AI Governance & ComplianceHow-to GuideFreshLast reviewed: · 42d ago

    EU AI Act Compliance Checklist 2026: A 10-Step Playbook

    TL;DR

    Quick Answer
    Cited by AI
    To comply with the EU AI Act, inventory every AI system, classify each by risk category, prepare Annex IV technical documentation for high-risk systems, conduct a Fundamental Rights Impact Assessment, run a conformity assessment, and establish an AI literacy program before 2 August 2026.

    High-risk AI obligations under Regulation (EU) 2024/1689 apply from 2 August 2026. This step-by-step checklist shows how to inventory, classify, document, and govern your AI systems before enforcement begins.

    EU AI Act compliance is the process of meeting Regulation (EU) 2024/1689, the European Union's risk-based AI law that entered into force on 1 August 2024. Compliance covers system inventory, risk classification, technical documentation, fundamental-rights impact assessments, AI literacy, conformity assessments, and post-market monitoring for providers and deployers of AI systems.

    Time

    8-16 weeks

    Difficulty

    Advanced

    Typical cost

    €25K-€150K

    Tools

    AI system inventory tool (spreadsheet or GRC platform such as OneTrust or Credo AI), Annex IV technical documentation templates, FRIA template aligned with Article 27…

    Before you start

    • Executive sponsorship at C-level — AI Act compliance is a board-level issue
    • Existing GDPR programme to build on (data inventory, DPIAs, records of processing)
    • Cross-functional AI governance committee (legal, security, data, product)
    • Budget authority for tooling, external counsel, and conformity assessment fees

    What you'll have at the end

    A documented, defensible EU AI Act compliance posture: every AI system classified, high-risk systems with Annex IV documentation and FRIA, an active AI literacy programme, post-market monitoring in place, and governance ready for the 2 August 2026 enforcement date.

    Eric Lundberg - Author at Alice Labs
    Written by
    Linus Ingemarsson - Reviewer at Alice Labs
    Reviewed by
    Published ·Updated
    14 min read

    10-step process

    0/10 complete
    1. Step 1: Inventory every AI system in your organisation

      Build a single registry of every AI system in development, production, or procured from vendors. Capture purpose, data inputs, decision outputs, business owner, model provider, and deployment context. Most enterprises discover 2-3x more AI systems than leadership initially estimates — including embedded AI in SaaS tools.

    2. Step 2: Classify each system by EU AI Act risk category

      Map each system to one of four tiers: unacceptable risk (Article 5, banned), high-risk (Annex III), limited risk (transparency obligations), or minimal risk (no obligations). Annex III lists eight high-risk domains including biometrics, employment, education, and essential services. Document the classification rationale for every system.

    3. Step 3: Determine your role: Provider, Deployer, or both

      A Provider develops or places an AI system on the market under its own name. A Deployer uses an AI system under its authority. Obligations differ significantly — Providers carry the full Annex IV documentation burden, while Deployers focus on FRIA, monitoring, and human oversight. Many enterprises are both, depending on the system.

    4. Step 4: Prepare Annex IV technical documentation for high-risk systems

      Annex IV requires a general description, design specifications, training data documentation, performance metrics, risk management measures, and human oversight design. The documentation must be ready before placing the system on the market and kept current for 10 years. This is where most enterprises are furthest behind.

    5. Step 5: Conduct a Fundamental Rights Impact Assessment (FRIA)

      Article 27 requires deployers of high-risk systems in public services and certain private contexts to assess impact on fundamental rights before deployment. Cover affected individuals, frequency of use, harm categories, mitigation measures, and human oversight. Notify the relevant national authority of the FRIA results.

    6. Step 6: Establish an AI literacy programme (Article 4)

      Article 4 has been applicable since 2 February 2025. Providers and deployers must ensure staff and contractors operating or affected by AI systems have a sufficient level of AI literacy. Build role-based training: executives, builders, deployers, and end users each need a different curriculum. Document attendance and refresh annually.

    7. Step 7: Set up logging, monitoring, and human oversight

      High-risk systems must automatically log events for traceability (Article 12). Implement continuous monitoring of accuracy, robustness, and bias. Define human oversight roles per Article 14: who reviews outputs, who can override decisions, who escalates anomalies. Logs must be retained for at least six months.

    8. Step 8: Run conformity assessment and CE marking

      High-risk systems require a conformity assessment under Article 43 before being placed on the market. Most Annex III systems use internal control (Annex VI), while biometric systems require a notified body (Annex VII). Affix CE marking, register the system in the EU database, and issue an EU declaration of conformity.

