EU AI Act Compliance Checklist: Are You Ready for August 2026?
Updated August 4, 2026: The main August 2026 milestone has arrived. Article 50 transparency requirements now apply, the European Commission can enforce the general-purpose AI model rules, and supervision of the AI-literacy obligation is active. However, a July 2026 amendment postponed most high-risk AI system requirements to December 2027 or August 2028.
The European Union’s Artificial Intelligence Act is no longer a distant compliance project.
The Regulation entered into force on August 1, 2024, and its obligations have been introduced in stages. Prohibited AI practices and AI-literacy requirements began applying in February 2025. General-purpose AI model obligations began applying in August 2025. On August 2, 2026, the Regulation’s general application date arrived, including the transparency duties in Article 50 and enforcement powers for general-purpose AI obligations.[^1][^2]
A last-minute legal change is essential to understand. Regulation (EU) 2026/1744—the Digital Omnibus on AI—entered into force on July 27, 2026. It delayed most requirements for high-risk AI systems:
- Annex III high-risk systems: December 2, 2027
- High-risk AI embedded in regulated products under Annex I: August 2, 2028
The amendment did not cancel the August 2026 milestone. Businesses still need to address AI transparency, AI literacy, prohibited uses, general-purpose AI rules, governance, vendor accountability, and regulatory evidence now.[^3]
This guide provides an end-to-end EU AI Act compliance checklist for providers, deployers, importers, distributors, product teams, public bodies, and companies using third-party AI services.
Legal notice: This article is general compliance information, not legal advice. The AI Act must be assessed alongside applicable national law, the GDPR, sector-specific legislation, employment law, consumer-protection rules, intellectual-property law, and contractual obligations.
Table of Contents
- EU AI Act Compliance in August 2026: The Quick Answer
- The Current EU AI Act Timeline
- Who Must Comply With the EU AI Act?
- Understand Your Role: Provider, Deployer, or Other Operator
- The EU AI Act Risk Framework
- The Complete EU AI Act Compliance Checklist
- Checklist 1: Establish AI Governance and Accountability
- Checklist 2: Build a Complete AI System Inventory
- Checklist 3: Identify and Stop Prohibited AI Practices
- Checklist 4: Implement AI Literacy Measures
- Checklist 5: Meet Article 50 Transparency Requirements
- Checklist 6: Comply With General-Purpose AI Obligations
- Checklist 7: Prepare for High-Risk AI Requirements
- Checklist 8: Strengthen Vendor and AI Supply-Chain Controls
- Checklist 9: Align the AI Act With GDPR and Fundamental Rights
- Checklist 10: Create Technical and Compliance Evidence
- Checklist 11: Establish Monitoring and Incident Response
- Checklist 12: Prepare for Regulators and Enforcement
- A 30-Day Remediation Plan
- EU AI Act Compliance Evidence Checklist
- Common Compliance Mistakes
- EU AI Act Penalties
- Frequently Asked Questions
- Final Readiness Test
- Official Sources
EU AI Act Compliance in August 2026: The Quick Answer
As of August 4, 2026, an organisation should be able to answer yes to the following questions:
- Do we know which AI systems and general-purpose AI models we provide, deploy, import, distribute, or integrate?
- Have we confirmed that none of our current uses fall within the prohibited-practice rules?
- Have we implemented context-appropriate AI-literacy measures for staff and others operating AI systems on our behalf?
- Do our chatbots and other directly interactive AI systems inform people that they are interacting with AI where Article 50 requires it?
- Can our generative AI systems mark synthetic outputs in a machine-readable and detectable form where required?
- Do we visibly disclose deepfakes and relevant AI-generated public-interest text where required?
- If we provide a general-purpose AI model, can we demonstrate compliance with the documentation, downstream-information, copyright, and training-summary duties?
- Do we have a plan for general-purpose AI models with systemic risk?
- Have we classified likely high-risk AI systems, even though most high-risk duties were postponed?
- Can we produce evidence showing how our controls work?
- Can we respond to a regulator, affected person, customer, or auditor without reconstructing our AI estate from scratch?
