All Articles EU AI Act

EU AI Act Compliance Checklist: Are You Ready for August 2026?

A definitive, action-oriented compliance guide for the EU AI Act ahead of the August 2026 enforcement deadline. This in-depth analysis covers risk classification, high-risk obligations, GPAI rules, conformity assessments, penalties up to €35M or 7% of global turnover, and a 10-step enterprise readiness checklist”tailored for organizations operating in the EU, Germany, and the UK.

33 min read Likhon
🎧 Listen to this article
Checking audio availability...

EU AI Act Compliance Checklist: Are You Ready for August 2026?

Updated August 4, 2026: The main August 2026 milestone has arrived. Article 50 transparency requirements now apply, the European Commission can enforce the general-purpose AI model rules, and supervision of the AI-literacy obligation is active. However, a July 2026 amendment postponed most high-risk AI system requirements to December 2027 or August 2028.

The European Union’s Artificial Intelligence Act is no longer a distant compliance project.

The Regulation entered into force on August 1, 2024, and its obligations have been introduced in stages. Prohibited AI practices and AI-literacy requirements began applying in February 2025. General-purpose AI model obligations began applying in August 2025. On August 2, 2026, the Regulation’s general application date arrived, including the transparency duties in Article 50 and enforcement powers for general-purpose AI obligations.[^1][^2]

A last-minute legal change is essential to understand. Regulation (EU) 2026/1744—the Digital Omnibus on AI—entered into force on July 27, 2026. It delayed most requirements for high-risk AI systems:

  • Annex III high-risk systems: December 2, 2027
  • High-risk AI embedded in regulated products under Annex I: August 2, 2028

The amendment did not cancel the August 2026 milestone. Businesses still need to address AI transparency, AI literacy, prohibited uses, general-purpose AI rules, governance, vendor accountability, and regulatory evidence now.[^3]

This guide provides an end-to-end EU AI Act compliance checklist for providers, deployers, importers, distributors, product teams, public bodies, and companies using third-party AI services.

Legal notice: This article is general compliance information, not legal advice. The AI Act must be assessed alongside applicable national law, the GDPR, sector-specific legislation, employment law, consumer-protection rules, intellectual-property law, and contractual obligations.


Table of Contents

  1. EU AI Act Compliance in August 2026: The Quick Answer
  2. The Current EU AI Act Timeline
  3. Who Must Comply With the EU AI Act?
  4. Understand Your Role: Provider, Deployer, or Other Operator
  5. The EU AI Act Risk Framework
  6. The Complete EU AI Act Compliance Checklist
  7. Checklist 1: Establish AI Governance and Accountability
  8. Checklist 2: Build a Complete AI System Inventory
  9. Checklist 3: Identify and Stop Prohibited AI Practices
  10. Checklist 4: Implement AI Literacy Measures
  11. Checklist 5: Meet Article 50 Transparency Requirements
  12. Checklist 6: Comply With General-Purpose AI Obligations
  13. Checklist 7: Prepare for High-Risk AI Requirements
  14. Checklist 8: Strengthen Vendor and AI Supply-Chain Controls
  15. Checklist 9: Align the AI Act With GDPR and Fundamental Rights
  16. Checklist 10: Create Technical and Compliance Evidence
  17. Checklist 11: Establish Monitoring and Incident Response
  18. Checklist 12: Prepare for Regulators and Enforcement
  19. A 30-Day Remediation Plan
  20. EU AI Act Compliance Evidence Checklist
  21. Common Compliance Mistakes
  22. EU AI Act Penalties
  23. Frequently Asked Questions
  24. Final Readiness Test
  25. Official Sources

EU AI Act Compliance in August 2026: The Quick Answer

As of August 4, 2026, an organisation should be able to answer yes to the following questions:

  • Do we know which AI systems and general-purpose AI models we provide, deploy, import, distribute, or integrate?
  • Have we confirmed that none of our current uses fall within the prohibited-practice rules?
  • Have we implemented context-appropriate AI-literacy measures for staff and others operating AI systems on our behalf?
  • Do our chatbots and other directly interactive AI systems inform people that they are interacting with AI where Article 50 requires it?
  • Can our generative AI systems mark synthetic outputs in a machine-readable and detectable form where required?
  • Do we visibly disclose deepfakes and relevant AI-generated public-interest text where required?
  • If we provide a general-purpose AI model, can we demonstrate compliance with the documentation, downstream-information, copyright, and training-summary duties?
  • Do we have a plan for general-purpose AI models with systemic risk?
  • Have we classified likely high-risk AI systems, even though most high-risk duties were postponed?
  • Can we produce evidence showing how our controls work?
  • Can we respond to a regulator, affected person, customer, or auditor without reconstructing our AI estate from scratch?

A “no” answer does not always mean the same legal exposure. Obligations vary by the organisation’s role, the system’s intended purpose, the people affected, and the type of AI involved. It does mean the organisation needs a documented remediation decision.


The Current EU AI Act Timeline

The timeline below reflects the AI Act as amended by Regulation (EU) 2026/1744.

Date What Applies
August 1, 2024 Regulation (EU) 2024/1689 entered into force.
February 2, 2025 The AI-system definition, initial prohibited-practice rules, and Article 4 AI-literacy obligation began applying.
August 2, 2025 Governance provisions, penalties, and obligations for providers of general-purpose AI models began applying.
July 27, 2026 Regulation (EU) 2026/1744 entered into force, amending the AI Act and postponing most high-risk requirements.
August 2, 2026 The AI Act’s general application date; Article 50 transparency rules apply. The Commission’s enforcement powers for general-purpose AI obligations apply.
August 3, 2026 According to the Commission’s AI-literacy Q&A, supervision and enforcement of Article 4 are active.
December 2, 2026 New prohibitions concerning certain AI-generated non-consensual intimate material and child sexual abuse material apply. Providers of generative systems placed on the market before August 2, 2026 must meet the Article 50(2) machine-readable marking duty by this date.
August 2, 2027 Providers of general-purpose AI models placed on the market before August 2, 2025 must comply with the applicable GPAI obligations.
December 2, 2027 Most requirements and operator obligations for Annex III high-risk AI systems apply.
August 2, 2028 Most requirements for AI systems classified as high-risk because they are regulated products or safety components under Annex I apply.