    9. Step 9: Implement post-market monitoring and incident reporting

      Article 72 requires providers of high-risk systems to operate a post-market monitoring system that collects, documents, and analyses performance data throughout the system's lifecycle. Article 73 requires reporting serious incidents to market surveillance authorities within 15 days (immediately for widespread infringements or critical infrastructure).

    10. Step 10: Update policies, contracts, and AI governance

      Refresh acceptable use policies, vendor contracts, data protection assessments, and board reporting to reflect AI Act obligations. Establish an AI governance committee with cross-functional representation: legal, security, data, product, and HR. Align with existing GDPR, NIS2, and DORA programmes — overlap is significant.

    Key Takeaways

    • The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. High-risk system obligations apply from 2 August 2026, with full enforcement by 2 August 2027.
    • Risk is classified into four tiers: unacceptable (banned), high-risk (Annex III), limited risk (transparency), and minimal risk (no obligations).
    • Annex III high-risk categories include biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, and democratic processes.
    • General-Purpose AI (GPAI) models follow a separate track. A 10^25 FLOPs training compute threshold triggers systemic-risk obligations under Article 51.
    • Penalties reach €35M or 7% of global annual turnover for banned practices, €15M or 3% for other violations, and €7.5M or 1% for incorrect information.
    • Article 4 AI literacy obligations have applied since 2 February 2025 — every organisation using AI must already have a literacy programme in place.
    • In Alice Labs' EU AI Act engagements with 12+ Nordic enterprises in 2025-2026, the most common gap is missing technical documentation for AI systems already in production.
    01 / 05Step

    The Alice Labs EU AI Act Readiness Assessment

    In short

    The Alice Labs EU AI Act Readiness Assessment is a proprietary 25-point checklist that scores an organisation's compliance posture across inventory, classification, documentation, governance, and monitoring — used in 12+ Nordic enterprise engagements in 2025-2026.

    We built the Alice Labs EU AI Act Readiness Assessment after seeing the same gaps repeat across enterprise clients. It is a 25-point checklist organised into five domains, each scored on a 0-4 maturity scale.

    The five domains map directly to the structure of Regulation (EU) 2024/1689:

    • System inventory and classification (5 points). Every AI system identified, classified, and registered with a business owner.
    • Technical documentation (5 points). Annex IV completeness, version control, and 10-year retention.
    • Risk and rights assessment (5 points). FRIA quality, risk management system, bias testing.
    • Governance and literacy (5 points). Article 4 training, governance committee, vendor controls.
    • Monitoring and incident response (5 points). Logging, post-market monitoring, incident reporting workflows.

    In Alice Labs' EU AI Act engagements with 12+ Nordic enterprises in 2025-2026, the most common gap is missing technical documentation for AI systems already in production. The second most common gap is an incomplete inventory — leadership consistently underestimates how many AI systems exist inside the organisation.

    A baseline assessment typically takes 2-3 weeks. Closing the gaps takes 8-16 weeks depending on system count and risk profile.

    02 / 05Step

    Risk Classification Framework: Four Tiers Explained

    In short

    The EU AI Act classifies AI systems into four tiers: unacceptable risk (banned), high-risk (Annex III, full obligations), limited risk (transparency only), and minimal risk (no obligations). Most enterprise AI falls into limited or minimal risk.

    Classification is the gate that determines every downstream obligation. Misclassification is the most expensive mistake an organisation can make under the AI Act.

    Use the table below as a first-pass mapping. Edge cases — for example, a chatbot that screens job applicants — almost always require legal review before classification is finalised.

    EU AI Act risk tiers, examples, and core obligations
    Risk tier Examples Core obligations Article
    Unacceptable Social scoring, manipulative subliminal techniques, real-time public biometric identification (with narrow exceptions) Banned outright; prohibited from market Article 5
    High-risk Biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, democratic processes Annex IV documentation, FRIA, conformity assessment, CE marking, post-market monitoring Articles 6-49 + Annex III
    Limited risk Chatbots, emotion recognition, deepfakes, AI-generated content Transparency: disclose AI interaction or AI-generated content Article 50
    Minimal risk Spam filters, AI-enabled video games, inventory optimisation No mandatory obligations; voluntary codes of conduct encouraged Article 95

    Source: Regulation (EU) 2024/1689

    03 / 05Step

    High-Risk Requirements Deep-Dive: Annex IV Documentation

    In short

    Annex IV requires nine documentation categories for every high-risk AI system: general description, system design, monitoring, performance metrics, risk management, lifecycle changes, standards applied, EU declaration of conformity, and post-market monitoring plan.

