Free download · No signup · Last reviewed 26 August 2026
Free EU AI Act compliance checklist and AI inventory — no signup
Download our free EU AI Act compliance checklist (PDF) and AI System Inventory (Lite) spreadsheet — no signup required. Both reflect the Act as amended by the Digital Omnibus, Regulation (EU) 2026/1744 (in force 27 July 2026), covering the duties binding in 2026 — Articles 4, 5 and 50 — and the high-risk deadlines of 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
Last reviewed: 26 August 2026 · Aligned to Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
Two free, immediately usable files: a PDF checklist that takes you from a blank page to documented baseline compliance in eleven steps, each with the article reference and its deadline, and an AI System Inventory (Lite) spreadsheet with the exact columns you need to record every AI system, its vendor, your role and its risk status. No email address, no account — click and download.
Both files reflect the law as it stands after the Digital Omnibus (Regulation (EU) 2026/1744): the softened Article 4 literacy standard, the Article 50 transparency split that has applied since 2 August 2026, the new prohibitions arriving on 2 December 2026, and the postponed high-risk deadlines. If a checklist you downloaded elsewhere still says high-risk obligations start in August 2026 — it is out of date.
The eleven steps in the checklist
Fill the AI System Inventory (Lite): system, vendor, purpose, owner, data processed, who is affected by outputs. Include third-party tools like generative AI assistants and AI features inside SaaS products. This inventory is the backbone for every later step.
Record provider or deployer per system. You are a provider if you develop a system or offer one under your own name or trademark; a deployer if you use it professionally under your authority. Watch Article 25(1): white-labelling or substantially modifying a high-risk system makes you its provider.
In force since 2 February 2025: manipulative techniques causing significant harm, social scoring, untargeted facial-image scraping, emotion recognition at work and in education, and the other listed practices. Document the outcome even when it is 'nothing prohibited' — fines here are the highest tier.
Regulation (EU) 2026/1744 adds prohibitions on AI systems generating or manipulating child sexual abuse material or non-consensual intimate imagery, applying from 2 December 2026. For providers of generative systems the prohibition is conditional on intended purpose or reasonably foreseeable, reproducible outcomes without adequate safeguards.
Since 2 February 2025, take measures supporting the development of sufficient AI literacy among staff using AI on your behalf — a short policy, role-appropriate guidance and records suffice. As amended by the Omnibus, no guaranteed competence level per individual is required, and training is one possible measure, not the only one.
Since 2 August 2026: design systems interacting with people so they know they are dealing with AI, and mark synthetic audio, image, video and text in machine-readable form. Generative systems on the market before 2 August 2026 have until 2 December 2026 to comply with marking. No SME exemption.
Inform people exposed to emotion recognition or biometric categorisation, and disclose deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest. Marking of synthetic output stays with the tool's provider — using a third-party generative tool does not transfer that duty to you.
Verify the vendor's role and yours, Annex III exposure, built-in Article 50 features, data flows and GDPR roles, and contractual AI Act commitments. Repeat the inventory, role and screening steps for every new tool at intake.
Recruitment and candidate screening, creditworthiness scoring, education, essential services, biometrics and the other Annex III areas become high-risk on 2 December 2027. Systems performing profiling of natural persons are always high-risk; an Article 6(3) derogation requires a documented assessment and registration under Article 49(2).
Providers of Annex III systems need risk management, data governance, Annex IV technical documentation (simplified form available for SMEs), human oversight design, conformity assessment and registration by 2 December 2027 — realistically a 12-18 month programme. Annex I product-embedded AI follows on 2 August 2028.
Diarise 2 December 2026, 2 December 2027 and 2 August 2028, review the inventory at least when tools change, and record who signed off each step. Fines are proportionate for SMEs, start-ups and small mid-caps — the lower of the percentage or fixed amount (Article 99(6)) — but only documentation proves compliance.
What's in the free download
The PDF checklist contains the eleven steps above in worksheet form: each with its article reference, deadline, a short 'how to know you are done' test, and a sign-off line. The AI System Inventory (Lite) is a ready-to-fill spreadsheet with columns for system, vendor, purpose, owner, data categories, affected persons, your role (provider/deployer), Article 5 screening result, Article 50 duties and Annex III flag — the same structure our full kit builds on, so nothing you fill in is throwaway work. Both are yours to use and adapt internally without attribution.
When you need more than the checklist
The checklist tells you what to do; at some point you need the documents that do it: an AI literacy policy your team can sign, a prohibited-practices screening record an auditor can read, chatbot disclosure and content-marking texts, a vendor due diligence questionnaire, and — for high-risk exposure — risk classification, Annex IV technical documentation, FRIA and human-oversight templates. The RegShelf EU AI Act Kit packages all of these, Omnibus-aligned and maintained as guidance lands, so you implement each checklist step by adapting a document instead of drafting one. Start with the free files, and upgrade when you hit a step you would rather not write from scratch.
Frequently asked
Is the checklist really free — what is the catch?+
It is free with no signup, no email and no trial. The checklist and inventory cover the assessment and planning layer; if you then want the implementation documents — policies, screening records, disclosure texts, due diligence questionnaires and the high-risk templates — those are what the paid RegShelf kit provides.
Is the checklist up to date with the 2026 Digital Omnibus?+
Yes. It reflects Regulation (EU) 2026/1744 (in force 27 July 2026): the amended Article 4 standard, the new prohibitions from 2 December 2026, the Article 50(2) marking grace period, and the high-risk deadlines of 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
Who is the checklist for?+
SMEs and mid-sized companies that use or provide AI systems in the EU — compliance owners, founders, ops and IT leads. It assumes no legal background: every step names the article, the deadline and the concrete output you should have at the end.
Ready to go beyond the checklist?
The EU AI Act Kit fills in what the checklist identifies: 24 ready-to-sign documents, launch price €149.
See the full kit