A “no” answer does not always mean the same legal exposure. Obligations vary by the organisation’s role, the system’s intended purpose, the people affected, and the type of AI involved. It does mean the organisation needs a documented remediation decision.
The Current EU AI Act Timeline
The timeline below reflects the AI Act as amended by Regulation (EU) 2026/1744.
| Date | What Applies |
|---|---|
| August 1, 2024 | Regulation (EU) 2024/1689 entered into force. |
| February 2, 2025 | The AI-system definition, initial prohibited-practice rules, and Article 4 AI-literacy obligation began applying. |
| August 2, 2025 | Governance provisions, penalties, and obligations for providers of general-purpose AI models began applying. |
| July 27, 2026 | Regulation (EU) 2026/1744 entered into force, amending the AI Act and postponing most high-risk requirements. |
| August 2, 2026 | The AI Act’s general application date; Article 50 transparency rules apply. The Commission’s enforcement powers for general-purpose AI obligations apply. |
| August 3, 2026 | According to the Commission’s AI-literacy Q&A, supervision and enforcement of Article 4 are active. |
| December 2, 2026 | New prohibitions concerning certain AI-generated non-consensual intimate material and child sexual abuse material apply. Providers of generative systems placed on the market before August 2, 2026 must meet the Article 50(2) machine-readable marking duty by this date. |
| August 2, 2027 | Providers of general-purpose AI models placed on the market before August 2, 2025 must comply with the applicable GPAI obligations. |
| December 2, 2027 | Most requirements and operator obligations for Annex III high-risk AI systems apply. |
| August 2, 2028 | Most requirements for AI systems classified as high-risk because they are regulated products or safety components under Annex I apply. |
The postponement of high-risk requirements is not a reason to stop preparing. Classification, data governance, procurement, system redesign, logging, human oversight, documentation, testing, and contractual access can require substantial lead time.
Who Must Comply With the EU AI Act?
The AI Act applies to public and private actors inside and outside the European Union when they:
- place an AI system or general-purpose AI model on the EU market;
- put an AI system into service in the EU;
- use an AI system in the EU; or
- are outside the EU but the output produced by the system is used in the EU, where the Regulation’s territorial conditions are met.
The Commission describes the framework as applying to actors inside and outside the EU that place AI systems or general-purpose AI models on the EU market, put systems into service, or use them in the EU.[^4]
The Act includes exclusions and special rules. For example, certain activities involving research, testing, or development before market release may fall outside its application, and systems exclusively used for military, defence, or national-security purposes are excluded under the conditions in the Regulation.
Do not assume that being headquartered outside Europe removes the obligation. A US, UK, Canadian, Indian, Singaporean, or other non-EU company may be in scope because it supplies an AI system to EU customers, operates an EU-facing service, or provides a model used in the European market.
Understand Your Role: Provider, Deployer, or Other Operator
Compliance begins with role classification.
Provider
A provider develops an AI system or general-purpose AI model—or has one developed—and places it on the market or puts it into service under its own name or trademark.
You may be a provider even when another vendor supplied the foundation model or core technology. A company that turns a third-party model into a branded recruitment, insurance, education, medical, or customer-service product may have provider obligations for the resulting AI system.
Deployer
A deployer uses an AI system under its authority, except for personal, non-professional use.
Examples include:
- an employer using an AI recruitment tool;
- a bank using an AI fraud or credit system;
- a retailer using a customer-service chatbot;
- a public authority using an eligibility or case-management system;
- a publisher using generative AI to produce public-interest content.
Importer and Distributor
Importers and distributors have supply-chain obligations, including checking relevant provider documentation and responding appropriately when they identify non-compliance.
Authorised Representative
A provider established outside the EU may need an authorised representative in the Union, particularly for general-purpose AI model obligations and other relevant provider duties.
Product Manufacturer or Downstream Integrator
A business incorporating AI into its own product can acquire provider responsibilities. Rebranding, changing intended purpose, or substantially modifying an AI system may also change the responsible legal role.
Why Role Mapping Matters
The same technology can create different obligations for different organisations.
