April 23, 2026 · 11 min read · infosec.qa team · Updated September 6, 2026

EU AI Act Compliance Checklist 2026 - Practical Steps for AI Teams

The practical EU AI Act compliance checklist for 2026. Risk classification, conformity assessment, technical documentation, data governance, human oversight, transparency, and post-market monitoring - with specific actions AI teams can take this quarter.

EU AI Act Compliance Checklist 2026 - Practical Steps for AI Teams

The EU AI Act compliance checklist is the practical translation of 459 articles into actions AI teams can actually execute. This guide breaks down what to do this quarter, organized around the Act’s risk-based structure. Written for AI product teams, CISOs, compliance leaders, and anyone building or deploying AI systems that touch EU markets.

Read This First - The 2026 Timeline Changed

If you built a plan against a 2 August 2026 high-risk deadline, that plan is out of date. The Digital Omnibus on AI - Regulation (EU) 2026/1744 - was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amends the AI Act’s application dates. The Commission proposed it in November 2025 because the implementation machinery was not ready: national competent authorities were still being designated, notified bodies were not in place, and the harmonised standards that high-risk providers were supposed to conform to had not been finalised.

Here is where every obligation actually sits now.

ObligationApplies fromChanged by the Omnibus?
Article 5 prohibited practices2 February 2025No
AI literacy (Article 4)2 February 2025No
GPAI model obligations (Articles 51-56)2 August 2025No
Commission enforcement powers over GPAI2 August 2026No
Article 50 transparency and content labelling2 August 2026No
Article 50(2) transition for systems already on market2 December 2026No
Annex III stand-alone high-risk systems2 December 2027Yes - deferred from 2 August 2026
Annex I embedded high-risk systems2 August 2028Yes - deferred from 2 August 2027
Legacy GPAI models placed before 2 August 20252 August 2027No

Three things follow from this table, and they are the things teams keep getting wrong.

The deferral is a deferral, not a repeal. Every substantive obligation in Steps 3 through 10 below survived intact. Risk management, data governance, Annex IV technical documentation, record-keeping, human oversight, accuracy and robustness, post-market monitoring - all unchanged in content. You simply have sixteen more months to evidence them for Annex III systems. And the new dates are fixed dates, replacing the conditional standards-availability trigger the Commission originally floated, so there is no second automatic slip waiting for you.

2026 is not a quiet year. Article 50 transparency landed on schedule on 2 August 2026 and applies to a much wider population of systems than the high-risk rules ever did - any chatbot, any generative feature, any synthetic media output. If you shipped a generative system before 2 August 2026, your labelling grace period runs out on 2 December 2026. Separately, the Commission’s supervision and enforcement powers over GPAI providers switched on in August 2026, which means documentation requests, model evaluations, and fines are now live instruments rather than future ones.

Sixteen months is roughly what the work actually takes. Teams that treat the deferral as permission to stop are the ones that will be assembling an Annex IV technical file in late 2027 with no test history behind it. Conformity evidence is cumulative: a risk register with two years of iterations, a bias evaluation with version history, a post-market monitoring dashboard with a year of drift data. None of that can be manufactured in the final quarter.

Do this in the next 30 days, given the new dates:

  • Re-baseline any internal deadline that says “August 2026” for high-risk conformity to 2 December 2027 (Annex III) or 2 August 2028 (Annex I)
  • Confirm nothing in your portfolio is caught by Article 5 - that has no deadline and no grace period
  • Audit every user-facing AI surface against Article 50: interaction disclosure, synthetic content labelling, deepfake labelling
  • Check whether any generative system you placed on the market before 2 August 2026 needs labelling retrofitted by 2 December 2026
  • If you provide a GPAI model, confirm your Article 53 technical documentation and training-content summary would survive a Commission information request today
  • Keep the high-risk programme running on its original cadence and bank the extra runway as evidence depth, not as slack

Step 1 - Inventory Your AI Systems

Before any classification or compliance work, you need visibility.

Checklist:

  • List every AI system your organization develops, deploys, or distributes
  • For each system: purpose, users, data inputs, data outputs, decision impact
  • Classify whether system is used in EU or serves EU users
  • Identify whether you are provider, deployer, importer, or distributor for each
  • Inventory any General-Purpose AI (GPAI) models you build on or provide

Most organizations underestimate this step. AI systems are deployed by product, marketing, sales, HR, security, and operations teams - often without central visibility. A fresh inventory typically surfaces 2-3x more AI systems than the compliance team expected.

