Skip to content
19 items · Free checklist

EU Artificial Intelligence Act Compliance Checklist 2026

Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, cr

Maximum penalty: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities

Enforcement: August 2, 2026

Complete each item below to achieve compliance. Use Aegis Firma to generate all required documentation automatically.

Regulatory Requirements

1. AI Risk Classification

Classify each AI system you use or deploy as Minimal, Limited, High, or Unacceptable risk under EU AI Act Annex III. High-risk categories: biometric systems, critical infrastructure, education/vocational training, employment/HR, essential services (credit, insurance), law enforcement, migration/asylum, administration of justice. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).

Due: December 2, 2027

2. Transparency Disclosures

Inform users when they are interacting with AI (chatbots, generated content, AI-assisted decisions). Deepfake content must be labeled. AI chatbots must identify themselves. Cannot deploy AI that impersonates humans without disclosure.

Due: August 2, 2026

3. AI Acceptable Use Policy

Document how employees may and may not use AI tools within your organization. Required for deployers of high-risk systems. Must include authorized uses, restrictions, human oversight requirements, and escalation procedures.

Due: December 2, 2027

4. Employee AI Monitoring Notice

Notify employees if AI systems are used to monitor their work performance or productivity. Covers AI-assisted performance management, productivity scoring, and automated scheduling. Must be clear, written notice before deployment. Art. 26(7): before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers. As an Art. 26 high-risk deployer obligation this follows the Digital Omnibus deferral to 2 Dec 2027.

Due: December 2, 2027

5. Human Oversight Procedures

Implement procedures ensuring human review of high-risk AI decisions. Must document how humans can intervene, override, or halt the AI system. Human oversight must be technically possible and operationally implemented — a nominal checkbox does not suffice.

Due: December 2, 2027

6. Technical Documentation (Annex IV)

Providers of high-risk AI systems must maintain Annex IV technical documentation: system description, development methodology, training data summary, testing procedures, accuracy metrics, post-market monitoring plan.

Due: December 2, 2027

7. Record Keeping & Logging

Deployers of high-risk AI must keep logs for minimum 6 months. Providers must keep technical documentation for 10 years. Logs must enable reconstruction of circumstances leading to any incident.

Due: December 2, 2027

8. Conformity Assessment (High-Risk)

Providers of Annex III high-risk AI systems must conduct conformity assessment before placing on market. Most systems: self-assessment via internal checks. Biometric and critical infrastructure: third-party assessment required. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).

Due: December 2, 2027

9. Prohibited: Non-Consensual Intimate Imagery & CSAM-Generation AI

Digital Omnibus amendment (Regulation (EU) 2026/1744) added two new Art. 5(1) prohibited practices, effective 2 Dec 2026: (ba) placing on market, putting into service, or using AI systems that generate or manipulate realistic depictions of an identifiable person's intimate body parts or sexually explicit activity without that person's freely-given, specific, informed, unambiguous, and explicit consent (targets "nudifier" apps); (bb) AI systems designed to generate child sexual abuse material, subject to narrow law-enforcement/crime-prevention/compliance-red-teaming exceptions. Providers are banned if generation/manipulation is the intended purpose OR a reasonably foreseeable outcome absent adequate technical safeguards (data cleaning, refusal training, content filtering, abuse detection); deployers are banned only for actual use to generate prohibited material.

Due: December 2, 2026

10. GPAI Model Obligations

General Purpose AI (GPAI) model providers must publish technical documentation, maintain copyright compliance policy, and train providers who use their models. Systemic risk GPAI (>10^25 FLOPs training compute) have additional obligations: adversarial testing, serious incident reporting, cybersecurity measures.

Due: August 2, 2025

Implementation Steps

11. Classify all AI-assisted clinical tools under EU AI Act Article 6(1) + Annex I — the MDR/IVDR route (most are high-risk)

12. Ensure AI diagnostic tools have CE marking if used in EU

13. Document training data sources, accuracy metrics, and known limitations for each AI tool

14. Implement human oversight for all AI diagnostic or treatment recommendations

15. Train clinical staff on AI tool limitations and override procedures

16. Maintain audit trails for AI-assisted clinical decisions

17. Review FDA AI/ML-based Software as a Medical Device (SaMD) guidance if US-based

18. Conduct bias testing across patient demographic groups

19. Establish procedures for AI-related adverse events