A model developer may be a GPAI provider. A software company integrating that model may be an AI-system provider. A corporation buying the software may be a deployer. A cloud marketplace may also have distribution or intermediary responsibilities.
Record the legal role for every system, not only for the organisation as a whole.
The EU AI Act Risk Framework
The AI Act uses a risk-based structure.
1. Prohibited Practices
A limited set of AI uses is prohibited because of unacceptable risks to fundamental rights, safety, and EU values.
2. High-Risk AI Systems
High-risk systems include certain systems listed in Annex III and AI systems that are regulated products or safety components under specified EU product legislation.
Annex III areas include certain uses involving:
- biometrics;
- critical infrastructure;
- education and vocational training;
- employment and worker management;
- access to essential public or private services;
- law enforcement;
- migration, asylum, and border control;
- administration of justice and democratic processes.
Most detailed high-risk requirements are now scheduled for December 2027 or August 2028.
3. Transparency-Risk Systems
Article 50 applies to specified interactive and generative AI uses, including:
- AI systems directly interacting with individuals;
- systems generating or manipulating synthetic content;
- emotion-recognition and biometric-categorisation systems;
- deepfakes;
- certain AI-generated text published to inform the public on matters of public interest.
These rules apply from August 2, 2026, subject to the legal exceptions and the limited transitional rule created by the Digital Omnibus.
4. Minimal or No Additional AI Act Risk
Most AI systems do not fall into the prohibited, high-risk, or specific transparency categories. They may still be governed by other laws and by the generally applicable AI-literacy duty.
5. General-Purpose AI Models
General-purpose AI models are regulated separately. All GPAI providers have transparency and copyright-related obligations, while providers of models with systemic risk have additional safety, evaluation, incident, and cybersecurity duties.
The Complete EU AI Act Compliance Checklist
Use the following status labels:
- Complete: Implemented, tested, and evidenced
- In progress: Owner and delivery date assigned
- Gap: No adequate control
- Not applicable: Legal basis documented
- Needs legal review: Classification or exception is uncertain
Checklist 1: Establish AI Governance and Accountability
1. Appoint an Accountable Executive
Assign an executive who owns AI Act readiness across legal, compliance, product, engineering, security, privacy, procurement, HR, communications, and internal audit.
Evidence to retain:
- board or executive mandate;
- responsibility matrix;
- reporting cadence;
- approved budget;
- escalation path.
2. Create a Cross-Functional AI Governance Committee
The committee should include relevant leaders from:
- legal and regulatory compliance;
- privacy and data protection;
- information security;
- enterprise risk;
- product management;
- engineering and machine learning;
- procurement and vendor management;
- HR and learning;
- communications or content operations;
- internal audit.
A committee without decision rights is not a control. Define who may approve, restrict, suspend, or retire an AI use.
3. Adopt an AI Governance Policy
The policy should establish:
- permitted and prohibited uses;
- required intake and approval;
- role classification;
- risk classification;
- vendor review;
- human-oversight expectations;
- documentation requirements;
- transparency and labelling;
- incident reporting;
- monitoring;
- staff responsibilities;
- exceptions and escalation.
4. Integrate AI Into Existing Risk Management
Connect AI governance with:
- enterprise risk management;
- privacy impact assessments;
- information-security reviews;
- product safety;
- model risk management;
- procurement;
- outsourcing;
- records management;
- complaints;
- internal audit.
Avoid building an isolated AI compliance process that duplicates controls but does not influence deployment decisions.
5. Define an AI Change-Control Process
Require reassessment when there is a material change to:
- model or model version;
- intended purpose;
- target users;
- affected population;
- training or reference data;
- prompt and system instructions;
- automated decision logic;
- human-oversight design;
- vendor;
- deployment region;
- output channel;
- integration or tool access.
Checklist 2: Build a Complete AI System Inventory
An AI inventory is the foundation of defensible compliance.