    Annex IV is the heart of high-risk compliance. It is also where most enterprises are weakest. The documentation must be ready before a system is placed on the market and updated continuously for 10 years after the last unit is placed on the market.

    The nine required sections are:

    1. General description. Intended purpose, version, provider name, hardware on which it runs, user interface.
    2. Detailed design. System architecture, key design choices, training methodology, datasets used, computational resources.
    3. Monitoring, functioning, and control. Capabilities and limitations, foreseeable outputs, expected accuracy levels.
    4. Performance metrics. Test datasets, validation results, accuracy, robustness, cybersecurity testing.
    5. Risk management system. Identified risks, mitigation measures, residual risk acceptance criteria.
    6. Lifecycle changes. Version control, change log with dates, rationale for each change.
    7. Harmonised standards applied. CEN-CENELEC, ISO, or IEC standards used to demonstrate conformity.
    8. EU declaration of conformity. Issued by the provider, signed, retained for 10 years.
    9. Post-market monitoring plan. Data collection, analysis cadence, escalation procedures.

    Treat Annex IV as a living artefact, not a one-time deliverable. Build it into the system's CI/CD pipeline so it never goes stale.

    Don't know how many AI systems you actually run?

    We start every EU AI Act engagement with a 2-week inventory sprint. Most clients discover 2-3x more AI systems than leadership initially estimated.

    Book an AI Act readiness call
    04 / 05Step

    GPAI Obligations: A Separate Track

    In short

    General-Purpose AI (GPAI) models — foundation models like GPT-4, Claude, and Gemini — follow a separate obligation track under Articles 51-55: documentation, copyright compliance, training-data summaries, and codes of practice. A 10^25 FLOPs training-compute threshold triggers systemic-risk obligations.

    GPAI obligations apply from 2 August 2025 and target the model providers themselves — OpenAI, Anthropic, Google DeepMind, Meta, Mistral, and others. If you build on top of these models, the primary GPAI obligations sit with the provider, not you.

    All GPAI providers must:

    • Maintain technical documentation covering training, evaluation, and intended use.
    • Comply with EU copyright law, including respecting Text and Data Mining (TDM) opt-outs.
    • Publish a sufficiently detailed summary of the content used for training the model.
    • Cooperate with the AI Office and provide information to downstream providers.

    Models trained with more than 10^25 FLOPs of compute are presumed to pose systemic risk and trigger additional obligations: model evaluations, adversarial testing, serious-incident reporting, and cybersecurity protections.

    If you are a deployer building on GPAI, your obligations primarily track with the use case — high-risk if Annex III applies, limited risk for chatbots and content generation. The model provider's documentation flows down to support your own.

    05 / 05Step

    Penalties and Timeline: What's at Stake and When

    In short

    EU AI Act penalties scale by violation: up to €35M or 7% of global turnover for prohibited practices, up to €15M or 3% for other infringements, and up to €7.5M or 1% for incorrect information. The timeline runs from 1 August 2024 entry into force to 2 August 2027 full enforcement.

    The penalty structure is more aggressive than GDPR's 4% cap. For prohibited AI practices, the AI Act allows up to 7% of global annual turnover — and supervisory authorities have signalled they will use it.

    The three penalty tiers are:

    • €35M or 7% of global turnover for violating prohibited AI practices under Article 5 (whichever is higher).
    • €15M or 3% of global turnover for other violations of obligations on providers and deployers.
    • €7.5M or 1% of global turnover for supplying incorrect, incomplete, or misleading information to authorities.

    The applicability timeline is staggered:

    1. 1 August 2024. Regulation enters into force.
    2. 2 February 2025. Prohibited practices ban and Article 4 AI literacy obligations apply.
    3. 2 August 2025. GPAI obligations and governance provisions apply.
    4. 2 August 2026. High-risk system obligations (Annex III) apply — the main enforcement milestone.
    5. 2 August 2027. Full enforcement, including high-risk systems under Annex I (product safety).

    If your roadmap doesn't have a delivery line for 2 August 2026, now is the time to add one.

    About the Authors & Reviewers

    Published ·Updated
    Written by
    Eric Lundberg - Co-Founder, Alice Labs at Alice Labs
    Eric Lundberg

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.

