TL;DR: December 2, 2027 is the EU AI Act deadline for high-risk AI systems (extended by EU Digital Omnibus). 35 checklist items: 15 for providers, 10 for deployers, 10 for both. Start with Annex III classification, then Annex IV documentation for each high-risk system.
The EU AI Act compliance landscape is complicated by jargon, overlapping obligations, and guidance that keeps arriving. This checklist cuts through it: 35 concrete items, organized by whether you are a provider or a deployer, with the article and deadline for each.
Not everything here is due December 2, 2027. Prohibited practices (Article 5) already applied from February 2025. GPAI obligations applied from August 2026. The items marked with the December 2, 2027 deadline are the high-risk system obligations newly applicable on that date (extended from August 2, 2026 by the EU Digital Omnibus, May 2026).
Who this checklist is for
Use this checklist if you develop AI systems for sale or deployment in the EU (provider), you use AI systems in your EU operations in a high-risk context (deployer), or you do both.
Skip this checklist if your only AI use is low-risk tools (document summarizers, coding assistants used internally) that do not fall into an Annex III category and do not affect EU residents in consequential ways.
Not sure which applies? The Annex III classification item below is your starting point.
Section 1: Both providers and deployers
These 10 items apply regardless of whether you built the AI system or are using someone else's.
1. Annex III classification complete
Status: [ ] Done / [ ] In progress / [ ] Not started
Work through the Annex III categories for every AI system you develop or use:
- Biometric identification and categorization
- Critical infrastructure management
- Education and vocational training
- Employment and worker management (CV screening, performance monitoring, task allocation)
- Access to essential private services (credit scoring, insurance underwriting)
- Access to public services and benefits
- Law enforcement
- Migration and asylum
- Administration of justice
Each AI system used in an EU context should be tagged: High Risk (Annex III), Limited Risk (Article 50 transparency), or Minimal Risk (no specific obligations).
Owner: AI governance lead or legal
2. No prohibited AI practices in use
Status: [ ] Done / [ ] In progress / [ ] Not started
Applicable since: February 2, 2025
Article 5 prohibitions that must not be in your AI stack:
- No subliminal manipulation systems that distort behavior without awareness
- No exploitation of vulnerability (age, disability) to distort behavior
- No real-time remote biometric surveillance in public spaces (narrow law enforcement exceptions exist)
- No social scoring by public authorities
- No predictive policing based solely on profiling
- No emotion recognition in workplace or educational settings (outside narrow exceptions)
- No facial recognition scraping from the internet or CCTV to build databases
Owner: Legal, CISO
3. GPAI transparency obligations (if using or distributing GPAI models)
Status: [ ] Done / [ ] In progress / [ ] Not started
Applicable since: August 2, 2025
If you distribute products or services that use a general-purpose AI model (GPAI), or if you are a GPAI provider yourself, Article 50 obligations apply. Synthetic content generated by AI must be marked as AI-generated when it could mislead users. Chatbots and AI-generated media have specific disclosure requirements.
Owner: Product, Legal
4. Vendor DPA covers EU AI Act deployer obligations
Status: [ ] Done / [ ] In progress / [ ] Not started
Standard SaaS data processing agreements were not drafted for EU AI Act obligations. For each high-risk AI vendor, confirm the agreement addresses: training data opt-out, incident notification timeline, and human oversight support documentation. See the AI vendor contract red flags checklist.
Owner: Legal, Procurement
5. AI register / inventory maintained
Status: [ ] Done / [ ] In progress / [ ] Not started
A current list of every AI system in use, tagged by Annex III risk category, with the responsible owner for each. This is the prerequisite for all other compliance steps. See the free AI register template.
Owner: AI governance lead
6. AI governance policy or acceptable use policy in place
Status: [ ] Done / [ ] In progress / [ ] Not started
An internal policy document that specifies which AI systems are approved, what uses are prohibited, and the escalation path for AI incidents. Needed to demonstrate governance structure to regulators.
Owner: Legal, HR
7. Shadow AI detection process in place
Status: [ ] Done / [ ] In progress / [ ] Not started
Unapproved AI tools in use by employees can create Annex III obligations you are not managing. A process for detecting shadow AI (expense audits, software inventory scans, manager surveys) is a prerequisite for a complete compliance posture.
