EU AI Act Compliance Checklist
This checklist maps the key compliance obligations under EU Regulation 2024/1689 (the EU AI Act). It is structured by obligation type and annotated with priority levels and enforcement timelines. It is a practical starting point, not a substitute for legal advice or a formal compliance assessment. UK organisations with EU customers, staff, or partners should assume the Act applies to them.
Maximum penalties
Violations involving prohibited AI systems: up to €35 million or 7% of global annual turnover, whichever is higher. Violations of high-risk obligations: up to €15 million or 3% of global annual turnover. Providing incorrect or misleading information: up to €7.5 million or 1% of global annual turnover. These penalties apply to legal persons including companies.
Enforcement timeline
Section A — Prohibited AI systems (Article 5)
Immediate action required: These prohibitions have been in force since 2 February 2025. Any AI system falling within Article 5 must be identified and decommissioned immediately. If you have deployed any system in a prohibited category, seek legal advice.
- Confirm you do not deploy AI systems that exploit subliminal techniques to influence behaviour in ways that cause harm to persons.Critical
- Confirm you do not deploy AI systems exploiting vulnerabilities of specific vulnerable groups (age, disability, socioeconomic situation) to distort behaviour to their detriment.Critical
- Confirm you do not operate real-time remote biometric identification (RBI) systems in publicly accessible spaces for law enforcement purposes (unless one of the narrow derogations applies).Critical
- Confirm you do not operate post-remote biometric identification systems by law enforcement except for specified serious crimes with judicial authorisation.Critical
- Confirm you do not deploy AI systems for social scoring by public authorities that leads to detrimental treatment.Critical
- Confirm you do not deploy AI systems for risk assessment of individuals predicting future criminal or administrative offences solely based on profiling or personality traits.Critical
- Confirm you do not deploy AI systems that create or expand facial recognition databases by untargeted scraping of facial images from the internet or CCTV.Critical
- Confirm you do not deploy AI systems that infer emotions of natural persons in workplace or educational institutions (outside permitted medical or safety uses).Critical
Section B — High-risk AI classification
Review your AI inventory against Annex III of the EU AI Act. High-risk AI systems include AI used in the following areas:
- AI used as safety components of products subject to Union harmonisation legislation (medical devices, machinery, aviation, vehicles, lifts, etc.).High
- AI used in management and operation of critical infrastructure (electricity, water, gas, transport, digital infrastructure).High
- AI used to determine access to, or admission in, educational or vocational training institutions.High
- AI used for recruitment, CV filtering, interview evaluation, performance monitoring, or termination of employment contracts.High
- AI used for credit scoring, creditworthiness assessment, or evaluation in insurance and life assurance.High
- AI used for assessment of eligibility for social security and social protection benefits, or in public emergency services.High
- AI used for risk assessment, evidence evaluation, or criminal profiling in law enforcement contexts.High
- AI used in migration, asylum, visa, or border control applications.High
- AI used in administration of justice or democratic processes (legal research, judicial decision support).High
- Document the outcome of classification assessment for each AI system and retain as part of technical documentation.Medium
Article 6(3) self-assessment: Even if your AI system falls within Annex III, it is not automatically high-risk. Providers may self-assess that a system does not present a significant risk of harm, subject to registering this determination in the EU database. This is a nuanced legal question — seek qualified advice before relying on this exemption.