The postponement of high-risk requirements is not a reason to stop preparing. Classification, data governance, procurement, system redesign, logging, human oversight, documentation, testing, and contractual access can require substantial lead time.


Who Must Comply With the EU AI Act?

The AI Act applies to public and private actors inside and outside the European Union when they:

  • place an AI system or general-purpose AI model on the EU market;
  • put an AI system into service in the EU;
  • use an AI system in the EU; or
  • are outside the EU but the output produced by the system is used in the EU, where the Regulation’s territorial conditions are met.

The Commission describes the framework as applying to actors inside and outside the EU that place AI systems or general-purpose AI models on the EU market, put systems into service, or use them in the EU.[^4]

The Act includes exclusions and special rules. For example, certain activities involving research, testing, or development before market release may fall outside its application, and systems exclusively used for military, defence, or national-security purposes are excluded under the conditions in the Regulation.

Do not assume that being headquartered outside Europe removes the obligation. A US, UK, Canadian, Indian, Singaporean, or other non-EU company may be in scope because it supplies an AI system to EU customers, operates an EU-facing service, or provides a model used in the European market.


Understand Your Role: Provider, Deployer, or Other Operator

Compliance begins with role classification.

Provider

A provider develops an AI system or general-purpose AI model—or has one developed—and places it on the market or puts it into service under its own name or trademark.

You may be a provider even when another vendor supplied the foundation model or core technology. A company that turns a third-party model into a branded recruitment, insurance, education, medical, or customer-service product may have provider obligations for the resulting AI system.

Deployer

A deployer uses an AI system under its authority, except for personal, non-professional use.

Examples include:

  • an employer using an AI recruitment tool;
  • a bank using an AI fraud or credit system;
  • a retailer using a customer-service chatbot;
  • a public authority using an eligibility or case-management system;
  • a publisher using generative AI to produce public-interest content.

Importer and Distributor

Importers and distributors have supply-chain obligations, including checking relevant provider documentation and responding appropriately when they identify non-compliance.

Authorised Representative

A provider established outside the EU may need an authorised representative in the Union, particularly for general-purpose AI model obligations and other relevant provider duties.

Product Manufacturer or Downstream Integrator

A business incorporating AI into its own product can acquire provider responsibilities. Rebranding, changing intended purpose, or substantially modifying an AI system may also change the responsible legal role.

Why Role Mapping Matters

The same technology can create different obligations for different organisations.

A model developer may be a GPAI provider. A software company integrating that model may be an AI-system provider. A corporation buying the software may be a deployer. A cloud marketplace may also have distribution or intermediary responsibilities.

Record the legal role for every system, not only for the organisation as a whole.


The EU AI Act Risk Framework

The AI Act uses a risk-based structure.

1. Prohibited Practices

A limited set of AI uses is prohibited because of unacceptable risks to fundamental rights, safety, and EU values.

2. High-Risk AI Systems

High-risk systems include certain systems listed in Annex III and AI systems that are regulated products or safety components under specified EU product legislation.

Annex III areas include certain uses involving:

  • biometrics;
  • critical infrastructure;
  • education and vocational training;
  • employment and worker management;
  • access to essential public or private services;
  • law enforcement;
  • migration, asylum, and border control;
  • administration of justice and democratic processes.

Most detailed high-risk requirements are now scheduled for December 2027 or August 2028.

3. Transparency-Risk Systems

Article 50 applies to specified interactive and generative AI uses, including:

  • AI systems directly interacting with individuals;
  • systems generating or manipulating synthetic content;
  • emotion-recognition and biometric-categorisation systems;
  • deepfakes;
  • certain AI-generated text published to inform the public on matters of public interest.

These rules apply from August 2, 2026, subject to the legal exceptions and the limited transitional rule created by the Digital Omnibus.

4. Minimal or No Additional AI Act Risk

Most AI systems do not fall into the prohibited, high-risk, or specific transparency categories. They may still be governed by other laws and by the generally applicable AI-literacy duty.

5. General-Purpose AI Models

General-purpose AI models are regulated separately. All GPAI providers have transparency and copyright-related obligations, while providers of models with systemic risk have additional safety, evaluation, incident, and cybersecurity duties.


The Complete EU AI Act Compliance Checklist

Use the following status labels:

  • Complete: Implemented, tested, and evidenced
  • In progress: Owner and delivery date assigned
  • Gap: No adequate control
  • Not applicable: Legal basis documented
  • Needs legal review: Classification or exception is uncertain

Checklist 1: Establish AI Governance and Accountability

1. Appoint an Accountable Executive

Assign an executive who owns AI Act readiness across legal, compliance, product, engineering, security, privacy, procurement, HR, communications, and internal audit.

Evidence to retain:

  • board or executive mandate;
  • responsibility matrix;
  • reporting cadence;
  • approved budget;
  • escalation path.

2. Create a Cross-Functional AI Governance Committee

The committee should include relevant leaders from:

  • legal and regulatory compliance;
  • privacy and data protection;
  • information security;
  • enterprise risk;
  • product management;
  • engineering and machine learning;
  • procurement and vendor management;
  • HR and learning;
  • communications or content operations;
  • internal audit.