Owner: IT, AI governance lead
8. Incident response plan covers AI incidents
Status: [ ] Done / [ ] In progress / [ ] Not started
Most cybersecurity incident response plans do not cover AI performance failures. EU AI Act incident reporting obligations run to different timelines (Article 73: 15 days for providers) than GDPR breach notification (Article 33: 72 hours). Your IR plan should address both. See the AI incident response plan guide.
Owner: CISO, Legal
9. Team AI literacy training in place
Status: [ ] Done / [ ] In progress / [ ] Not started
Article 4 of the EU AI Act requires providers and deployers to ensure staff working with AI systems have sufficient AI literacy. This does not require certification, but it does require a documented effort to educate employees who interact with AI systems.
Owner: HR, Training
10. EU national competent authority identified for your sector
Status: [ ] Done / [ ] In progress / [ ] Not started
Incident reporting under Article 73 goes to the national competent authority (NCA) in the member state where the incident occurred. Identify which NCA regulates your sector in your primary EU markets now, before an incident occurs.
Owner: Legal
Section 2: Provider obligations
If you develop AI systems and place them on the EU market (or deploy them in EU operations), these 15 items apply.
11. Technical documentation per Annex IV
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Annex IV requires technical documentation covering nine areas:
- General description: purpose, intended use, version, date of placement on market
- Detailed description of system elements (training, validation, testing methodology)
- Detailed information about the monitoring, functioning, and control of the system
- Description of the risk management system
- Changes made to the system over its lifecycle
- Assessment of the standards applied and solutions adopted where harmonized standards are not fully applied
- EU Declaration of Conformity copy
- Post-market monitoring plan
- Copy of the instructions for use
This documentation must be maintained and available to NCAs for 10 years after placement on the market.
Owner: Engineering, Legal
12. Risk management system documented (Article 9)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 9 requires an iterative risk management process throughout the AI system lifecycle. Minimum requirements:
- Known and reasonably foreseeable risks identified
- Risks estimated and evaluated (including from reasonably foreseeable misuse)
- Risk evaluation after post-market monitoring data
- Appropriate risk management measures adopted
- Residual risks communicated in instructions for use
The risk management system is not a one-time assessment. It must be updated over the system's lifecycle.
Owner: Product, Engineering, Legal
13. Data governance documentation (Article 10)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 10 requires data governance practices for training, validation, and testing data to be documented. This includes:
- Data collection practices documented
- Data preparation operations (labeling, cleaning, enrichment) documented
- Relevance, representativeness, and coverage of datasets assessed
- Known limitations and biases in datasets identified
- Measures to detect and address data gaps
Owner: Data team, ML engineering
14. Instructions for use / transparency documentation (Article 13)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Deployers must receive sufficient information to use the system appropriately. Your instructions for use must include:
- Identity and contact details of the provider
- Capabilities, limitations, and performance characteristics of the system
- Level of accuracy, robustness, and cybersecurity performance
- Known or foreseeable circumstances that may affect accuracy
- Human oversight measures the deployer should implement
- How to interpret the system's output
- Maintenance requirements
- Expected lifetime and post-market monitoring obligations for deployers
Owner: Product, Technical writing
15. Human oversight measures designed into the system (Article 14)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 14 requires high-risk AI systems to be designed to allow effective human oversight. This means:
- System can be monitored and interpreted by human operators
- Operators can override, interrupt, or disregard the system
- System alerts operators when it detects anomalous inputs or outputs
- System provides interpretability information sufficient for operators to understand its decisions
- System does not create dependencies that make human override impractical
Owner: Engineering, Product
16. Accuracy, robustness, and cybersecurity requirements met (Article 15)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 15 requires high-risk AI systems to achieve appropriate levels of accuracy, resilience, and cybersecurity. This includes:
- Performance metrics documented and validated
- Resilience to errors, faults, and inconsistencies in inputs tested
- Resilience to adversarial inputs (for applicable systems) assessed
- Backup plans or fail-safes defined for system failure scenarios
Owner: Engineering, Security
17. Conformity assessment pathway determined
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Most Annex III systems can use internal conformity assessment (Annex VI procedure, self-assessment). Systems where harmonized standards are not fully applied, certain high-risk biometric AI systems, and systems in law enforcement and public-sector high-stakes contexts may require third-party assessment from a notified body (Annex VII) under Article 43. Confirm which pathway applies to each system, the provider is responsible for making this determination.
