Your Progress: 0 / 0 items
↓ PDF Checklist
August 2026 Deadline

EU AI Act Compliance Checklist 2026: Step-by-Step Implementation Guide

The EU AI Act compliance checklist on this page walks organisations through every requirement in four manageable implementation phases — from initial scoping through to EU database registration. Every item includes a one-sentence “How to comply” tip and a direct article reference.

Use the interactive checkboxes to track your progress. Your state is saved automatically in your browser — come back anytime and pick up where you left off.

TL;DR — Key Facts
  • 1 The primary deadline is 2 August 2026. High-risk AI systems listed in Annex III must be fully compliant — conformity assessments, documentation, human oversight, and EU database registration all complete.
  • 2 Compliance obligations differ by role. Providers (builders) carry the heaviest burden. Deployers (users) have distinct but significant duties. Many organisations are both — especially those that customise third-party AI tools.
  • 3 Non-compliance fines reach €35M or 7% of global turnover. This checklist covers all four implementation phases — from initial classification through EU database registration — in the logical order a compliance team should work through them.
Quick Tool
Not sure if your AI system is High-Risk?
Answer 5 questions about your AI system’s use case and we’ll tell you exactly which EU AI Act tier applies — and which sections of this checklist are mandatory for you.
Take the 2-Minute Assessment →
August 2026 Priority Items — Act on These First

With the 2 August 2026 deadline approaching, these four items have the longest lead times and must be started immediately. They appear in full detail in the phases below — this is your fast-track list.

① Appoint an Authorised Representative
Mandatory for all non-EU providers (US, UK, etc.) before placing high-risk AI on the EU market. Allow 4–8 weeks to identify, contract, and register. Art. 22
② Establish Human-in-the-Loop (HITL)
Document exactly how a human can monitor, intervene, override, or halt the AI’s decisions in real-time. Must be built into system design. Art. 14
③ Create Your Annex IV Technical Documentation
Compile the “Living Document” covering system architecture, training data, testing methodology, accuracy metrics, and limitations. Takes 3–6 months for complex systems. Art. 11 + Annex IV
④ Register in the EU AI Database
Final mandatory step for all Annex III high-risk systems before EU market placement. Requires completed conformity assessment and Declaration of Conformity. Art. 49
Phase 1 of 4
Scoping & Classification
Determine your role, identify which AI systems you operate, and establish whether they fall under high-risk or prohibited categories. This phase sets the scope of everything that follows.
Step 1A — Identify Your Legal Role
Step 1B — Risk Classification
Phase 2 of 4
Gap Analysis
Compare your current AI governance practices against the Act’s requirements. This phase surfaces exactly what needs to be built, upgraded, or documented before you can proceed to implementation.
Step 2A — Governance & Policy Gaps
Step 2B — Supply Chain & Vendor Gaps
Step 2C — Fundamental Rights Gap Assessment
Phase 3 of 4
Technical Implementation
Build or upgrade the technical systems, documentation, and processes required by the Act. This is the most resource-intensive phase — begin as early as possible.
Step 3A — Risk Management System (Art. 9)
Step 3B — Data Governance (Art. 10)
Step 3C — Technical Documentation (Art. 11 + Annex IV)
Step 3D — Logging and Record-Keeping (Art. 12)
Step 3E — Human Oversight (Art. 14)
Step 3F — Accuracy, Robustness and Cybersecurity (Art. 15)
Step 3G — Transparency to Deployers (Art. 13) and Transparency Obligations (Art. 50)
Step 3H — Quality Management System (Art. 17)
Phase 4 of 4
Registration & Filing
Complete formal compliance filings — conformity assessment, Declaration of Conformity, CE marking, and EU AI database registration. These steps gate your legal right to place the system on the EU market.
Step 4A — Conformity Assessment (Art. 43)
Step 4B — Declaration of Conformity and CE Marking (Art. 47–48)
Step 4C — EU AI Database Registration (Art. 49)
Step 4D — Post-Market Obligations (Art. 72–73)
Role-Specific
Deployer-Specific Obligations
These items apply specifically to organisations using (but not building) high-risk AI systems. They apply in addition to the Phase 1–4 items above.
Role-Specific
GPAI Model Provider Obligations
These items apply to organisations that develop or release General Purpose AI models (foundation models, large language models). Obligations applied from 2 August 2025.
Download the Complete Checklist as PDF
All four phases, every checklist item with “How to comply” tips, article references, and the August 2026 priority items — formatted for print and team distribution. Free to download.
↓ Download PDF Checklist

EU AI Act Compliance Checklist — FAQ

Common questions from legal, technical, and operations teams working through EU AI Act implementation.

