations
General Purpose AI (GPAI) model providers must publish technical documentation, maintain copyright compliance policy, and train providers who use their models. Systemic risk GPAI (>10^25 FLOPs training compute) have additional obligations: adversarial testing, serious incident reporting, cybersecurity measures.
Due: August 2, 2025
Implementation Steps
11. Classify all AI-assisted clinical tools under EU AI Act Article 6(1) + Annex I — the MDR/IVDR route (most are high-risk)
12. Ensure AI diagnostic tools have CE marking if used in EU
13. Document training data sources, accuracy metrics, and known limitations for each AI tool
14. Implement human oversight for all AI diagnostic or treatment recommendations
15. Train clinical staff on AI tool limitations and override procedures
16. Maintain audit trails for AI-assisted clinical decisions
17. Review FDA AI/ML-based Software as a Medical Device (SaMD) guidance if US-based
18. Conduct bias testing across patient demographic groups
19. Establish procedures for AI-related adverse events