Owner: Legal, Compliance
18. EU Declaration of Conformity produced
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 47 requires providers to draw up an EU Declaration of Conformity for each high-risk AI system. This declaration states that the system meets all applicable EU AI Act requirements. It must include the provider's name, the system's description, the standards applied, and the provider's signature.
Owner: Legal
19. CE marking affixed (where required)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 48 requires CE marking on high-risk AI systems when the conformity assessment is complete and the EU Declaration of Conformity has been produced. For software systems, CE marking is displayed in the user interface and documentation.
Owner: Product, Legal
20. Registration in EU AI Act database (Article 49)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 49 requires providers to register themselves and their high-risk AI systems in the EU database (established under Article 71) before placing them on the market. The database is operated by the European AI Office. Registration information includes: provider identity, system description, intended use, risk management summary. Systems used in law enforcement, migration, and border control are registered in a non-public section accessible only to the Commission and national authorities.
Owner: Legal, Compliance
21. Post-market monitoring plan in place (Article 72)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 72 requires providers to establish a post-market monitoring system to collect and analyze data on the system's performance after deployment. The plan must include:
- Indicators and thresholds for performance monitoring
- Process for receiving and analyzing user feedback
- Criteria for triggering a review or update of the risk management system
- Documentation of lessons learned and system updates
Owner: Engineering, Product
22. Serious incident notification process in place (Article 73)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 73 requires providers to notify the national competent authority within 15 calendar days of becoming aware of a serious incident involving a high-risk AI system. For incidents where rapid spread is possible or imminent risk exists, initial notification must be earlier. Process requirements:
- Defined criteria for what constitutes a serious incident
- Named person responsible for making the NCA notification
- Documented process for the 15-day notification
- Notification templates prepared in advance
Owner: Legal, CISO
23. Deployer support obligations covered in product design
Status: [ ] Done / [ ] In progress / [ ] Not started
Deployers have Article 26 obligations that they can only fulfill if your product supports them. Verify your product enables deployers to:
- Access audit logs for their use of the system
- Request technical documentation relevant to their deployer obligations
- Receive timely notification of serious incidents
- Implement the human oversight measures described in your instructions for use
Owner: Product, Engineering
24. Supply chain AI obligations assessed (Article 25)
Status: [ ] Done / [ ] In progress / [ ] Not started
If your high-risk AI system incorporates or builds on another high-risk AI system (a component AI system), Article 25 requires you to have agreements with the upstream provider that delineate obligations and provide access to necessary technical documentation.
Owner: Legal, Procurement
25. SME support measures assessed for eligibility
Status: [ ] Done / [ ] In progress / [ ] Not started
Article 62 of the EU AI Act includes SME support measures: priority access to regulatory sandboxes (Articles 57-58), guidance resources, simplified documentation templates, and reduced fee structures for conformity assessments. Article 63 provides additional simplified compliance pathways for microenterprises (under 10 employees, under €2M revenue). Organizations meeting EU SME definition (under 250 employees) may qualify for Article 62 support.
Owner: Finance, Legal
Section 3: Deployer obligations
If you use AI systems built by someone else in your EU operations in a high-risk context, these 10 items apply.
26. Human oversight implemented per Article 26
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 26 requires deployers to implement human oversight measures specified by the provider. This is not passive; you must:
- Assign qualified individuals to monitor the AI system
- Document what human oversight means in your specific operational context
- Train operators on how to interpret AI outputs and when to override
- Establish criteria for when the AI system output is not to be relied on without human review
Owner: Operations, HR, Training
27. Records of use maintained (Article 26)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Article 26 requires deployers to maintain logs of their use of high-risk AI systems, to the extent the system generates logs automatically. At minimum, document: which AI system you use, in what context, for what decisions, and who the responsible operator is.
