EU AI Act Compliance Checklist: August 2026 Deadline
TL;DR — The EU AI Act compliance deadline for high-risk AI systems is August 2, 2026. Fines reach EUR 35M or 7% of global turnover. This 12-step checklist covers AI inventory, risk classification, conformity assessment, risk management, human oversight, transparency, logging, data governance, GPAI obligations, vendor management, documentation, and post-market monitoring. If your AI touches anyone in the EU, you must comply — regardless of where your company is headquartered.
The EU AI Act (Regulation 2024/1689) entered into force on August 1, 2024. Its obligations phase in across four dates:
| Date | Obligation | Status |
|---|---|---|
| February 2, 2025 | Prohibited AI practices + AI literacy | In effect |
| August 2, 2025 | GPAI model obligations + governance rules | In effect |
| August 2, 2026 | High-risk AI system obligations | Upcoming |
| August 2, 2027 | Full applicability (remaining provisions) | Future |
The August 2, 2026 deadline is the one enterprises cannot miss. It triggers the full set of obligations for high-risk AI systems — risk management, conformity assessment, human oversight, transparency, logging, and post-market monitoring. Non-compliance carries fines up to EUR 35 million or 7% of global annual turnover, whichever is higher (European Commission 2024).
This checklist provides 12 actionable steps. For organizations also working on GDPR and AI compliance, the two frameworks overlap significantly — both require data protection by design, documentation, and impact assessments.
Who Must Comply With the EU AI Act?
The EU AI Act applies to any AI system whose output is used in the EU, regardless of where the provider is headquartered. If your AI touches EU users, customers, or data subjects, you must comply. A US company deploying AI for EU customers is subject to the Act. A Japanese company whose AI outputs are used by EU residents is subject to the Act.
The Act defines four roles:
- Provider: Develops an AI system and places it on the market (bears the most obligations)
- Deployer: Uses an AI system under its authority (bears use-case obligations)
- Importer: Places a third-country AI system on the EU market
- Distributor: Makes an AI system available on the EU market
Most enterprises are deployers. If you build AI in-house and use it internally, you are both provider and deployer. If you buy AI from a vendor, you are a deployer and the vendor is the provider.
EU AI Act Risk Classifications
The Act classifies AI systems into four risk tiers, each with different obligations:
practice?} Q1 -->|Yes| STOP[Prohibited — banned entirely] Q1 -->|No| Q2{High-risk?
Annex I or III} Q2 -->|Yes| HR[High-risk — full obligations
conformity assessment, risk mgmt,
human oversight, logging, transparency] Q2 -->|No| Q3{Limited risk?
transparency only} Q3 -->|Yes| LR[Limited risk — transparency obligations
users must know they interact with AI] Q3 -->|No| MR[Minimal risk — no obligations
voluntary codes of conduct]
Prohibited AI practices (in effect since February 2025)
- Social scoring by public authorities
- Real-time remote biometric identification in public spaces (with narrow exceptions)
- Manipulative or deceptive techniques that cause harm
- Exploitation of vulnerabilities (age, disability, social/economic situation)
- Predictive policing based solely on profiling
- Untargeted facial image scraping
- Emotion recognition in workplaces and schools (with exceptions)
- Biometric categorization inferring sensitive attributes
High-risk AI systems (deadline: August 2, 2026)
High-risk categories include:
- Employment: CV screening, job candidate evaluation, promotion decisions
- Credit assessment: Creditworthiness, credit scoring, risk pricing
- Biometric identification: Remote biometric identification, categorization
- Critical infrastructure: Safety components in transport, water, gas, electricity
- Education: Admissions, exam scoring, student evaluation
- Essential services: Access to public assistance, healthcare triage, insurance pricing
- Law enforcement: Polygraphs, evidence reliability assessment, offense profiling
- Migration: Visa eligibility, asylum application assessment, security risk detection
- Democratic processes: Election influence, voter behavior prediction
The 12-Step EU AI Act Compliance Checklist
Step 1: Build an AI system inventory
Catalog every AI system your organization uses, builds, or procures. For each system, record:
- System name and vendor
- Provider vs. deployer role
- Purpose and use case
- Data sources (training, input, output)
- EU exposure (users, data subjects, market presence)
- Risk tier (prohibited, high-risk, limited, minimal)
This inventory is the foundation for everything else. You cannot comply with what you have not identified. Include shadow AI — unsanctioned AI tools used by employees count if they process EU data.
Step 2: Classify each AI system by risk tier
For each system in your inventory, determine its risk classification under the Act. Use Annex III (high-risk categories) and Annex I (safety components). If a system falls into a high-risk category, document the classification rationale.
Classification is the gating decision. It determines which obligations apply and how much compliance work is needed. When in doubt, classify conservatively — the cost of over-compliance is lower than the cost of a misclassification.
Step 3: Discontinue prohibited AI practices
If any system in your inventory uses prohibited practices, discontinue them immediately. These prohibitions have been in effect since February 2, 2025. Continuing to use prohibited AI is the most expensive violation under the Act.
Step 4: Implement a risk management system
High-risk AI systems require a continuous risk management system throughout their lifecycle. This includes:
- Identifying and analyzing known and foreseeable risks
- Estimating and evaluating risks when the AI is used as intended
- Adopting appropriate risk mitigation measures
- Testing for residual risks before market placement
The risk management system must be documented, versioned, and updated when the AI system is modified.