Minimum Inventory Fields
| Field | What to Record |
|---|---|
| System name | Internal and vendor names |
| Business owner | Accountable operational owner |
| Technical owner | Engineering or IT owner |
| Vendor/model | Provider, model, version, service |
| Intended purpose | The purpose approved by the organisation |
| Actual uses | How teams currently use the system |
| Users | Staff, contractors, customers, public |
| Affected persons | People whose rights, access, employment, credit, education, or services may be affected |
| Input data | Personal, confidential, biometric, copyrighted, public |
| Output | Decision, recommendation, ranking, content, prediction |
| Automation level | Advisory, human-approved, automated |
| Legal role | Provider, deployer, importer, distributor, integrator |
| Risk category | Prohibited, high-risk candidate, Article 50, GPAI, other |
| Geography | EU countries and non-EU markets |
| Transparency method | Notice, label, watermark, machine-readable mark |
| Human oversight | Assigned persons and intervention rights |
| Logging | Inputs, outputs, decisions, version, timestamp |
| Status | Pilot, production, suspended, retired |
| Review date | Last and next assessment |
Find Shadow AI
Inventory work must include unsanctioned or decentralised use, such as:
- staff using public generative AI accounts;
- browser extensions;
- AI meeting assistants;
- marketing content tools;
- recruitment add-ons;
- customer-support copilots;
- code-generation tools;
- AI features activated inside existing SaaS products;
- automated scoring created by analytics teams;
- third-party agents connected to company systems.
Use surveys, procurement records, SSO logs, expense data, SaaS discovery, network telemetry, data-loss prevention alerts, and interviews.
Link Systems to Evidence
Each inventory record should link to:
- classification assessment;
- vendor contract;
- privacy assessment;
- security review;
- transparency design;
- AI-literacy requirements;
- testing results;
- monitoring plan;
- incident history;
- approval record.
Checklist 3: Identify and Stop Prohibited AI Practices
Most prohibited-practice rules have applied since February 2, 2025.
The Commission’s current summary includes prohibitions involving:
- harmful manipulation, deception, or subliminal techniques under the legal conditions in Article 5;
- exploitation of vulnerabilities linked to age, disability, or particular social or economic situations;
- social scoring that leads to prohibited detrimental or unfavourable treatment;
- individual criminal-risk prediction based solely on profiling or personality traits, subject to the Regulation’s limited distinction for supporting human assessments based on objective facts;
- untargeted scraping of facial images from the internet or CCTV to create or expand facial-recognition databases;
- emotion inference in workplaces and educational institutions, except for specified medical or safety purposes;
- biometric categorisation to infer protected or sensitive characteristics under Article 5;
- real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, except under narrow legally controlled circumstances.[^5]
Regulation (EU) 2026/1744 added prohibitions involving AI systems intended for—or lacking adequate safeguards against certain reasonably foreseeable generation of—non-consensual intimate material and child sexual abuse material. Those additions apply from December 2, 2026.[^3]
Prohibited-Practice Action List
- Screen every AI use against Article 5.
- Suspend any potentially prohibited system pending legal review.
- Check whether employee-monitoring tools infer emotion.
- Review biometric products and datasets.
- Review public-space surveillance and law-enforcement-related use.
- Prohibit untargeted facial-image scraping.
- Review scoring systems for cross-context social scoring.
- Review behavioural design for manipulation or exploitation.
- Add controls against non-consensual intimate content and child sexual abuse material before December 2, 2026.
- Document any exception and the evidence supporting it.
- Add prohibited-use clauses to vendor and employee policies.
- Create a reporting channel for suspected prohibited uses.
Evidence
Retain:
- screening questionnaire;
- legal analysis;
- product test results;
- safeguards;
- misuse testing;
- content-safety controls;
- suspension or remediation decisions;
- executive approval for any reliance on an exception.
Checklist 4: Implement AI Literacy Measures
Article 4 applies to providers and deployers of AI systems.
