Skip to content
Innopulse Consulting

EU AI Act conformity: a checklist for the first pass

For: Companies with AI in use

Updated: 2026-09

In short

A workable first pass through the EU AI Act has six parts: know which AI runs in the business, determine your role for each system, classify under Article 6, check transparency duties separately, ensure AI literacy, and file everything so it can be found under scrutiny.

The EU AI Act reads as overwhelming on first contact because it bundles obligations for very different actors into one instrument. For any single company the slice that actually applies is usually far smaller than feared — but you only know that once you have determined it.

This checklist walks through the first complete pass. It does not replace legal assessment of individual cases, but it puts the starting position into a state where such assessment becomes targeted and therefore affordable.

The checklist

  1. 01

    Inventory AI systems completely

    Record every system with an AI function, explicitly including functions activated later inside existing software. Assistant features in CRM, accounting or collaboration tools are the ones most often missed.

    Done when: The list gives purpose, responsible person and vendor for each system, and a business unit has confirmed nothing is missing.

  2. 02

    Determine your role per system

    For each system establish whether you act as provider or deployer. With bought-in software carrying your own branding or substantial modification, the role can shift to provider, which widens the obligations considerably.

    Done when: Every inventory entry carries a reasoned role assignment rather than a bare label.

  3. 03

    Classify under Article 6

    Establish the risk tier per system: prohibited practice, high risk under Annex III or as a safety component, or outside those categories. What governs is the intended purpose, not the technology.

    Done when: Each system has a written classification with reasoning, including the alternatives considered and rejected.

  4. 04

    Check transparency duties separately

    Labelling and disclosure duties under Article 50 apply regardless of risk tier. Chatbots, synthetic content and emotion recognition trigger them even where the system is not high risk.

    Done when: For every system it is noted whether a disclosure duty applies and where in the product it is implemented.

  5. 05

    Ensure AI literacy under Article 4

    Grade the training requirement by role: more depth for people selecting or operating systems, less for occasional use. The regulation asks for a sufficient level, not a uniform one.

    Done when: A mapping from role to training depth exists, and each person has a recorded date and content.

  6. 06

    File evidence so it can be found

    Gather classifications, vendor statements, training records and reasoning in one place. In practice the evidence rarely fails because a document is missing; it fails because nobody knows where it sits.

    Done when: A third party can locate the classification and its reasoning for any given system without asking.

  7. 07

    Set a review cycle

    Define the triggers for revisiting the inventory: new software, material change in purpose, new Commission guidance. Without a trigger the inventory goes stale within a few months.

    Done when: A date and a named responsible person are in the calendar.

Common mistakes

  • The inventory is built once and never touched again. Two quarters later it no longer reflects reality and the evidence loses its value.
  • The AI Act classification gets confused with the GDPR risk assessment. Both are needed, they answer different questions, and neither converts into the other.
  • Bought-in software is treated as settled because the vendor asserts conformity. As a deployer you carry your own obligations regardless.
  • Transparency duties are missed because the system was not classified as high risk. The two questions are independent.

What this checklist does not cover

  • This checklist is not legal advice. For contested classifications — particularly at the Annex III boundary — a specialist law firm is not substitutable.
  • It does not cover the detailed conformity assessment for high-risk systems. Once a system lands there, a considerably larger set of obligations follows.
  • Sector-specific requirements — medical devices, financial services, critical infrastructure — come on top and are not addressed here.
  • Commission guidance is still outstanding on several points. Where practice is still forming, documented reasoning is currently the best available answer.

Parent service: EU AI Act & Compliance Advisory

FAQ

Where do you start with nothing prepared?

The inventory. Without the list none of the later questions can be answered meaningfully, and it is the only step that can be completed internally without legal knowledge.

Does this apply to Swiss companies?

Switzerland has not adopted the AI Act. Swiss companies are nonetheless in scope when they place AI systems on the EU market or their output is used in the EU.

How long does a first pass take?

Almost entirely a function of how many systems there are. The effort sits in the inventory and in gathering vendor statements, not in the classification itself.

Do we need a dedicated role for this?

In smaller organisations, no. The task sits well with whoever already owns data protection or quality. What matters is that it is explicitly assigned.

LM
Reviewed by
Founder & CEO · MSc Innovation Management (FFHS) · Author of “Identity Over Discipline”
Working on something similar?

EU AI Act conformity: a checklist for the first pass