Step 2 - Risk Classification

Classify each AI system against the AI Act’s risk categories.

Unacceptable risk (prohibited - Article 5)

Checklist:

  • Not used for social scoring by public authorities
  • Not used for manipulative techniques exploiting vulnerabilities
  • Not used for emotion recognition in workplaces or educational institutions (narrow exceptions)
  • Not used for biometric categorization inferring sensitive attributes (narrow exceptions)
  • Not used for real-time remote biometric identification in publicly accessible spaces (narrow law enforcement exceptions)
  • Not used for untargeted scraping of facial images from internet or CCTV
  • Not predicting criminal offenses based solely on profiling

If any of these apply, the system cannot be placed on the EU market. Period. Redesign or remove.

High-risk AI (Annex III)

Checklist:

  • Biometric systems - categorization, identification (narrow cases only)
  • Critical infrastructure - safety components (water, gas, electricity, internet, transport)
  • Education and vocational training - access, evaluation, monitoring
  • Employment and HR - recruitment, evaluation, task allocation, monitoring, promotion/termination
  • Access to essential private and public services - credit scoring, insurance risk, emergency dispatch
  • Law enforcement use
  • Migration, asylum, border control
  • Administration of justice and democratic processes

If any apply, full compliance programme required (Steps 3-10 below).

Limited risk

Checklist:

  • Chatbots and conversational AI - transparency obligation (users must be informed they are interacting with AI)
  • Emotion recognition and biometric categorization (not in prohibited category)
  • AI-generated or manipulated content - labelling obligation (synthetic content disclosed)
  • Deep fakes - labelling obligation

Transparency obligations only.

Minimal risk

Checklist:

  • Voluntary adherence to codes of conduct
  • No specific Act obligations beyond general consumer protection

Most AI systems fall here. Spam filters, recommendation engines, content moderation (non-political), productivity AI features.

General-Purpose AI (GPAI)

Separate obligations apply. Checklist:

  • GPAI models: technical documentation, information disclosure to downstream users, EU copyright compliance, training content summary
  • GPAI models with systemic risk: additional evaluation, adversarial testing, reporting to Commission

Step 3 - Risk Management System (Article 9)

For high-risk AI systems:

Checklist:

  • Documented risk management process covering full lifecycle
  • Identify and analyze known and foreseeable risks
  • Estimate and evaluate risks for reasonably foreseeable misuse
  • Risk management measures documented and tested
  • Continuous iterative process - not one-time exercise
  • Testing against suitable metrics and thresholds
  • Assessment of residual risks after mitigations
  • Documentation of risk acceptance decisions by appropriate authority

Step 4 - Data Governance (Article 10)

For high-risk AI systems:

Checklist:

  • Training, validation, testing datasets are relevant, representative, free of errors, complete
  • Data governance practices documented
  • Assessment of availability, quantity, suitability
  • Examination of biases likely to affect health, safety, fundamental rights, or discrimination
  • Appropriate data preparation - pre-processing, annotation, labelling, cleansing, updating
  • Special categories of personal data only when strictly necessary with safeguards
  • Data processing respects GDPR

Step 5 - Technical Documentation (Article 11, Annex IV)

For high-risk AI systems, documentation covering:

Checklist:

  • General description - intended purpose, developer details, version history
  • Detailed description of elements - methods used, main design choices, rationale
  • Description of monitoring and control mechanisms
  • Detailed description of risk management system
  • Description of changes made through system lifecycle
  • Information about datasets used - provenance, quality measures
  • Validation and testing procedures used
  • Cybersecurity measures
  • Description of performance metrics, level of accuracy, foreseeable consequences

Step 6 - Record-Keeping (Article 12)

Checklist:

  • High-risk AI systems designed to automatically log events
  • Logs enable tracing of operation
  • Logs allow post-market monitoring and compliance verification
  • Appropriate log retention period
  • Log integrity and tamper-evidence
  • Access controls on log review

Step 7 - Transparency and Information (Article 13)

For high-risk AI systems:

Checklist:

  • Instructions for use accompany the system
  • Information clear, comprehensive, concise, accessible to deployers
  • Identity and contact details of provider
  • Characteristics, capabilities, limitations
  • Changes made to high-risk AI system since initial conformity assessment
  • Human oversight measures
  • Expected lifetime and maintenance measures

For limited-risk AI (chatbots, content):

Checklist:

  • Users informed when interacting with AI
  • AI-generated content clearly disclosed
  • Deep fakes and manipulated content labelled

Step 8 - Human Oversight (Article 14)

For high-risk AI systems:

Checklist:

  • System designed to enable effective human oversight
  • Oversight measures identify and address risks
  • Human capable of understanding capacities and limitations
  • Human can intervene, override, stop, or disregard output
  • Oversight can be ensured through interface design and procedural measures
  • Training provided to oversight personnel

Step 9 - Accuracy, Robustness, Cybersecurity (Article 15)

For high-risk AI systems:

Checklist:

  • Designed to achieve appropriate level of accuracy for intended purpose
  • Accuracy declared in instructions for use
  • Resilient against errors, faults, and inconsistencies
  • Resilient against attempts to alter use or performance (adversarial examples, data poisoning, model inversion, membership inference)
  • Cybersecurity measures proportionate to risks
  • Incident response planning for cybersecurity breaches affecting the AI system

Cybersecurity specifically requires testing against adversarial AI attacks - prompt injection, data poisoning, model extraction, membership inference. This is where penetration testing intersects AI Act compliance.

Step 10 - Post-Market Monitoring (Article 72)

Checklist:

  • Post-market monitoring plan documented
  • Monitoring activities proportionate to AI system risks
  • Data collected on system performance in real use
  • Data analyzed for compliance with requirements
  • Serious incidents reported to competent authorities (typically within 15 days)
  • Corrective action tracked

Additional Obligations for Specific Roles

Providers (Article 16)

  • Conformity assessment before placing on market
  • CE marking for high-risk systems
  • EU declaration of conformity
  • Register in EU database for high-risk AI systems (Annex VIII)
  • Authorized representative if based outside EU
  • Corrective action and information sharing obligations

Deployers (Article 26)

  • Use system in accordance with instructions
  • Appropriate human oversight
  • Monitor operation for risks
  • Keep logs as required
  • For workplace deployment: inform workers and their representatives
  • Fundamental rights impact assessment for certain deployments (Article 27)

Importers and Distributors

  • Verify provider has conducted conformity assessment
  • Verify CE marking and EU declaration
  • Technical documentation available for 10 years
  • Corrective action if non-conformity identified
Stuck on Step 9 - Accuracy, Robustness, Cybersecurity?

Article 15 is the step most teams cannot self-certify. Our AI Red Team Assessment produces the robustness and adversarial-testing evidence your technical file needs.

Book a compliance scope call

Timeline for Action

Working backwards from 2 December 2027 for Annex III systems, here is the shape of a programme that arrives with evidence rather than intentions.

Next 30 days:

  • Complete Step 1 inventory
  • Complete Step 2 risk classification
  • Identify any prohibited AI - immediate action required, no deadline applies
  • Close any open Article 50 transparency gaps, since that obligation is already live
  • Identify high-risk AI - plan full compliance programme against the 2027 date

Next 90 days:

  • Build compliance programme for high-risk AI systems (Steps 3-10)
  • Establish governance structure - AI governance committee, roles, responsibilities
  • Begin technical documentation, and start versioning it from the first draft
  • Integrate with GDPR compliance programme
  • Retrofit labelling on any pre-August-2026 generative system ahead of 2 December 2026

Next 180 days:

  • Stand up post-market monitoring early so you accumulate real drift and performance data
  • Run first-pass adversarial and robustness testing against Article 15, then schedule it to repeat
  • Draft the Annex IV technical file and identify which sections have no evidence behind them yet
  • Complete transparency obligations for limited-risk AI

Through 2027:

  • Re-run risk assessment, bias evaluation, and robustness testing on a fixed cadence so the evidence trail has depth
  • Complete conformity assessments for high-risk AI
  • Register in EU database and draw up the EU declaration of conformity
  • Track harmonised standards as they are published and align the technical file to them

Ongoing:

  • Maintain documentation current
  • Execute post-market monitoring
  • Serious incident reporting
  • Framework updates as EU Commission issues guidance

How infosec.qa Supports EU AI Act Compliance

Our engagement types supporting AI Act compliance:

If the work lands on your QA function. Steps 4, 8, 9, and 10 above are not really governance work once you get past the policy layer - somebody has to build the bias evaluation harness, run the adversarial suite, and keep the drift dashboard alive. Our sister practice covers what the AI Act deferral means for a remote QA team’s staffing and workflow: who owns model-level evaluation when your testers are distributed, how to split conformity evidence work across time zones, and why the extra runway changes the build-versus-engage decision.