Following the July 2026 amendment, providers and deployers must take measures to support the development of AI literacy among staff and other people dealing with AI-system operation or use on their behalf. The measures should take account of technical knowledge, experience, education, training, context of use, and the people or groups affected. The amendment does not mandate a single “sufficient” literacy level for every person.[^3][^6]
The Commission states that Article 4 has applied since February 2, 2025 and that its supervision and enforcement rules apply from August 3, 2026.[^6]
Build Role-Based Training
All Staff
Cover:
- what AI is and is not;
- approved tools;
- confidential and personal data;
- hallucinations and verification;
- copyright and attribution;
- security threats;
- prohibited uses;
- reporting concerns.
AI Product and Engineering Teams
Cover:
- AI Act roles and classification;
- intended purpose;
- evaluation and testing;
- data governance;
- robustness and cybersecurity;
- technical documentation;
- transparency;
- human oversight;
- logging;
- change control.
HR and Recruitment
Cover:
- employment-related high-risk use cases;
- discrimination;
- workplace notices;
- human review;
- vendor claims;
- candidate rights;
- prohibited emotion inference.
Marketing, Media, and Communications
Cover:
- AI-generated content disclosure;
- deepfake labelling;
- public-interest text;
- machine-readable marking;
- review and editorial responsibility;
- brand and consumer-protection risks.
Procurement and Legal
Cover:
- role allocation;
- supplier evidence;
- audit and access rights;
- model changes;
- sub-processors;
- geography;
- incident notifications;
- termination and migration.
Executives and Board Members
Cover:
- legal timeline;
- accountability;
- risk appetite;
- enforcement;
- resource decisions;
- material incidents;
- reporting.
AI Literacy Evidence Checklist
- Training-needs assessment
- Role-based curriculum
- Attendance and completion records
- Training materials and versions
- Scenario exercises
- Knowledge checks where appropriate
- Refresher schedule
- Contractor coverage
- New-hire onboarding
- Lessons learned from incidents
- Board and executive briefings
The Commission maintains a repository of AI-literacy practices. It is a useful source of examples, but copying a listed practice does not automatically create a presumption of compliance.[^7]
Checklist 5: Meet Article 50 Transparency Requirements
Article 50 is one of the most important August 2026 obligations.
The Commission published final transparency guidelines on July 20, 2026. It also assessed the voluntary Code of Practice on Transparency of AI-Generated Content as an adequate instrument for facilitating compliance with Article 50(2), (4), and (5). Adherence is useful evidence but is not conclusive proof of compliance.[^8][^9]
A. AI Systems That Interact Directly With People
Providers must design relevant systems so that individuals are informed that they are interacting with AI, unless a legal exception applies.
Examples may include:
- customer-service chatbots;
- virtual assistants;
- AI interviewers;
- voice bots;
- interactive avatars;
- conversational sales systems.
Checklist:
- Display or communicate the AI notice clearly.
- Do not bury it in general terms and conditions.
- Test the notice across web, mobile, telephone, and accessibility modes.
- Preserve evidence of the notice presented.
- Document any conclusion that the AI nature is obvious or an exception applies.
- Ensure local-language notices where required for meaningful communication.
B. Machine-Readable Marking of Synthetic Content
Providers of AI systems generating or manipulating synthetic audio, image, video, or text content must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to technical feasibility and the legal exceptions.
The obligation does not apply to the extent that a system merely performs standard assistive editing or does not substantially alter the input or its meaning, as specified in Article 50 and the Commission guidance.
Checklist:
- Identify all systems capable of generating or substantially manipulating content.
- Implement machine-readable provenance or marking.
- Test whether the marker survives normal export and distribution workflows.
- Document supported formats and known limitations.
- Prevent downstream product features from stripping required markers where reasonably controllable.
- Maintain versioned technical evidence.
- Review the Transparency Code of Practice.
- Document alternative adequate compliance measures if not signing the Code.
Transitional Rule for Existing Systems
Providers of relevant generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to comply with Article 50(2). This is a targeted transitional rule for the machine-readable marking duty; it is not a general postponement of Article 50.[^3]
C. Emotion Recognition and Biometric Categorisation
Deployers must inform individuals exposed to emotion-recognition or biometric-categorisation systems where Article 50 applies.
Checklist:
- Confirm the system is lawful and not prohibited under Article 5.