A committee without decision rights is not a control. Define who may approve, restrict, suspend, or retire an AI use.

3. Adopt an AI Governance Policy

The policy should establish:

  • permitted and prohibited uses;
  • required intake and approval;
  • role classification;
  • risk classification;
  • vendor review;
  • human-oversight expectations;
  • documentation requirements;
  • transparency and labelling;
  • incident reporting;
  • monitoring;
  • staff responsibilities;
  • exceptions and escalation.

4. Integrate AI Into Existing Risk Management

Connect AI governance with:

  • enterprise risk management;
  • privacy impact assessments;
  • information-security reviews;
  • product safety;
  • model risk management;
  • procurement;
  • outsourcing;
  • records management;
  • complaints;
  • internal audit.

Avoid building an isolated AI compliance process that duplicates controls but does not influence deployment decisions.

5. Define an AI Change-Control Process

Require reassessment when there is a material change to:

  • model or model version;
  • intended purpose;
  • target users;
  • affected population;
  • training or reference data;
  • prompt and system instructions;
  • automated decision logic;
  • human-oversight design;
  • vendor;
  • deployment region;
  • output channel;
  • integration or tool access.

Checklist 2: Build a Complete AI System Inventory

An AI inventory is the foundation of defensible compliance.

Minimum Inventory Fields

Field What to Record
System name Internal and vendor names
Business owner Accountable operational owner
Technical owner Engineering or IT owner
Vendor/model Provider, model, version, service
Intended purpose The purpose approved by the organisation
Actual uses How teams currently use the system
Users Staff, contractors, customers, public
Affected persons People whose rights, access, employment, credit, education, or services may be affected
Input data Personal, confidential, biometric, copyrighted, public
Output Decision, recommendation, ranking, content, prediction
Automation level Advisory, human-approved, automated
Legal role Provider, deployer, importer, distributor, integrator
Risk category Prohibited, high-risk candidate, Article 50, GPAI, other
Geography EU countries and non-EU markets
Transparency method Notice, label, watermark, machine-readable mark
Human oversight Assigned persons and intervention rights
Logging Inputs, outputs, decisions, version, timestamp
Status Pilot, production, suspended, retired
Review date Last and next assessment

Find Shadow AI

Inventory work must include unsanctioned or decentralised use, such as:

  • staff using public generative AI accounts;
  • browser extensions;
  • AI meeting assistants;
  • marketing content tools;
  • recruitment add-ons;
  • customer-support copilots;
  • code-generation tools;
  • AI features activated inside existing SaaS products;
  • automated scoring created by analytics teams;
  • third-party agents connected to company systems.

Use surveys, procurement records, SSO logs, expense data, SaaS discovery, network telemetry, data-loss prevention alerts, and interviews.

Each inventory record should link to:

  • classification assessment;
  • vendor contract;
  • privacy assessment;
  • security review;
  • transparency design;
  • AI-literacy requirements;
  • testing results;
  • monitoring plan;
  • incident history;
  • approval record.

Checklist 3: Identify and Stop Prohibited AI Practices

Most prohibited-practice rules have applied since February 2, 2025.

The Commission’s current summary includes prohibitions involving:

  • harmful manipulation, deception, or subliminal techniques under the legal conditions in Article 5;
  • exploitation of vulnerabilities linked to age, disability, or particular social or economic situations;
  • social scoring that leads to prohibited detrimental or unfavourable treatment;
  • individual criminal-risk prediction based solely on profiling or personality traits, subject to the Regulation’s limited distinction for supporting human assessments based on objective facts;
  • untargeted scraping of facial images from the internet or CCTV to create or expand facial-recognition databases;
  • emotion inference in workplaces and educational institutions, except for specified medical or safety purposes;
  • biometric categorisation to infer protected or sensitive characteristics under Article 5;
  • real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, except under narrow legally controlled circumstances.[^5]

Regulation (EU) 2026/1744 added prohibitions involving AI systems intended for—or lacking adequate safeguards against certain reasonably foreseeable generation of—non-consensual intimate material and child sexual abuse material. Those additions apply from December 2, 2026.[^3]

Prohibited-Practice Action List

  • Screen every AI use against Article 5.
  • Suspend any potentially prohibited system pending legal review.
  • Check whether employee-monitoring tools infer emotion.
  • Review biometric products and datasets.
  • Review public-space surveillance and law-enforcement-related use.
  • Prohibit untargeted facial-image scraping.
  • Review scoring systems for cross-context social scoring.
  • Review behavioural design for manipulation or exploitation.
  • Add controls against non-consensual intimate content and child sexual abuse material before December 2, 2026.
  • Document any exception and the evidence supporting it.
  • Add prohibited-use clauses to vendor and employee policies.
  • Create a reporting channel for suspected prohibited uses.

Evidence

Retain:

  • screening questionnaire;
  • legal analysis;
  • product test results;
  • safeguards;
  • misuse testing;
  • content-safety controls;
  • suspension or remediation decisions;
  • executive approval for any reliance on an exception.

Checklist 4: Implement AI Literacy Measures

Article 4 applies to providers and deployers of AI systems.

Following the July 2026 amendment, providers and deployers must take measures to support the development of AI literacy among staff and other people dealing with AI-system operation or use on their behalf. The measures should take account of technical knowledge, experience, education, training, context of use, and the people or groups affected. The amendment does not mandate a single “sufficient” literacy level for every person.[^3][^6]

The Commission states that Article 4 has applied since February 2, 2025 and that its supervision and enforcement rules apply from August 3, 2026.[^6]

Build Role-Based Training

All Staff

Cover:

  • what AI is and is not;
  • approved tools;
  • confidential and personal data;
  • hallucinations and verification;
  • copyright and attribution;
  • security threats;
  • prohibited uses;
  • reporting concerns.