Owner: Operations, IT
28. Individuals informed of AI decisions (Article 26)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
Where a high-risk AI system makes or meaningfully contributes to a decision affecting an identifiable individual, Article 26 requires the deployer to inform that individual that the decision involved an AI system. This applies in particular to employment decisions and access to services.
Owner: HR, Legal, Product
29. Incidents reported to the provider (Article 26)
Status: [ ] Done / [ ] In progress / [ ] Not started
Deadline: December 2, 2027
If you observe a malfunction, performance issue, or serious incident in a high-risk AI system you deploy, Article 26 requires you to report this to the provider. Establish a process for:
- Internal detection and classification of AI incidents
- Contacting the provider within a defined timeframe
- Documenting the incident and the provider's response
Owner: Operations, Legal, CISO
30. Responsible person for AI compliance designated
Status: [ ] Done / [ ] In progress / [ ] Not started
Article 26 and the EU AI Act's governance provisions require deployers to have identifiable responsibility for AI compliance. This does not require a dedicated role; it can be combined with an existing compliance, legal, or data protection function. But the responsibility must be documented.
Owner: Legal, HR
31. Vendor technical documentation on file
Status: [ ] Done / [ ] In progress / [ ] Not started
Request and retain the Annex IV technical documentation from each high-risk AI vendor. You need this to satisfy your own deployer documentation requirements and to respond to NCA inquiries. A vendor that cannot provide this documentation is not compliant with Article 13.
Owner: Procurement, Legal
32. Fundamental rights impact assessment (FRIA) completed where required
Status: [ ] Done / [ ] In progress / [ ] Not started
Article 27 requires deployers who are public authorities, or private entities providing services in public interest contexts (banking, insurance, education, healthcare), to complete a fundamental rights impact assessment before deploying certain high-risk AI systems. Confirm whether this applies to your deployment context.
Owner: Legal, Compliance
33. Provider's instructions for use followed and documented
Status: [ ] Done / [ ] In progress / [ ] Not started
Following the provider's instructions for use is a legal obligation under Article 26, not just a recommendation. Specifically:
- Instructions for use obtained and reviewed
- Training of operators against the instructions documented
- Any use cases outside the stated intended use documented and risk-assessed
Owner: Operations, Training
34. Deployer role vs provider role boundary confirmed
Status: [ ] Done / [ ] In progress / [ ] Not started
If you customize, fine-tune, or substantially modify a third-party AI system, you may be reclassified as a provider under Article 25, triggering the full provider obligation set. Confirm with legal counsel whether your customization of third-party AI systems triggers provider status.
Owner: Engineering, Legal
35. EU AI Act compliance factored into vendor renewal decisions
Status: [ ] Done / [ ] In progress / [ ] Not started
Before renewing contracts with AI vendors, confirm they can provide the documentation you need for your deployer obligations (Article 26), that their contract includes incident notification obligations, and that their DPA covers EU AI Act requirements. Non-compliant vendors create compliance risk for your deployment. See the AI vendor contract red flags guide.
Owner: Procurement, Legal
How to use this checklist
Prioritization: If you are starting from zero in late June 2026, focus first on items 1, 11, 12, and 17 (inventory, Annex IV documentation, risk management, and conformity pathway). These unlock the rest of the checklist.
Documentation cadence: Complete this checklist, save your answers with dates and owners, and schedule a review every six months or when a vendor announces a policy change.
Resource constraints: For small teams with limited compliance bandwidth, the EU AI Act August 2026 sprint checklist prioritizes six weeks of work across the minimum viable set of items.
For deeper coverage of specific obligation areas:
- Technical documentation: EU AI Act high-risk documentation templates
- Conformity assessment: EU AI Act conformity assessment process 2026
- Incident reporting: AI incident response plan: what regulators expect
- Vendor contracts: AI vendor contract red flags 2026
Related Reading
- EU AI Act August 2026: 6-week compliance sprint checklist
- EU AI Act Annex III high-risk AI systems: full category guide
- EU AI Act conformity assessment process 2026
- AI incident response plan: what regulators expect
- AI vendor contract red flags 2026
- Free AI register template for EU AI Act Article 70 compliance
- EU AI Act national competent authorities: who enforces and how
- Vietnam's 46 High-Risk AI Systems: Who Must Comply by August 2026