- Provide clear notice to exposed individuals.
- Address GDPR and biometric-data rules separately.
- Document purpose, data, retention, access, and affected groups.
- Test whether individuals can understand the notice.
D. Deepfake Disclosure
Deployers using an AI system to create or manipulate image, audio, or video content constituting a deepfake must disclose that the content was artificially generated or manipulated, subject to the Act’s exceptions and tailored rules for artistic, creative, satirical, fictional, and analogous works.
Checklist:
- Define how deepfakes are detected internally.
- Apply a clear and perceivable disclosure.
- Preserve machine-readable marking where the provider duty applies.
- Review artistic and editorial exceptions with counsel.
- Include disclosure in syndicated and republished versions.
- Create approval controls for realistic depictions of people.
E. AI-Generated Public-Interest Text
Deployers must disclose artificially generated or manipulated text published to inform the public on matters of public interest, unless an applicable exception applies—for example, where there has been human review or editorial control and a person holds editorial responsibility under the conditions in Article 50.
Checklist:
- Identify public-interest content workflows.
- Define what constitutes meaningful human review.
- Assign editorial responsibility.
- Document the review and approval.
- Label content when the exception is not satisfied.
- Retain the generated draft, edits, reviewer, and publication record where proportionate.
Article 50 Evidence Pack
Create a package containing:
- applicability analysis;
- screenshots or recordings of AI notices;
- marker specifications;
- detection tests;
- sample labelled content;
- exception analyses;
- editorial-review procedures;
- supplier documentation;
- Code of Practice decision;
- user complaints and remediation.
Checklist 6: Comply With General-Purpose AI Obligations
The GPAI rules began applying on August 2, 2025. From August 2, 2026, the European Commission can enforce full compliance for models placed on the market after the applicable date.[^10]
Are You a GPAI Provider?
You may be a provider if you:
- develop a general-purpose model;
- place a model on the EU market;
- make a model available through an API or downloadable release;
- significantly modify a general-purpose model in a way that creates provider responsibilities;
- release a model under your name or trademark.
Using a third-party model does not automatically make you its GPAI provider, but you may be the provider of the downstream AI system.
Duties for GPAI Providers
The Commission summarises the core obligations as:
- drawing up and maintaining technical model documentation;
- giving downstream AI-system providers information needed to understand capabilities and limitations and comply with their own duties;
- implementing a policy to comply with EU copyright and related-rights law, including rights reservations;
- publishing a sufficiently detailed summary of the training content using the Commission template;
- appointing an authorised representative in the EU when required for providers established outside the Union.[^11]
Additional Duties for GPAI Models With Systemic Risk
Providers of GPAI models with systemic risk must address additional duties including:
- notification to the Commission;
- model evaluations;
- systemic-risk assessment and mitigation;
- serious-incident reporting;
- cybersecurity protection for the model and relevant infrastructure.
The Regulation uses a computational threshold that creates a presumption of systemic risk, while allowing Commission designation and reassessment under the legal criteria.
GPAI Compliance Checklist
- Determine whether the model is a GPAI model.
- Determine whether your organisation is the provider or has significantly modified the model.
- Assess open-source provisions and exceptions with counsel.
- Create technical documentation.
- Prepare downstream integration information.
- Adopt and operate an EU copyright-compliance policy.
- Publish the required training-content summary.
- Appoint an EU authorised representative where required.
- Evaluate systemic-risk status.
- Notify the AI Office when required.
- Establish model evaluation and systemic-risk processes.
- Establish serious-incident reporting.
- Protect models and infrastructure against cyber risks.
- Review the GPAI Code of Practice.
- Sign the Code or document alternative adequate compliance measures.
- Prepare submissions through the EU SEND platform where applicable.
Existing GPAI Models
Providers of GPAI models placed on the market before August 2, 2025 have until August 2, 2027 to meet the applicable obligations.[^1]
Checklist 7: Prepare for High-Risk AI Requirements
The Digital Omnibus postponed most high-risk duties, but it did not remove them.