AI Product and Engineering Teams

Cover:

  • AI Act roles and classification;
  • intended purpose;
  • evaluation and testing;
  • data governance;
  • robustness and cybersecurity;
  • technical documentation;
  • transparency;
  • human oversight;
  • logging;
  • change control.

HR and Recruitment

Cover:

  • employment-related high-risk use cases;
  • discrimination;
  • workplace notices;
  • human review;
  • vendor claims;
  • candidate rights;
  • prohibited emotion inference.

Marketing, Media, and Communications

Cover:

  • AI-generated content disclosure;
  • deepfake labelling;
  • public-interest text;
  • machine-readable marking;
  • review and editorial responsibility;
  • brand and consumer-protection risks.

Cover:

  • role allocation;
  • supplier evidence;
  • audit and access rights;
  • model changes;
  • sub-processors;
  • geography;
  • incident notifications;
  • termination and migration.

Executives and Board Members

Cover:

  • legal timeline;
  • accountability;
  • risk appetite;
  • enforcement;
  • resource decisions;
  • material incidents;
  • reporting.

AI Literacy Evidence Checklist

  • Training-needs assessment
  • Role-based curriculum
  • Attendance and completion records
  • Training materials and versions
  • Scenario exercises
  • Knowledge checks where appropriate
  • Refresher schedule
  • Contractor coverage
  • New-hire onboarding
  • Lessons learned from incidents
  • Board and executive briefings

The Commission maintains a repository of AI-literacy practices. It is a useful source of examples, but copying a listed practice does not automatically create a presumption of compliance.[^7]


Checklist 5: Meet Article 50 Transparency Requirements

Article 50 is one of the most important August 2026 obligations.

The Commission published final transparency guidelines on July 20, 2026. It also assessed the voluntary Code of Practice on Transparency of AI-Generated Content as an adequate instrument for facilitating compliance with Article 50(2), (4), and (5). Adherence is useful evidence but is not conclusive proof of compliance.[^8][^9]

A. AI Systems That Interact Directly With People

Providers must design relevant systems so that individuals are informed that they are interacting with AI, unless a legal exception applies.

Examples may include:

  • customer-service chatbots;
  • virtual assistants;
  • AI interviewers;
  • voice bots;
  • interactive avatars;
  • conversational sales systems.

Checklist:

  • Display or communicate the AI notice clearly.
  • Do not bury it in general terms and conditions.
  • Test the notice across web, mobile, telephone, and accessibility modes.
  • Preserve evidence of the notice presented.
  • Document any conclusion that the AI nature is obvious or an exception applies.
  • Ensure local-language notices where required for meaningful communication.

B. Machine-Readable Marking of Synthetic Content

Providers of AI systems generating or manipulating synthetic audio, image, video, or text content must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to technical feasibility and the legal exceptions.

The obligation does not apply to the extent that a system merely performs standard assistive editing or does not substantially alter the input or its meaning, as specified in Article 50 and the Commission guidance.

Checklist:

  • Identify all systems capable of generating or substantially manipulating content.
  • Implement machine-readable provenance or marking.
  • Test whether the marker survives normal export and distribution workflows.
  • Document supported formats and known limitations.
  • Prevent downstream product features from stripping required markers where reasonably controllable.
  • Maintain versioned technical evidence.
  • Review the Transparency Code of Practice.
  • Document alternative adequate compliance measures if not signing the Code.

Transitional Rule for Existing Systems

Providers of relevant generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to comply with Article 50(2). This is a targeted transitional rule for the machine-readable marking duty; it is not a general postponement of Article 50.[^3]

C. Emotion Recognition and Biometric Categorisation

Deployers must inform individuals exposed to emotion-recognition or biometric-categorisation systems where Article 50 applies.

Checklist:

  • Confirm the system is lawful and not prohibited under Article 5.
  • Provide clear notice to exposed individuals.
  • Address GDPR and biometric-data rules separately.
  • Document purpose, data, retention, access, and affected groups.
  • Test whether individuals can understand the notice.

D. Deepfake Disclosure

Deployers using an AI system to create or manipulate image, audio, or video content constituting a deepfake must disclose that the content was artificially generated or manipulated, subject to the Act’s exceptions and tailored rules for artistic, creative, satirical, fictional, and analogous works.

Checklist:

  • Define how deepfakes are detected internally.
  • Apply a clear and perceivable disclosure.
  • Preserve machine-readable marking where the provider duty applies.
  • Review artistic and editorial exceptions with counsel.
  • Include disclosure in syndicated and republished versions.
  • Create approval controls for realistic depictions of people.

E. AI-Generated Public-Interest Text

Deployers must disclose artificially generated or manipulated text published to inform the public on matters of public interest, unless an applicable exception applies—for example, where there has been human review or editorial control and a person holds editorial responsibility under the conditions in Article 50.

Checklist:

  • Identify public-interest content workflows.
  • Define what constitutes meaningful human review.
  • Assign editorial responsibility.
  • Document the review and approval.
  • Label content when the exception is not satisfied.
  • Retain the generated draft, edits, reviewer, and publication record where proportionate.

Article 50 Evidence Pack

Create a package containing:

  • applicability analysis;
  • screenshots or recordings of AI notices;
  • marker specifications;
  • detection tests;
  • sample labelled content;
  • exception analyses;
  • editorial-review procedures;
  • supplier documentation;
  • Code of Practice decision;
  • user complaints and remediation.

Checklist 6: Comply With General-Purpose AI Obligations

The GPAI rules began applying on August 2, 2025. From August 2, 2026, the European Commission can enforce full compliance for models placed on the market after the applicable date.[^10]

Are You a GPAI Provider?