Section C — High-risk AI obligations (Articles 8–27)
Risk management (Article 9)
- Establish and maintain a risk management system for each high-risk AI system throughout its lifecycle.High
- Identify and analyse known and foreseeable risks to health, safety, and fundamental rights.High
- Adopt and implement risk mitigation measures; evaluate residual risk against acceptable threshold.High
- Test for risks arising from reasonably foreseeable misuse.High
Data and data governance (Article 10)
- Training, validation, and testing datasets are subject to appropriate data governance practices.High
- Datasets are relevant, representative, free of errors, and complete for the intended purpose.High
- Datasets account for characteristics and possible biases of the geographic, contextual, and behavioural setting.High
Technical documentation (Article 11)
- Technical documentation prepared before system is placed on market or put into service and kept up to date.High
- Documentation covers: general description; intended purpose; training methodology; performance metrics; dataset descriptions; risk management outcomes.High
- Documentation is retained for 10 years after last placing on market.Medium
Transparency and instructions for use (Articles 13–14)
- System is designed so that its operation is sufficiently transparent to enable deployers to interpret output and use appropriately.High
- Instructions for use provided covering: intended purpose; performance level; human oversight measures; expected lifetime and maintenance requirements.High
- Human oversight measures implemented allowing human review, intervention, and override of AI system outputs.High
Accuracy, robustness, and cybersecurity (Article 15)
- System achieves appropriate level of accuracy, robustness, and cybersecurity throughout its lifecycle.High
- System is resilient against attempts to alter its use, outputs, or performance by third parties exploiting system vulnerabilities (adversarial attacks).High
- Security measures implemented proportionate to the risk and technical state of the art.Medium
Quality management system (Article 17)
- Quality management system documented and implemented covering: compliance strategy; design methodology; testing procedures; post-market monitoring plan.High
- Roles and responsibilities within organisation clearly defined in relation to quality management.Medium
EU database registration (Article 49)
- High-risk AI systems registered in the EU AI Act public database before placing on market (from August 2026).High
- Deployers of high-risk AI systems listed in Annex III (points 1–7) register their use in the EU database.Medium
Section D — Transparency obligations
- AI systems interacting with natural persons (chatbots, AI assistants) clearly disclose that the person is interacting with an AI, unless this is obvious from context.High
- Emotion recognition systems and biometric categorisation systems inform persons of their operation.High
- Deep fake or AI-generated content (images, audio, video, text) is labelled as artificially generated or manipulated where it could be mistaken for authentic.High
- AI-generated text published with intent to inform on matters of public interest is labelled as AI-generated (unless subject to human review or editorial responsibility).Medium
Section E — General-purpose AI (GPAI) model obligations
Scope note: GPAI model obligations apply to organisations that provide GPAI models (train and make available). If you use a GPAI model via API (e.g., via a commercial LLM provider), you are a deployer and provider-level GPAI obligations fall on the model provider, not you. Deployer-specific transparency and human oversight obligations still apply.
- Technical documentation for GPAI model prepared and kept up to date (Article 53).High
- Information and documentation provided to downstream providers integrating the model into AI systems (Article 53).High
- Policy adopted to comply with EU copyright law, including training data transparency (Article 53).High
- Summary of training content published (Article 53).High
- Systemic risk evaluation performed where model has FLOP count ≥ 10²⁵ or meets other systemic risk criteria (Article 55).Medium
- Incident reporting to AI Office for serious incidents caused by GPAI model with systemic risk (Article 55).Medium
Section F — AI governance and accountability
- Authorised representative designated if provider is established outside the EU but places AI systems on EU market (Article 22).High
- Post-market monitoring system established for high-risk AI systems (Article 72).High
- Serious incident reporting procedure in place — notify national authority within 15 days of becoming aware of a serious incident caused by a high-risk AI system (Article 73).High
- Fundamental rights impact assessment conducted by deployers of certain high-risk AI systems (Article 27).Medium
- Staff training completed — persons responsible for operating high-risk AI systems have sufficient AI literacy (Article 4).Medium
- Logs maintained by deployers of high-risk AI systems to enable monitoring and post-incident review (Article 26).Medium
Need a formal EU AI Act assessment?
This checklist identifies the obligations — a Holster EU AI Act Compliance Assessment maps your specific AI estate against each requirement, produces a gap analysis, and delivers the technical documentation and roadmap you need for compliance by the relevant deadlines.
Book a free consultation →