A comprehensive checklist to guide your organization through EU AI Act compliance. Filter by risk level and download as PDF.
Document every AI system in your organization and map it to the EU AI Act risk categories (Unacceptable, High, Limited, Minimal).
Check that none of your AI systems involve social scoring, subliminal manipulation, exploitation of vulnerabilities, or prohibited biometric identification.
Establish and maintain an ongoing risk management process for high-risk AI systems, including risk identification, analysis, estimation, and mitigation.
Ensure training, validation, and testing datasets are relevant, representative, free of errors, and complete. Implement data quality criteria.
Prepare comprehensive documentation covering system design, development process, capabilities, limitations, and performance metrics.
Implement logging capabilities to record events throughout the AI system lifecycle for traceability and audit purposes.
Create clear instructions for use, including system capabilities, limitations, intended purpose, and human oversight requirements. Article 13 for high-risk systems; Article 50 covers limited-risk disclosure separately.
Ensure human operators can understand, monitor, and intervene in the AI system operation. Define clear override procedures.
Ensure the AI system achieves appropriate levels of accuracy, is resilient to errors, and is protected against security threats.
Conduct the appropriate conformity assessment procedure before placing the high-risk AI system on the market or putting it into service.
Register your high-risk AI system in the EU database as required by Article 71 of the EU AI Act.
Ensure users are clearly informed when they are interacting with an AI system, including chatbots and automated decision tools. Article 50(1).
Mark all AI-generated or manipulated content (text, images, audio, video) in a machine-readable format so users and platforms can identify it. Article 50(2).
Ensure all personal data processed by AI systems complies with GDPR, including lawful basis, purpose limitation, and data minimization.
Create procedures for reporting serious incidents to relevant national authorities within the required timeframes.
Ensure all employees involved in AI system development, deployment, or oversight understand their compliance obligations under the EU AI Act.
Consider adopting voluntary codes of conduct for minimal-risk AI systems covering environmental sustainability, accessibility, and stakeholder participation.
Evaluate compliance of third-party AI providers and ensure contractual obligations include EU AI Act requirements.
Establish a post-market monitoring system to actively collect and review experience with the AI system after deployment.
Perform a DPIA for high-risk AI systems processing personal data, as required by both GDPR Article 35 and the EU AI Act.
Run a free scan of your website to identify specific compliance gaps.