You may be a provider if you:

  • develop a general-purpose model;
  • place a model on the EU market;
  • make a model available through an API or downloadable release;
  • significantly modify a general-purpose model in a way that creates provider responsibilities;
  • release a model under your name or trademark.

Using a third-party model does not automatically make you its GPAI provider, but you may be the provider of the downstream AI system.

Duties for GPAI Providers

The Commission summarises the core obligations as:

  • drawing up and maintaining technical model documentation;
  • giving downstream AI-system providers information needed to understand capabilities and limitations and comply with their own duties;
  • implementing a policy to comply with EU copyright and related-rights law, including rights reservations;
  • publishing a sufficiently detailed summary of the training content using the Commission template;
  • appointing an authorised representative in the EU when required for providers established outside the Union.[^11]

Additional Duties for GPAI Models With Systemic Risk

Providers of GPAI models with systemic risk must address additional duties including:

  • notification to the Commission;
  • model evaluations;
  • systemic-risk assessment and mitigation;
  • serious-incident reporting;
  • cybersecurity protection for the model and relevant infrastructure.

The Regulation uses a computational threshold that creates a presumption of systemic risk, while allowing Commission designation and reassessment under the legal criteria.

GPAI Compliance Checklist

  • Determine whether the model is a GPAI model.
  • Determine whether your organisation is the provider or has significantly modified the model.
  • Assess open-source provisions and exceptions with counsel.
  • Create technical documentation.
  • Prepare downstream integration information.
  • Adopt and operate an EU copyright-compliance policy.
  • Publish the required training-content summary.
  • Appoint an EU authorised representative where required.
  • Evaluate systemic-risk status.
  • Notify the AI Office when required.
  • Establish model evaluation and systemic-risk processes.
  • Establish serious-incident reporting.
  • Protect models and infrastructure against cyber risks.
  • Review the GPAI Code of Practice.
  • Sign the Code or document alternative adequate compliance measures.
  • Prepare submissions through the EU SEND platform where applicable.

Existing GPAI Models

Providers of GPAI models placed on the market before August 2, 2025 have until August 2, 2027 to meet the applicable obligations.[^1]


Checklist 7: Prepare for High-Risk AI Requirements

The Digital Omnibus postponed most high-risk duties, but it did not remove them.

Current Deadlines

  • December 2, 2027: Annex III high-risk systems
  • August 2, 2028: high-risk AI systems regulated as products or safety components under Annex I

The Commission’s high-risk classification materials were still being finalised during summer 2026. Use the Regulation, current Commission information, and legal advice, and track final guidance as it is adopted.[^12]

High-Risk Classification Questions

Ask:

  1. Is the AI a regulated product or a safety component of a product covered by Annex I?
  2. Is third-party conformity assessment required under the relevant product legislation?
  3. Is the intended purpose listed in Annex III?
  4. Does an Article 6 exception apply to an Annex III use because the system does not pose a significant risk of harm and does not materially influence decision-making?
  5. Does the system perform profiling, affecting the application of the high-risk classification rules?
  6. Has the intended purpose or deployment context changed?

Provider Readiness

Future provider requirements include:

  • risk-management system;
  • data and data-governance controls;
  • technical documentation;
  • automatic record-keeping and logs;
  • information and instructions for deployers;
  • human-oversight design;
  • accuracy, robustness, and cybersecurity;
  • quality-management system;
  • conformity assessment;
  • EU database registration;
  • corrective action;
  • post-market monitoring;
  • serious-incident reporting.

Deployer Readiness

Future deployer obligations include:

  • following the provider’s instructions;
  • assigning competent and empowered human oversight;
  • ensuring relevant and sufficiently representative input data when the deployer controls it;
  • monitoring operation;
  • retaining logs under the applicable conditions;
  • reporting risks and serious incidents;
  • workplace notices for affected employees and worker representatives;
  • notices to people affected by decisions in relevant circumstances;
  • public-authority registration duties;
  • fundamental-rights impact assessments for specified deployers and use cases.

Fundamental Rights Impact Assessment

The AI Act requires an FRIA for specified deployers of high-risk systems, including certain public bodies, public-service providers, and specified creditworthiness and insurance uses. The 2026 amendment permits cross-referencing relevant parts of a GDPR data-protection impact assessment to reduce duplication.[^3][^4]

Do Not Wait for 2027

Begin now because:

  • vendors may not provide the required information later;
  • logging may require architecture changes;
  • data-quality evidence may not exist retrospectively;
  • human oversight must be designed and tested;
  • conformity work can affect release planning;
  • procurement contracts may need renegotiation;
  • high-risk status may affect whether a product remains viable.

Checklist 8: Strengthen Vendor and AI Supply-Chain Controls

Third-party AI does not outsource your compliance risk.

Supplier Due-Diligence Questions

Ask the vendor to provide:

  • legal role under the AI Act;
  • model and system description;
  • intended purpose;
  • supported and prohibited uses;
  • EU market status;
  • risk classification;
  • Article 50 compliance information;
  • machine-readable marking capabilities;
  • GPAI provider information;
  • training-content summary where applicable;
  • copyright policy information;
  • authorised representative;
  • technical documentation available to downstream providers;
  • model limitations and failure modes;
  • human-oversight guidance;
  • logging and export capability;
  • security architecture;
  • incident-notification process;
  • model-update policy;
  • sub-provider and hosting locations;
  • deletion and retention settings;
  • evidence of conformity when future high-risk duties apply.

