HOLSTER holstersecurity.com
Compliance Checklist · Free

EU AI Act Compliance Checklist

Regulation: EU 2024/1689
Updated: July 2026
Applies to: Providers, deployers, importers & distributors of AI systems affecting EU persons

This checklist maps the key compliance obligations under EU Regulation 2024/1689 (the EU AI Act). It is structured by obligation type and annotated with priority levels and enforcement timelines. It is a practical starting point, not a substitute for legal advice or a formal compliance assessment. UK organisations with EU customers, staff, or partners should assume the Act applies to them.

Maximum penalties

Violations involving prohibited AI systems: up to €35 million or 7% of global annual turnover, whichever is higher. Violations of high-risk obligations: up to €15 million or 3% of global annual turnover. Providing incorrect or misleading information: up to €7.5 million or 1% of global annual turnover. These penalties apply to legal persons including companies.

Enforcement timeline

Feb 2025
Prohibited AI in force
Article 5 prohibitions enforceable. Identify and decommission any prohibited systems immediately.
Aug 2025
GPAI model obligations
General-purpose AI model providers must comply with transparency, copyright, and systemic risk requirements.
Aug 2026
High-risk AI obligations
Full Annex III high-risk AI requirements in force. Conformity assessments, technical documentation, and registration required.

Section A — Prohibited AI systems (Article 5)

ENFORCEMENT DATE: February 2025 · Priority: CRITICAL — immediate action required

Immediate action required: These prohibitions have been in force since 2 February 2025. Any AI system falling within Article 5 must be identified and decommissioned immediately. If you have deployed any system in a prohibited category, seek legal advice.

Section B — High-risk AI classification

ENFORCEMENT DATE: August 2026 · Priority: HIGH — assess now, compliance by deadline

Review your AI inventory against Annex III of the EU AI Act. High-risk AI systems include AI used in the following areas:

Article 6(3) self-assessment: Even if your AI system falls within Annex III, it is not automatically high-risk. Providers may self-assess that a system does not present a significant risk of harm, subject to registering this determination in the EU database. This is a nuanced legal question — seek qualified advice before relying on this exemption.

Section C — High-risk AI obligations (Articles 8–27)

ENFORCEMENT DATE: August 2026 · Applies to: providers and deployers of high-risk AI systems

Risk management (Article 9)

Data and data governance (Article 10)

Technical documentation (Article 11)

Transparency and instructions for use (Articles 13–14)

Accuracy, robustness, and cybersecurity (Article 15)

Quality management system (Article 17)

EU database registration (Article 49)

Section D — Transparency obligations

ENFORCEMENT DATE: August 2026 · Applies to: providers and deployers of AI systems with transparency obligations

Section E — General-purpose AI (GPAI) model obligations

ENFORCEMENT DATE: August 2025 · Applies to: providers of general-purpose AI models placed on EU market

Scope note: GPAI model obligations apply to organisations that provide GPAI models (train and make available). If you use a GPAI model via API (e.g., via a commercial LLM provider), you are a deployer and provider-level GPAI obligations fall on the model provider, not you. Deployer-specific transparency and human oversight obligations still apply.

Section F — AI governance and accountability

ONGOING · Applies to: all providers and deployers

Need a formal EU AI Act assessment?

This checklist identifies the obligations — a Holster EU AI Act Compliance Assessment maps your specific AI estate against each requirement, produces a gap analysis, and delivers the technical documentation and roadmap you need for compliance by the relevant deadlines.

Book a free consultation →