Frequently Asked Questions

Who needs to comply with the EU AI Act?

The EU AI Act applies to providers, deployers, importers, and distributors of AI systems used in the EU - regardless of where the organization is based. Non-EU companies serving EU users or markets are in scope. Specific obligations scale with risk classification: prohibited AI (outright ban), high-risk AI (full conformity assessment), limited-risk AI (transparency obligations), and minimal-risk AI (voluntary codes). General-purpose AI models have separate obligations.

When does the EU AI Act come into effect?

The AI Act entered into force on 1 August 2024 with phased application, and the phasing was amended in 2026 by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026). Current dates: prohibited practices from 2 February 2025; general-purpose AI model obligations from 2 August 2025, with Commission enforcement powers over GPAI from 2 August 2026; Article 50 transparency and AI-content labelling from 2 August 2026; stand-alone high-risk systems under Annex III from 2 December 2027; and high-risk systems embedded in regulated products under Annex I from 2 August 2028. The Annex III date was deferred from its original 2 August 2026 deadline.

Did the Digital Omnibus cancel the EU AI Act high-risk requirements?

No. It deferred them, it did not remove them. The Digital Omnibus on AI moved the application date for Annex III stand-alone high-risk systems from 2 August 2026 to 2 December 2027, and for Annex I embedded high-risk systems to 2 August 2028. These are fixed dates, replacing the conditional trigger the Commission originally proposed, so there is no further automatic slip if harmonised standards run late. The substantive obligations - risk management, data governance, technical documentation, human oversight, accuracy and robustness, post-market monitoring - are unchanged. What changed is how long you have to evidence them.

What EU AI Act obligations are actually enforceable right now in 2026?

Three blocks. Article 5 prohibited practices have been enforceable since February 2025 and are a hard stop, not a deadline. GPAI model obligations have applied since August 2025, and from 2 August 2026 the Commission can request documentation, run evaluations, demand mitigation measures, and issue fines. Article 50 transparency applied from 2 August 2026: users must be told when they are interacting with an AI system, and synthetic audio, image, video, and text must be labelled, with a transition period to 2 December 2026 for generative systems already on the market before August 2026. High-risk conformity is the piece that moved to 2027 and 2028.

How are AI systems classified under the AI Act?

Four risk categories: Unacceptable risk (prohibited - social scoring, manipulative AI, real-time remote biometric identification with narrow exceptions), High risk (Annex III lists - biometric categorization, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, democratic processes), Limited risk (chatbots, AI-generated content - transparency obligations), and Minimal risk (voluntary codes of conduct). Plus separate rules for General-Purpose AI (GPAI) models.

What is the conformity assessment requirement?

Providers of high-risk AI systems must conduct conformity assessment before placing the system on the market - either through internal assessment (most high-risk systems) or by involving a notified body (certain biometric and critical infrastructure systems). Assessment covers risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity. CE marking required.

What are the AI Act fines?

Significant. Prohibited AI practices: up to 35 million EUR or 7% of global annual turnover, whichever is higher. Non-compliance with other obligations: up to 15 million EUR or 3% of turnover. Supplying incorrect information to authorities: up to 7.5 million EUR or 1%. Similar or higher to GDPR maxima. EU AI Office and national authorities enforce.

How does the EU AI Act interact with GDPR?

Both apply concurrently to AI systems processing personal data. GDPR covers personal data protection; AI Act covers AI-specific risks (safety, fundamental rights, transparency). Data governance obligations in AI Act Article 10 for high-risk AI references GDPR compliance. Privacy impact assessments (DPIA) often feed into AI Act risk management. Compliance programmes should address both frameworks integrated - one compliance function, two framework deliverables.

Know Your AI Attack Surface

Request a free AI Security Scorecard assessment and discover your AI exposure in 5 minutes.

Get Your Free Scorecard