Contractual Clauses

Address:

  • role allocation;
  • permitted purpose;
  • change notification;
  • model version changes;
  • transparency and marking;
  • documentation delivery;
  • audit rights;
  • regulatory cooperation;
  • serious incidents;
  • security incidents;
  • service suspension;
  • data use and training;
  • IP and copyright;
  • subcontractors;
  • retention and deletion;
  • exit and portability;
  • indemnity and liability.

For high-risk AI supply chains, the AI Act requires written agreements concerning necessary information, technical access, capabilities, and assistance under the conditions of Article 25. The detailed timing follows the postponed high-risk framework, but organisations should prepare the contractual foundation now.[^3]

Vendor Monitoring

Do not make due diligence a one-time questionnaire.

Monitor:

  • new model releases;
  • changed terms;
  • changed training-data practices;
  • new sub-processors;
  • changes to content marking;
  • security events;
  • regulatory findings;
  • discontinued features;
  • geographic availability;
  • changes in intended purpose or limitations.

Checklist 9: Align the AI Act With GDPR and Fundamental Rights

The Digital Omnibus confirms that EU privacy and data-protection law continues to apply to personal data processed in connection with AI Act rights and obligations. AI Act compliance does not replace GDPR compliance.[^3]

Data-Protection Checklist

  • Identify personal-data processing.
  • Establish a GDPR legal basis.
  • Assess special-category and biometric data.
  • Provide privacy notices.
  • Apply data minimisation.
  • Define retention and deletion.
  • Control international transfers.
  • Assess automated decision-making rules.
  • Conduct a DPIA where required.
  • Address data-subject rights.
  • Implement security controls.
  • Review processor and controller roles.
  • Coordinate DPIA and future FRIA work.

Fundamental-Rights Review

Assess potential effects involving:

  • non-discrimination;
  • privacy and data protection;
  • freedom of expression;
  • workers’ rights;
  • access to services;
  • consumer rights;
  • children;
  • persons with disabilities;
  • due process;
  • human dignity;
  • democratic participation.

Record affected groups, foreseeable harms, controls, monitoring indicators, complaints, and remediation.


Checklist 10: Create Technical and Compliance Evidence

A policy stating “we use responsible AI” is not enough.

Evidence by Lifecycle Stage

Design

  • intended-purpose statement;
  • role and risk classification;
  • affected-person analysis;
  • requirements;
  • prohibited-use screening;
  • data-source record;
  • architecture;
  • human-oversight design.

Development

  • model and version;
  • training or configuration data;
  • prompts and guardrails;
  • evaluation datasets;
  • test results;
  • bias and subgroup testing;
  • security testing;
  • known limitations.

Release

  • approval;
  • user instructions;
  • transparency notices;
  • machine-readable marking;
  • monitoring plan;
  • rollback plan;
  • vendor evidence;
  • training completion.

Operation

  • system logs;
  • model changes;
  • output review;
  • complaints;
  • errors;
  • overrides;
  • incidents;
  • monitoring reports;
  • periodic reassessment.

Retirement

  • deactivation;
  • user notification;
  • data retention or deletion;
  • record preservation;
  • replacement-system review.

Evidence Quality Principles

Evidence should be:

  • dated;
  • versioned;
  • attributable to an owner;
  • linked to the system;
  • reproducible where possible;
  • protected against unauthorised alteration;
  • retained for the required period;
  • accessible to authorised reviewers.

Checklist 11: Establish Monitoring and Incident Response

AI behaviour can change because of model updates, data drift, integration changes, user behaviour, or attacks.

Monitoring Areas

Track:

  • performance against intended purpose;
  • error and failure rates;
  • harmful or discriminatory outcomes;
  • human overrides;
  • user complaints;
  • refusal behaviour;
  • prohibited-content attempts;
  • transparency failures;
  • missing content markers;
  • unauthorised use;
  • security events;
  • vendor changes;
  • data drift;
  • affected-group outcomes;
  • latency or availability where safety-relevant.

AI Incident Procedure

Define:

  1. how an event is reported;
  2. severity levels;
  3. who investigates;
  4. when a system is suspended;
  5. evidence preservation;
  6. affected-person response;
  7. vendor escalation;
  8. regulator notification;
  9. serious-incident analysis;
  10. corrective and preventive action;
  11. lessons learned;
  12. governance reporting.

GPAI Serious Incidents

Providers of GPAI models with systemic risk need a process for reporting serious incidents to the AI Office under the applicable rules.

High-Risk Serious Incidents

Provider and deployer procedures should be ready before the postponed high-risk dates. Contracts must allow deployers to notify providers and providers to investigate and report.


Checklist 12: Prepare for Regulators and Enforcement

The AI Act uses a two-tier structure:

  • national competent authorities oversee and enforce rules for AI systems;
  • the European AI Office governs and enforces GPAI provider duties and certain systems within its competence.

Regulatory Response File

Prepare:

  • organisation and contact details;
  • AI inventory;
  • legal-role analysis;
  • risk classifications;
  • prohibited-practice screening;
  • Article 50 evidence;
  • AI-literacy programme;
  • GPAI documentation where applicable;
  • vendor contracts;
  • monitoring reports;
  • complaints and incident records;
  • corrective actions;
  • internal audit results;
  • board reporting.

Regulatory Response Process

  • Designate a response owner.
  • Verify authority and scope of request.
  • Preserve relevant records.
  • Coordinate legal, security, privacy, and technical teams.
  • Supply accurate and complete information.
  • Track deadlines.
  • Maintain privilege where legally applicable.
  • Correct known inaccuracies promptly.
  • Record all submissions and decisions.

The supply of incorrect, incomplete, or misleading information can itself trigger penalties.


A 30-Day Remediation Plan

Because the August 2026 milestone has already arrived, organisations with gaps should use a risk-prioritised remediation plan.

