EU AI Act conformity: a checklist for the first pass
For: Companies with AI in use
Updated: 2026-09
A workable first pass through the EU AI Act has six parts: know which AI runs in the business, determine your role for each system, classify under Article 6, check transparency duties separately, ensure AI literacy, and file everything so it can be found under scrutiny.
The EU AI Act reads as overwhelming on first contact because it bundles obligations for very different actors into one instrument. For any single company the slice that actually applies is usually far smaller than feared — but you only know that once you have determined it.
This checklist walks through the first complete pass. It does not replace legal assessment of individual cases, but it puts the starting position into a state where such assessment becomes targeted and therefore affordable.
The checklist
- 01
Inventory AI systems completely
Record every system with an AI function, explicitly including functions activated later inside existing software. Assistant features in CRM, accounting or collaboration tools are the ones most often missed.
Done when: The list gives purpose, responsible person and vendor for each system, and a business unit has confirmed nothing is missing.
- 02
Determine your role per system
For each system establish whether you act as provider or deployer. With bought-in software carrying your own branding or substantial modification, the role can shift to provider, which widens the obligations considerably.
Done when: Every inventory entry carries a reasoned role assignment rather than a bare label.
- 03
Classify under Article 6
Establish the risk tier per system: prohibited practice, high risk under Annex III or as a safety component, or outside those categories. What governs is the intended purpose, not the technology.
Done when: Each system has a written classification with reasoning, including the alternatives considered and rejected.
- 04
Check transparency duties separately
Labelling and disclosure duties under Article 50 apply regardless of risk tier. Chatbots, synthetic content and emotion recognition trigger them even where the system is not high risk.
Done when: For every system it is noted whether a disclosure duty applies and where in the product it is implemented.
- 05
Ensure AI literacy under Article 4
Grade the training requirement by role: more depth for people selecting or operating systems, less for occasional use. The regulation asks for a sufficient level, not a uniform one.
Done when: A mapping from role to training depth exists, and each person has a recorded date and content.
- 06
File evidence so it can be found
Gather classifications, vendor statements, training records and reasoning in one place. In practice the evidence rarely fails because a document is missing; it fails because nobody knows where it sits.
Done when: A third party can locate the classification and its reasoning for any given system without asking.
- 07
Set a review cycle
Define the triggers for revisiting the inventory: new software, material change in purpose, new Commission guidance. Without a trigger the inventory goes stale within a few months.
Done when: A date and a named responsible person are in the calendar.
Common mistakes
- —The inventory is built once and never touched again. Two quarters later it no longer reflects reality and the evidence loses its value.
- —The AI Act classification gets confused with the GDPR risk assessment. Both are needed, they answer different questions, and neither converts into the other.
- —Bought-in software is treated as settled because the vendor asserts conformity. As a deployer you carry your own obligations regardless.
- —Transparency duties are missed because the system was not classified as high risk. The two questions are independent.
What this checklist does not cover
- —This checklist is not legal advice. For contested classifications — particularly at the Annex III boundary — a specialist law firm is not substitutable.
- —It does not cover the detailed conformity assessment for high-risk systems. Once a system lands there, a considerably larger set of obligations follows.
- —Sector-specific requirements — medical devices, financial services, critical infrastructure — come on top and are not addressed here.
- —Commission guidance is still outstanding on several points. Where practice is still forming, documented reasoning is currently the best available answer.
Parent service: EU AI Act & Compliance Advisory
Matching offers
EU AI Act gap assessment
A gap assessment answers three questions: which AI systems do we use, how are they classified under the EU AI Act, and what is missing for conformity? The output is a prioritised action plan, with an eye on the 2 August 2026 enforcement window.
Building AI governance
AI governance gives your handling of AI a repeatable structure: an AI policy, a risk inventory, clear roles and a lifecycle process — oriented to ISO/IEC 42001. The result is the organisational backbone that produces the records the AI Act requires, audit-ready and durably.
FAQ
Where do you start with nothing prepared?
The inventory. Without the list none of the later questions can be answered meaningfully, and it is the only step that can be completed internally without legal knowledge.
Does this apply to Swiss companies?
Switzerland has not adopted the AI Act. Swiss companies are nonetheless in scope when they place AI systems on the EU market or their output is used in the EU.
How long does a first pass take?
Almost entirely a function of how many systems there are. The effort sits in the inventory and in gathering vendor statements, not in the classification itself.
Do we need a dedicated role for this?
In smaller organisations, no. The task sits well with whoever already owns data protection or quality. What matters is that it is explicitly assigned.
More checklists
High risk or not: reasoning an Annex III classification properly
High-risk classification follows a fixed order: first the deployment area under Annex III, then whether the system plays a substantive role in the decision, then the exemption in Article 6(3). Each of those steps has to be documented with reasoning.
AI literacy under Article 4: from intention to evidence that holds
Article 4 asks for a sufficient level of AI literacy, measured against role, context and the people affected. It becomes workable in four moves: form roles, set a depth per role, train accordingly, and record attendance with date, content and the link to the role.
GDPR for SaaS: what has to stand before your first enterprise customer
Six areas are unavoidable for a SaaS product: a legal basis per processing activity, a maintained processing register, data subject rights implemented in the system, a deletion concept that actually works, clean sub-processor chains, and a demonstrable statement on data residency.
