EU Artificial Intelligence Act Compliance Checklist 2026
Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, cr…
Maximum penalty: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities
Enforcement: August 2, 2026
Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.
Regulatory Requirements
1. AI Risk Classification
Classify each AI system you use or deploy as Minimal, Limited, High, or Unacceptable risk under EU AI Act Annex III. High-risk categories: biometric systems, critical infrastructure, education/vocational training, employment/HR, essential services (credit, insurance), law enforcement, migration/asylum, administration of justice. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).
Due: December 2, 2027
2. Transparency Disclosures
Inform users when they are interacting with AI (chatbots, generated content, AI-assisted decisions). Deepfake content must be labeled. AI chatbots must identify themselves. Cannot deploy AI that impersonates humans without disclosure.
Due: August 2, 2026
3. AI Acceptable Use Policy
Document how employees may and may not use AI tools within your organization. Required for deployers of high-risk systems. Must include authorized uses, restrictions, human oversight requirements, and escalation procedures.
Due: December 2, 2027
4. Employee AI Monitoring Notice
Notify employees if AI systems are used to monitor their work performance or productivity. Covers AI-assisted performance management, productivity scoring, and automated scheduling. Must be clear, written notice before deployment. Art. 26(7): before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers. As an Art. 26 high-risk deployer obligation this follows the Digital Omnibus deferral to 2 Dec 2027.
Due: December 2, 2027
5. Human Oversight Procedures
Implement procedures ensuring human review of high-risk AI decisions. Must document how humans can intervene, override, or halt the AI system. Human oversight must be technically possible and operationally implemented — a nominal checkbox does not suffice.
Due: December 2, 2027
6. Technical Documentation (Annex IV)
Providers of high-risk AI systems must maintain Annex IV technical documentation: system description, development methodology, training data summary, testing procedures, accuracy metrics, post-market monitoring plan.
Due: December 2, 2027
7. Record Keeping & Logging
Deployers of high-risk AI must keep logs for minimum 6 months. Providers must keep technical documentation for 10 years. Logs must enable reconstruction of circumstances leading to any incident.
Due: December 2, 2027
8. Conformity Assessment (High-Risk)
Providers of Annex III high-risk AI systems must conduct conformity assessment before placing on market. Most systems: self-assessment via internal checks. Biometric and critical infrastructure: third-party assessment required. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).
Due: December 2, 2027
9. Prohibited: Non-Consensual Intimate Imagery & CSAM-Generation AI
Digital Omnibus amendment (Regulation (EU) 2026/1744) added two new Art. 5(1) prohibited practices, effective 2 Dec 2026: (ba) placing on market, putting into service, or using AI systems that generate or manipulate realistic depictions of an identifiable person's intimate body parts or sexually explicit activity without that person's freely-given, specific, informed, unambiguous, and explicit consent (targets "nudifier" apps); (bb) AI systems designed to generate child sexual abuse material, subject to narrow law-enforcement/crime-prevention/compliance-red-teaming exceptions. Providers are banned if generation/manipulation is the intended purpose OR a reasonably foreseeable outcome absent adequate technical safeguards (data cleaning, refusal training, content filtering, abuse detection); deployers are banned only for actual use to generate prohibited material.
Due: December 2, 2026
10. GPAI Model Obligations
General Purpose AI (GPAI) model providers must publish technical documentation, maintain copyright compliance policy, and train providers who use their models. Systemic risk GPAI (>10^25 FLOPs training compute) have additional obligations: adversarial testing, serious incident reporting, cybersecurity measures.
Due: August 2, 2025
Implementation Steps
11. Answer: does your startup use AI in any customer-facing way?
12. Answer: do you have any customers in the EU? → EU AI Act applies
13. Answer: do you use AI for hiring? → Check NYC, Colorado, Illinois laws
14. Answer: do you process personal data with AI? → GDPR/CCPA applies
15. Write a simple AI Acceptable Use Policy for your employees
16. Add an AI transparency notice to your privacy policy
17. Document which AI APIs/tools you use and why
18. If you use ChatGPT/Claude/Gemini for customer data: check vendor data agreements
19. Subscribe to Aegis Firma to auto-monitor regulation changes