Days 1–5: Contain Immediate Risk

  • Appoint an executive owner.
  • Create an emergency AI inventory.
  • Suspend suspected prohibited practices.
  • Identify public-facing chatbots and generative-content systems.
  • Identify whether the organisation provides a GPAI model.
  • Escalate high-impact uncertainties to counsel.

Days 6–10: Fix Article 50 Gaps

  • Add AI interaction notices.
  • add deepfake and public-interest content disclosure.
  • confirm emotion-recognition and biometric notices.
  • assess machine-readable marking.
  • identify systems eligible for the December 2, 2026 transition.
  • decide whether to sign the Transparency Code of Practice.

Days 11–15: Address GPAI and Vendors

  • complete GPAI provider classification;
  • gather technical documentation;
  • review copyright policies;
  • publish or prepare training summaries;
  • review systemic risk;
  • send vendor evidence requests;
  • identify contract gaps.

Days 16–20: AI Literacy

  • issue a minimum mandatory training module;
  • add role-specific sessions;
  • brief executives;
  • train content, HR, procurement, product, and security teams;
  • record attendance and materials.

Days 21–25: Evidence and Monitoring

  • create system compliance files;
  • preserve transparency screenshots and tests;
  • establish incident reporting;
  • create monitoring indicators;
  • define change control.

Days 26–30: Independent Review

  • conduct a legal and control gap review;
  • test a sample of AI systems;
  • report residual risk to executives;
  • approve a funded roadmap for high-risk readiness;
  • schedule quarterly reassessment.

This plan is a practical prioritisation framework, not an official grace period.


EU AI Act Compliance Evidence Checklist

A mature organisation should be able to produce the following evidence without an extensive reconstruction exercise.

Governance

  • AI policy
  • accountability matrix
  • committee minutes
  • risk appetite
  • escalation process
  • internal audit plan

Inventory and Classification

  • complete inventory
  • AI-system definition analysis
  • role classification
  • Article 5 screening
  • Article 50 classification
  • GPAI classification
  • high-risk assessment
  • legal exceptions

AI Literacy

  • needs assessment
  • training materials
  • attendance
  • role-specific modules
  • refreshers
  • effectiveness review

Transparency

  • chatbot notices
  • deepfake labels
  • public-interest text disclosures
  • emotion and biometric notices
  • machine-readable marking specification
  • detection testing
  • Code of Practice decision

GPAI

  • technical documentation
  • downstream information
  • copyright policy
  • training-content summary
  • authorised representative
  • systemic-risk assessment
  • evaluation and mitigation records
  • incident reporting
  • cybersecurity framework

Privacy and Rights

  • privacy assessment
  • DPIA
  • legal basis
  • notices
  • retention
  • data rights process
  • fundamental-rights analysis

Operations

  • monitoring plan
  • incident records
  • complaints
  • overrides
  • model changes
  • vendor changes
  • corrective actions
  • retirement records

Common Compliance Mistakes

Mistake 1: Believing All Requirements Were Delayed

Only most high-risk requirements were postponed. Article 50, GPAI enforcement, AI literacy, and existing prohibited-practice rules still matter in August 2026.

Mistake 2: Treating Every AI Tool as Minimal Risk

A familiar SaaS feature can be high-risk or subject to transparency duties because of its intended use.

Mistake 3: Assuming the Vendor Is Solely Responsible

A customer can be a deployer or become a provider through branding, integration, intended-purpose changes, or substantial modification.

Mistake 4: Using a Spreadsheet Without Evidence

An inventory is not compliance unless each entry links to classification, controls, tests, notices, and ownership.

Mistake 5: Giving Everyone the Same AI Training

Article 4 is contextual. Product engineers, HR staff, content teams, procurement teams, and executives need different knowledge.

Mistake 6: Hiding AI Disclosure in a Privacy Policy

Article 50 duties require operational transparency. A general legal notice may not adequately inform a person at the relevant interaction or exposure.

Mistake 7: Calling Ordinary Metadata a Machine-Readable Mark

The organisation must assess whether its solution meets the legal requirement and Commission guidance for effective, interoperable, robust, and reliable detection as far as technically feasible.

Mistake 8: Assuming Human Review Automatically Solves Everything

Human review must be real, competent, and documented. It does not automatically remove other provider, deployer, privacy, or safety obligations.

Mistake 9: Ignoring Model Updates

A vendor model change can alter performance, risk, transparency, or classification.

Mistake 10: Waiting Until 2027 for High-Risk Work

The postponed dates are implementation deadlines, not recommended project start dates.


EU AI Act Penalties

Member States must establish effective, proportionate, and dissuasive penalties. The Regulation sets maximum thresholds, and the final amount depends on the infringement and relevant circumstances.

The Commission summarises the thresholds as follows:[^4]

Infringement Maximum Threshold
Prohibited practices or specified non-compliance with data requirements Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, subject to the Regulation’s company-size rules
Other AI Act requirements or obligations Up to €15 million or 3% of total worldwide annual turnover
Incorrect, incomplete, or misleading information supplied to notified bodies or national authorities Up to €7.5 million or 1% of total worldwide annual turnover
GPAI provider non-compliance enforced by the Commission Up to €15 million or 3% of total worldwide annual turnover

For SMEs, the applicable maximum for each category is generally the lower of the fixed amount and percentage. The Digital Omnibus also added proportionality provisions for small mid-cap enterprises in specified penalty categories.[^3][^4]

Penalties are not the only risk. Organisations may face corrective orders, system withdrawal, market restrictions, contractual disputes, reputational damage, employment claims, consumer claims, privacy enforcement, or sector-specific action.


Frequently Asked Questions

Is the August 2026 EU AI Act deadline still valid?

