EU AI Act compliance templates

Thirteen template families — 24 documents in total — cover every current EU AI Act obligation and the full Annex III high-risk preparation set. Each page below explains what the law requires, what the template contains, and who needs it.

Last reviewed: 26 August 2026 · All documents aligned to Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

AI Literacy Policy

An AI literacy policy is the internal document that records the measures your organisation takes to support the development of AI literacy among staff and others using AI on its behalf, as Article 4 of the EU AI Act (Regulation (EU) 2024/1689, as amended by the Digital Omnibus, Regulation (EU) 2026/1744) requires.

AI System Inventory

An AI system inventory is a single register of every AI system a company builds, buys or uses, recording for each what it does, the company's legal role (provider, deployer, importer, distributor) and its risk tier under Regulation (EU) 2024/1689.

Internal AI-Use Policy

An internal AI use policy is the company rulebook for how staff may use AI at work: which tools are approved, what data may go into them, which uses are off-limits, and what to do when something goes wrong.

Prohibited-Practices Screening

A prohibited practices screening is a documented check of every AI system against the practices banned outright by Article 5 of the EU AI Act (Regulation (EU) 2024/1689).

Chatbot Disclosure

A chatbot disclosure is the notice that tells people they are interacting with an AI system rather than a human.

AI Content-Marking SOP

Content marking under Article 50(2) of the EU AI Act (Regulation (EU) 2024/1689) is the duty of providers of generative AI systems to mark synthetic audio, image, video and text in a machine-readable format, so software can detect that the content was artificially generated or manipulated.

Vendor Due-Diligence Questionnaire

An AI vendor due diligence questionnaire is a structured question set you send to every supplier whose product contains AI you deploy, to verify their compliance posture under the EU AI Act (Regulation (EU) 2024/1689) before and during adoption.

Risk Classification Assessment

An EU AI Act risk classification assessment is the documented determination of whether an AI system is prohibited, high-risk or neither under Article 6 and Annex III of Regulation (EU) 2024/1689 (as amended by Regulation (EU) 2026/1744).

Annex IV Technical Documentation

Annex IV technical documentation is the file that Article 11 of the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744) requires providers of high-risk AI systems to draw up before market placement and keep up to date afterwards, following the content list in Annex IV — system description, design and data, oversight, testing, risk management, standards, declaration of conformity and post-market monitoring.

Fundamental Rights Impact Assessment (FRIA)

A fundamental rights impact assessment (FRIA) is the assessment that Article 27 of the EU AI Act (Regulation (EU) 2024/1689) requires certain deployers of Annex III high-risk AI systems to perform before first use: public bodies, private entities providing public services, and any deployer using AI for creditworthiness assessment or life and health insurance pricing (Annex III points 5(b)–(c)).

Human Oversight Protocol

Human oversight under Article 14 of the EU AI Act (Regulation (EU) 2024/1689) means high-risk AI systems must be designed and developed so that natural persons can effectively oversee them in use, to prevent or minimise risks to health, safety and fundamental rights; Article 26 adds the deployer's side — assigning oversight to people with the necessary competence, training, authority and support.

Post-Market Monitoring Plan

A post-market monitoring plan is the documented system by which a provider of a high-risk AI system actively and systematically collects and analyses data on the system's real-world performance throughout its lifetime, as required by Article 72 of the EU AI Act (Regulation (EU) 2024/1689); Article 73 adds the duty to report serious incidents within strict deadlines (15 days standard, 2 days for widespread infringement or critical-infrastructure disruption, 10 days for a death).

Compliance Calendar

An EU AI Act compliance checklist for 2026 is a dated record of which obligations under Regulation (EU) 2024/1689 apply to your company now and which come later, using the timeline as amended by the Digital Omnibus (Regulation (EU) 2026/1744, adopted 8 July 2026, in force since 27 July 2026).

Get all 24 documents in one kit

Launch price €149, twelve months of updates included.

See the full kit