Guide · Last reviewed 26 August 2026

EU AI Act compliance checklist: seven steps, with articles and deadlines

EU AI Act compliance in 2026 comes down to seven steps: inventory your AI systems, determine your role per system (Articles 3(3)-(4)), screen against the Article 5 prohibitions (in force since 2 February 2025; new CSAM/NCII prohibitions from 2 December 2026), take Article 4 AI literacy measures, implement your Article 50 transparency duties (since 2 August 2026), run vendor due diligence, and prepare any high-risk systems for 2 December 2027 (Annex III) or 2 August 2028 (Annex I).

Last reviewed: 26 August 2026 · Primary source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

Step 1 — Build an AI system inventory (foundation for everything)

You cannot classify what you have not listed. Start with a company-wide inventory of every AI system you use, develop, sell or embed — including the unglamorous ones: the chatbot on your website, the CV-screening feature in your HR suite, the generative AI tools your marketing team uses, the scoring module inside your ERP. For each entry record: the system and vendor, what it does, who operates it, what data goes in, whether outputs affect individuals, and whether it touches an Annex III area.

There is no general statutory inventory duty, but every subsequent obligation — role assessment, prohibition screening, transparency, high-risk classification — applies per system, so the inventory is the practical backbone of compliance. Our AI System Inventory template gives you the column structure; a first pass takes hours in a small company, not weeks.

Step 2 — Determine your role for each system (Articles 3(3) and 3(4))

The AI Act attaches duties to roles, not to companies as such. For each system in your inventory, decide whether you are the provider (you developed it or have it developed and place it on the market or put it into service under your own name) or the deployer (you use it under your authority in a professional context). The same company is routinely a deployer for one system and a provider for another.

Watch the traps: putting your own name or trademark on a third-party system, or substantially modifying a high-risk system, can make you the provider under Article 25(1). Merely calling a vendor's API does not. Full analysis: provider vs deployer.

Step 3 — Screen against the Article 5 prohibitions (since 2 Feb 2025; additions 2 Dec 2026)

The prohibited practices have applied since 2 February 2025 and carry the highest fines (up to €35 million or 7% of worldwide turnover). Screen every system against the list: manipulative or exploitative techniques causing significant harm, social scoring, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in the workplace or education (with narrow exceptions), biometric categorisation inferring sensitive attributes, and real-time remote biometric identification in public spaces for law enforcement.

From 2 December 2026, the Digital Omnibus (Regulation (EU) 2026/1744) adds prohibitions on AI systems that generate or manipulate child sexual abuse material or non-consensual intimate imagery. For providers of general-purpose generative systems the new prohibition is conditional: it applies where such content is the intended purpose or a reasonably foreseeable and reproducible outcome and adequate safeguards are absent — not an absolute ban on every generative system capable of misuse. For most SMEs the screening result will be 'no prohibited practices' — but you should be able to show you actually checked, which is what our Prohibited Practices Screening template documents.

Step 4 — Put Article 4 AI literacy measures in place (since 2 Feb 2025)

Article 4 — as amended by the Omnibus — requires providers and deployers to take measures that support the development of a sufficient level of AI literacy among staff and other persons operating or using AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context of use. Two things it does not require: a guaranteed competence level for any individual, and formal training courses as the only acceptable measure — usage guidelines, role-specific briefings and documented onboarding all count.

What you need in practice: a short AI literacy policy, an assignment of measures to roles, and records showing the measures happened. Any review cadence (annual refreshers, onboarding within 30 days) is your internal policy choice, not a statutory requirement — label it as such. See Article 4 explained.

Step 5 — Implement your Article 50 transparency duties (since 2 Aug 2026)

Article 50 splits by role. Providers: design systems that interact with natural persons so people know they are dealing with AI (Article 50(1) — the Commission's July 2026 guidelines confirm this targets genuine two-way conversational exchanges), and mark synthetic audio, image, video and text output in a machine-readable, detectable way (Article 50(2)). Generative systems already on the market before 2 August 2026 have a grace period until 2 December 2026 for the marking duty. Deployers: inform people exposed to emotion recognition or biometric categorisation (Article 50(3)), and disclose deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest (Article 50(4), with an exception where there is human editorial control).

If you only use third-party generative tools, the Article 50(2) marking duty stays with the tool's provider — your exposure is Article 50(4) disclosure. Templates: Chatbot Disclosure and AI Content Marking. Full guide: Article 50 transparency.

Steps 6 and 7 — Vendor due diligence and the high-risk timeline

Step 6 — vendor due diligence. As a deployer you depend on your vendors for marking, documentation and instructions for use. Before onboarding an AI tool, verify: the vendor's role and yours, whether the tool touches Annex III areas, what Article 50 features it ships with, where data goes (GDPR roles — a vendor is a processor only if it actually processes personal data on your behalf), and contractual commitments to AI Act compliance. Our Vendor Due Diligence template turns this into a questionnaire.

Step 7 — high-risk preparation. If anything in your inventory plausibly falls under Annex III (employment, credit, education, essential services, biometrics and other listed areas), diarise 2 December 2027; product-embedded AI under Annex I follows on 2 August 2028. Providers face the full Chapter III programme (risk management, data governance, Annex IV technical documentation, conformity assessment, registration); deployers face Article 26 duties and, for some, a fundamental rights impact assessment under Article 27. Start 12-18 months ahead — and if you plan to rely on the Article 6(3) derogation, remember the assessment must be documented and registered, and profiling of natural persons is always high-risk. Use the Risk Classification template and the Compliance Calendar to track it.

Related reading

Frequently asked

What is legally required right now (August 2026)?+

Article 5 prohibition screening (in force since 2 February 2025), Article 4 AI literacy measures (since 2 February 2025), and Article 50 transparency duties (since 2 August 2026, with marking grace until 2 December 2026 for pre-existing generative systems). GPAI model rules apply to model providers. High-risk obligations are not yet applicable.

How long does the checklist take for a small company?+

A typical SME using off-the-shelf AI tools can complete the inventory, role mapping, prohibition screening and literacy measures in a few working days spread over two to four weeks. High-risk preparation is the only genuinely large workstream, and it only applies if you have Annex III or Annex I systems.

Do I need to repeat the checklist when I adopt a new AI tool?+

Yes, per system: add it to the inventory, determine your role, screen it against Article 5, check which Article 50 duties apply, and run vendor due diligence. This is why a standing intake process beats a one-off project.

Is an AI system inventory legally mandatory?+

There is no general statutory inventory duty for deployers of ordinary systems. But role assessment, prohibition screening and transparency duties all apply per system, so an inventory is the only practical way to evidence compliance — and registration duties do exist for high-risk systems and Article 6(3) self-assessments.

Primary sources

See exactly what applies to your company

Six questions, two minutes, no signup.

Run the check