Yes. The general application date was August 2, 2026. The Digital Omnibus postponed most high-risk system requirements, but Article 50 transparency requirements, GPAI enforcement, AI literacy, and existing prohibited-practice rules were not generally postponed.

Do high-risk AI requirements apply in August 2026?

Most requirements in Chapter III Sections 1, 2, and 3 were postponed. Annex III high-risk rules are scheduled for December 2, 2027, while high-risk AI integrated into products under Annex I is scheduled for August 2, 2028.

Must a chatbot say it is AI?

Providers of systems directly interacting with people must design them so people are informed that they are interacting with AI when Article 50 applies, subject to exceptions in the Regulation and Commission guidance.

Is watermarking AI-generated content mandatory?

Article 50(2) requires providers of relevant systems to mark synthetic outputs in a machine-readable format and make them detectable as artificially generated or manipulated, subject to technical feasibility and legal exceptions. The law is broader and more technical than merely adding a visible watermark.

Must deepfakes be labelled?

Deployers must disclose that qualifying deepfake content was artificially generated or manipulated, subject to applicable exceptions and tailored disclosure rules.

Does AI-generated text require a label?

It can. Deployers must disclose specified AI-generated or manipulated text published to inform the public on matters of public interest unless an exception applies, including the human-review and editorial-responsibility conditions in Article 50.

Is the Transparency Code of Practice mandatory?

No. It is voluntary. The Commission and AI Board assessed it as an adequate means to facilitate compliance. A non-signatory remains responsible for proving compliance through alternative adequate measures.

Does the AI Act apply to companies outside the EU?

It can. The rules apply to relevant actors outside the EU that place systems or GPAI models on the EU market, put systems into service or use them in the EU, or meet the Act’s output-related territorial scope.

Does using a third-party AI API make us a provider?

Not automatically. You may be a deployer, a downstream AI-system provider, or another operator depending on how you integrate, brand, modify, and use the service. Role classification must be performed for the specific system.

Is GDPR compliance enough?

No. GDPR and the AI Act apply alongside each other. An AI project may require both AI Act controls and GDPR measures such as a legal basis, transparency, data minimisation, security, rights handling, and a DPIA.

What is required for AI literacy?

Providers and deployers must take context-appropriate measures to support the development of AI literacy among staff and other persons operating or using AI systems on their behalf. The amended Article 4 does not impose one universal level for every person.

When can GPAI providers be fined?

The Commission’s enforcement powers for GPAI provider obligations apply from August 2, 2026. Models placed on the market before August 2, 2025 have a transition until August 2, 2027.

Are small companies exempt?

No general small-business exemption removes all AI Act duties. The Regulation includes proportionality, support, simplified pathways, and penalty rules for SMEs and certain small mid-cap enterprises, but obligations can still apply.


Final Readiness Test

Score each statement:

  • 0: Not started
  • 1: Identified
  • 2: Control designed
  • 3: Implemented
  • 4: Tested and evidenced
Readiness Area Score 0–4
Executive accountability
AI inventory
Legal-role mapping
Prohibited-practice screening
AI literacy
Article 50 interaction notices
Synthetic-content marking
Deepfake and public-interest labels
GPAI provider compliance
Vendor due diligence
Privacy and fundamental-rights review
High-risk classification
Documentation and records
Monitoring and incidents
Regulatory response

Interpreting the Score

  • 50–60: Strong programme; focus on independent testing and changing guidance.
  • 35–49: Material controls exist, but evidence or coverage is incomplete.
  • 20–34: Significant compliance gaps; prioritised remediation is needed.
  • Below 20: Immediate executive intervention is advisable.

This scoring model is an internal management tool, not an official EU assessment.


Conclusion

The key August 2026 compliance question is not whether every AI system has become high-risk.

It is whether your organisation can demonstrate that it:

  • knows where AI is used;
  • understands its legal roles;
  • has stopped prohibited practices;
  • supports AI literacy;
  • meets Article 50 transparency duties;
  • complies with GPAI obligations where applicable;
  • controls vendors and downstream integrations;
  • respects privacy and fundamental rights;
  • records decisions and evidence;
  • monitors systems after release; and
  • has a funded roadmap for the postponed high-risk requirements.

The Digital Omnibus gave organisations more time for high-risk-system compliance. It did not create a general pause.

As of August 4, 2026, the most defensible approach is to close immediate transparency, GPAI, literacy, and prohibited-use gaps while using the extended high-risk timeline to build controls that are technically real, contractually supported, and auditable.


Official Sources

[^1]: EUR-Lex, Regulation (EU) 2024/1689—the Artificial Intelligence Act.

[^2]: European Commission, Navigating the AI Act, updated July 27, 2026.

[^3]: EUR-Lex, Regulation (EU) 2026/1744—the Digital Omnibus on AI, in force from July 27, 2026.

[^4]: European Commission, Navigating the AI Act: scope, high-risk obligations, governance, and penalties.

[^5]: European Commission, Guidelines on prohibited artificial-intelligence practices.

[^6]: European Commission, AI Literacy—Questions and Answers.

[^7]: European Commission, Repository of AI literacy practices.

[^8]: European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, July 20, 2026.

[^9]: European Commission, Opinion on the Code of Practice on Transparency of AI-Generated Content, July 9, 2026.

[^10]: European Commission, Guidelines for providers of general-purpose AI models.

[^11]: European Commission, Guidelines on obligations for General-Purpose AI providers—Q&A.

[^12]: European Commission, Guidelines for providers and deployers of AI high-risk systems.

Likhon - Gen AI Specialist

Senior Cloud and AI Engineer

Generative AI expert with 6+ years experience and 300+ certifications. Building LLM, RAG systems, and multi-cloud AI solutions.