Step 5: Conduct conformity assessment
High-risk AI systems require a conformity assessment before market placement. The assessment type depends on the system:
- Internal control (Annex VI): For most high-risk systems, the provider conducts the assessment
- Notified body: For biometric systems and systems where the provider does not apply harmonized standards
The conformity assessment verifies that the AI system meets all high-risk requirements. The results must be documented in a technical file.
Step 6: Ensure human oversight
High-risk AI systems must be designed to allow human oversight during use. Oversight must be meaningful — not a rubber stamp. Human operators must be able to:
- Understand the system's output and limitations
- Override or reverse the system's decisions
- Disregard the system's output in appropriate circumstances
For AI agent approval gates, this requirement connects directly to the Act's human-in-the-loop mandate.
Step 7: Implement transparency requirements
High-risk AI systems must include instructions for use that enable deployers to interpret the system's output. Limited-risk AI systems must inform users they are interacting with AI. Deep fakes and AI-generated content must be labeled as artificial.
Transparency also extends to preventing sensitive data from leaking into AI prompts — deployers must understand what data the system processes and how it is used.
Step 8: Enable automatic logging and event tracking
High-risk AI systems must automatically log events during operation. Logs must:
- Record the period of each use of the system
- Store the reference database against which input data was checked
- Log the results of the evaluation
- Be time-stamped and protected against alteration
Logs must be kept for a period appropriate to the intended purpose. For AI systems used in law enforcement, logging requirements are stricter.
Step 9: Ensure data governance and quality
High-risk AI systems must be trained on datasets that meet quality criteria:
- Relevant, representative, and free of errors
- Complete as much as possible
- Consider the characteristics of the specific geographical, behavioral, or functional setting
Data governance must include bias examination and mitigation. Training data must be subject to data management and analysis appropriate to the system's purpose.
Step 10: Meet GPAI model obligations
If you use or provide GPAI models (GPT-4, Claude, Gemini, Llama), additional obligations apply:
- Publish technical documentation (training data, model architecture, capabilities, limitations)
- Comply with EU copyright law in training data
- Provide a summary of training content
- Implement information-sharing downstream to deployers
Systemic-risk GPAI models (those with training compute above 10^25 FLOPs) face additional obligations: model evaluation, adversarial testing, incident reporting, and cybersecurity measures.
Step 11: Manage vendor compliance
If you procure AI from third parties, you are a deployer. Your obligations include:
- Verifying the provider has completed conformity assessment for high-risk systems
- Using the AI system according to its instructions for use
- Monitoring the system's operation
- Reporting serious incidents to the relevant authority
Request documentation from vendors: technical files, conformity assessment results, risk management documentation. If a vendor cannot provide these, that is a compliance risk for your organization.
Step 12: Establish post-market monitoring
High-risk AI system providers must establish a post-market monitoring system. This includes:
- Collecting and analyzing data on the AI system's performance in real-world use
- Evaluating continued compliance with the Act
- Reporting serious incidents to market surveillance authorities
- Implementing corrective actions when needed
Post-market monitoring must be proportionate to the risks and documented in a plan.
EU AI Act Penalties
| Violation type | Maximum fine |
|---|---|
| Prohibited AI practices | EUR 35M or 7% of global annual turnover |
| High-risk obligations (risk management, logging, transparency) | EUR 15M or 3% of global annual turnover |
| Supplying incorrect information to authorities | EUR 7.5M or 1% of global annual turnover |
| GPAI model obligations | EUR 15M or 3% of global annual turnover |
Fines are imposed by national competent authorities. The actual amount depends on the infringement's nature, gravity, and duration, plus the size and market position of the offender.
EU AI Act Compliance Timeline
FAQ
When is the EU AI Act compliance deadline?
The EU AI Act has staggered deadlines. Prohibited AI practices applied from February 2, 2025. GPAI model obligations applied from August 2, 2025. High-risk AI system obligations apply from August 2, 2026. Full applicability is August 2, 2027.
What are the EU AI Act penalties for non-compliance?
Fines reach up to EUR 35 million or 7% of global annual turnover for prohibited-AI violations. Missing risk-management, logging, or transparency duties costs up to EUR 15 million or 3% of turnover. Supplying incorrect information to authorities costs up to EUR 7.5 million or 1%.
Does the EU AI Act apply to non-EU companies?
Yes. The EU AI Act applies to any AI system whose output is used in the EU, regardless of where the provider is headquartered. If your AI touches EU users, customers, or data subjects, you must comply.
What is a high-risk AI system under the EU AI Act?
High-risk AI systems include those used in employment (candidate screening), credit assessment, biometric identification, critical infrastructure, education, essential public services, law enforcement, migration, and democratic processes. They require conformity assessments, risk management systems, and human oversight.
What is a GPAI model under the EU AI Act?
GPAI (General-Purpose AI) models are foundation models like GPT-4, Claude, and Gemini that can serve a wide range of purposes. GPAI providers must publish technical documentation, comply with copyright law, and provide training content summaries. Systemic-risk GPAI models face additional obligations.
Want a self-hosted AI company brain that does all of this out of the box?
Book a demo →