Where do I start if I have never done any EU AI Act compliance work? +
Start with Phase 1 — Scoping & Classification. Build your AI System Inventory first: list every AI tool your organisation develops or uses. Then classify each against the prohibited practices (Article 5) and Annex III high-risk categories. Only once you know which of your systems are in scope can you plan the work required. This classification step alone typically takes 2–4 weeks for a medium-sized organisation with 10–30 AI systems.
How long does EU AI Act compliance realistically take? +
For a single high-risk AI system, a well-resourced compliance team should expect 4–9 months end-to-end: 2–4 weeks for scoping and classification, 4–8 weeks for gap analysis, 3–6 months for technical documentation and implementation, and 4–8 weeks for conformity assessment and registration. Organisations with multiple high-risk systems running in parallel can compress this timeline but need more resources. Given the August 2026 deadline, organisations should target internal completion by April 2026 at the latest to allow buffer time for unforeseen issues.
Do I need a dedicated AI compliance officer? +
The EU AI Act does not require a specific “AI Compliance Officer” role by name, but practically speaking, large organisations with multiple high-risk AI systems need a dedicated lead. Smaller organisations can often manage compliance with a part-time programme owned by the legal, data protection, or technology team. In all cases, clear ownership is essential — compliance programmes without a named accountable person consistently fall behind. Whoever leads the programme needs both legal and technical fluency, or access to both disciplines.
What is the difference between a conformity assessment and a Fundamental Rights Impact Assessment? +
A conformity assessment (Article 43) is a technical and procedural verification that a high-risk AI system meets the Act’s mandatory requirements — done by the Provider before market placement. It covers data governance, documentation, accuracy, human oversight, cybersecurity, and the QMS. A Fundamental Rights Impact Assessment (Article 27) is a separate assessment done by the Deployer before deploying a high-risk AI system in a regulated public-service or essential-services context. It evaluates the system’s potential impact on individuals’ fundamental rights — not its technical compliance. Both are required, by different parties, at different stages.
Can I use an existing ISO 9001 or ISO 27001 QMS to meet Article 17 requirements? +
Yes — partially. An existing ISO 9001 QMS provides a strong foundation for Article 17 compliance and can significantly reduce the work required. However, you will need to extend it with AI-specific procedures that ISO 9001 does not cover: AI-specific risk management integrated with Article 9, AI system testing protocols, bias detection procedures, and post-market AI monitoring. ISO 42001 (the AI Management System standard published in 2023) is specifically designed to bridge this gap and aligns closely with Article 17 requirements. Organisations already holding ISO 27001 for information security will also find strong overlap with the cybersecurity requirements of Article 15.
What happens if I miss the August 2026 deadline? +
From 2 August 2026, national market surveillance authorities are empowered to enforce the Act against non-compliant high-risk AI systems. Missing the deadline does not mean you must immediately withdraw your system — enforcement will be risk-prioritised and authorities are likely to focus first on the highest-risk sectors. However, you will be operating in violation of EU law and exposed to fines of up to €15 million or 3% of global turnover per violation. Your system may be ordered withdrawn from the EU market. Critically, you will also face reputational and contractual risk with EU clients who have their own compliance obligations and need their AI vendors to be compliant. The safest position is to have a documented compliance programme underway even if not fully complete by the deadline.
Where can I find official EU AI Act compliance guidance and standards? +
The primary authoritative sources are: the full regulation text on EUR-Lex; the EU AI Office guidance documents; the ISO 42001 AI Management System standard; and CEN-CENELEC harmonised standards for AI (which, when cited in the Official Journal, create a presumption of conformity). The NIST AI RMF and OECD AI Principles are internationally recognised complementary frameworks.
MF
Martina Fowler
EU AI Act Expert
Senior AI Regulatory Counsel & Lead Author, EU AI Act Guide

Martina Fowler is a senior AI regulatory counsel with over a decade of experience advising multinational organisations on technology law, data governance, and EU digital policy. She has closely tracked the EU AI Act since the Commission’s initial proposal in April 2021 and has guided dozens of enterprises through risk classification, conformity assessment design, and cross-border compliance strategy. Martina holds an LL.M. in European Law from KU Leuven and is a frequent speaker at EU policy forums on AI regulation and fundamental rights. Her work at EU AI Act Guide focuses on translating complex legislative text into actionable compliance frameworks for legal, technical, and business audiences.

[email protected]