    • AI automation & agent systems lead
    • Workflow design across 100+ deployments
    • Specialist in RAG, integrations & APIs
    Reviewed by
    Linus Ingemarsson - Co-Founder, Alice Labs at Alice Labs
    Linus Ingemarsson

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.

    • 8+ years in AI strategy & implementation
    • Top-5 AI Speaker, Sweden (Mindley 2025)
    • 100+ enterprise AI engagements
    Published · Updated
    Reviewed for technical accuracy, methodology and source integrity.·All claims trace to public sources cited in-line.

    Frequently Asked Questions

    When does the EU AI Act apply to my organisation?

    The EU AI Act entered into force on 1 August 2024. Prohibited practices and AI literacy (Article 4) applied from 2 February 2025. GPAI obligations apply from 2 August 2025. High-risk system obligations apply from 2 August 2026. Full enforcement is reached on 2 August 2027.

    What counts as a high-risk AI system?

    High-risk systems are listed in Annex III and cover eight domains: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice and democratic processes. AI used as a safety component of a regulated product (Annex I) is also high-risk.

    What is the difference between a Provider and a Deployer?

    A Provider develops or commissions an AI system and places it on the EU market or puts it into service under its own name or trademark. A Deployer uses an AI system under its authority, except when use is in the course of a personal non-professional activity. Providers carry the full Annex IV documentation burden; deployers focus on FRIA, monitoring, and human oversight.

    What are the penalties for non-compliance with the EU AI Act?

    Penalties reach up to €35 million or 7% of global annual turnover (whichever is higher) for violations of prohibited practices in Article 5. Other violations of provider and deployer obligations carry fines up to €15 million or 3% of global turnover. Supplying incorrect or misleading information to authorities is fined up to €7.5 million or 1% of global turnover.

    Do I need a Fundamental Rights Impact Assessment (FRIA)?

    Article 27 requires deployers of high-risk AI systems that are bodies governed by public law, private operators providing public services, or deployers using systems for credit scoring or insurance pricing to conduct a FRIA before deployment. The FRIA covers affected individuals, frequency of use, harm categories, mitigation measures, and human oversight, and must be notified to the relevant national authority.

    What is the 10^25 FLOPs threshold for GPAI models?

    Article 51 of the EU AI Act presumes that a General-Purpose AI model has high-impact capabilities — and therefore systemic risk — when the cumulative compute used for training is greater than 10^25 floating-point operations. Models above this threshold trigger additional obligations including model evaluations, adversarial testing, serious-incident reporting, and cybersecurity protections.

    Does the AI Act apply if my company is outside the EU?

    Yes. The EU AI Act applies extraterritorially. It covers providers placing AI systems on the EU market regardless of where they are established, and deployers established in the EU. It also covers providers and deployers outside the EU when the system's output is used in the EU. Non-EU providers must appoint an authorised representative established in the EU.

    How does AI Act compliance overlap with GDPR?

    There is significant overlap. Records of AI systems can extend records of processing under GDPR Article 30. Data Protection Impact Assessments (DPIAs) align with FRIAs for high-risk systems. Transparency obligations under Article 50 reinforce GDPR Articles 13-15. Most enterprises run AI Act compliance as an extension of their existing GDPR programme rather than a parallel workstream.

    Next in AI Governance & Compliance

    Shadow AI Policy Template: Stop Unauthorized AI Use at Work

    Further reading

    Related services

    Related reading

    Sources

    1. Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)(accessed 2026-04-28)
    2. European Commission — Regulatory framework on AI (digital-strategy.ec.europa.eu)(accessed 2026-04-28)
    3. European AI Office — General-Purpose AI codes of practice(accessed 2026-04-28)
    4. EU AI Act Explorer — Annex III high-risk categories(accessed 2026-04-28)
    5. EU AI Act — Annex IV technical documentation requirements(accessed 2026-04-28)
    6. EU AI Act — Article 99 penalties for providers and deployers(accessed 2026-04-28)
    7. EU AI Act — Article 51 GPAI systemic-risk threshold (10^25 FLOPs)(accessed 2026-04-28)

    Next scheduled review:

    Need to be EU AI Act ready before 2 August 2026?

    Alice Labs runs the EU AI Act Readiness Assessment with Nordic enterprises — a 25-point baseline plus a 90-day remediation plan tailored to your AI portfolio.

    See AI governance services
    Share

    Get in Touch!

    The lab usually responds within 24 hours.

    Need help with AI?Get in touch