Current Deadlines
- December 2, 2027: Annex III high-risk systems
- August 2, 2028: high-risk AI systems regulated as products or safety components under Annex I
The Commission’s high-risk classification materials were still being finalised during summer 2026. Use the Regulation, current Commission information, and legal advice, and track final guidance as it is adopted.[^12]
High-Risk Classification Questions
Ask:
- Is the AI a regulated product or a safety component of a product covered by Annex I?
- Is third-party conformity assessment required under the relevant product legislation?
- Is the intended purpose listed in Annex III?
- Does an Article 6 exception apply to an Annex III use because the system does not pose a significant risk of harm and does not materially influence decision-making?
- Does the system perform profiling, affecting the application of the high-risk classification rules?
- Has the intended purpose or deployment context changed?
Provider Readiness
Future provider requirements include:
- risk-management system;
- data and data-governance controls;
- technical documentation;
- automatic record-keeping and logs;
- information and instructions for deployers;
- human-oversight design;
- accuracy, robustness, and cybersecurity;
- quality-management system;
- conformity assessment;
- EU database registration;
- corrective action;
- post-market monitoring;
- serious-incident reporting.
Deployer Readiness
Future deployer obligations include:
- following the provider’s instructions;
- assigning competent and empowered human oversight;
- ensuring relevant and sufficiently representative input data when the deployer controls it;
- monitoring operation;
- retaining logs under the applicable conditions;
- reporting risks and serious incidents;
- workplace notices for affected employees and worker representatives;
- notices to people affected by decisions in relevant circumstances;
- public-authority registration duties;
- fundamental-rights impact assessments for specified deployers and use cases.
Fundamental Rights Impact Assessment
The AI Act requires an FRIA for specified deployers of high-risk systems, including certain public bodies, public-service providers, and specified creditworthiness and insurance uses. The 2026 amendment permits cross-referencing relevant parts of a GDPR data-protection impact assessment to reduce duplication.[^3][^4]
Do Not Wait for 2027
Begin now because:
- vendors may not provide the required information later;
- logging may require architecture changes;
- data-quality evidence may not exist retrospectively;
- human oversight must be designed and tested;
- conformity work can affect release planning;
- procurement contracts may need renegotiation;
- high-risk status may affect whether a product remains viable.
Checklist 8: Strengthen Vendor and AI Supply-Chain Controls
Third-party AI does not outsource your compliance risk.
Supplier Due-Diligence Questions
Ask the vendor to provide:
- legal role under the AI Act;
- model and system description;
- intended purpose;
- supported and prohibited uses;
- EU market status;
- risk classification;
- Article 50 compliance information;
- machine-readable marking capabilities;
- GPAI provider information;
- training-content summary where applicable;
- copyright policy information;
- authorised representative;
- technical documentation available to downstream providers;
- model limitations and failure modes;
- human-oversight guidance;
- logging and export capability;
- security architecture;
- incident-notification process;
- model-update policy;
- sub-provider and hosting locations;
- deletion and retention settings;
- evidence of conformity when future high-risk duties apply.
Contractual Clauses
Address:
- role allocation;
- permitted purpose;
- change notification;
- model version changes;
- transparency and marking;
- documentation delivery;
- audit rights;
- regulatory cooperation;
- serious incidents;
- security incidents;
- service suspension;
- data use and training;
- IP and copyright;
- subcontractors;
- retention and deletion;
- exit and portability;
- indemnity and liability.
For high-risk AI supply chains, the AI Act requires written agreements concerning necessary information, technical access, capabilities, and assistance under the conditions of Article 25. The detailed timing follows the postponed high-risk framework, but organisations should prepare the contractual foundation now.[^3]
Vendor Monitoring
Do not make due diligence a one-time questionnaire.
Monitor:
- new model releases;
- changed terms;
- changed training-data practices;
- new sub-processors;
- changes to content marking;
- security events;
- regulatory findings;
- discontinued features;
- geographic availability;
- changes in intended purpose or limitations.
Checklist 9: Align the AI Act With GDPR and Fundamental Rights
The Digital Omnibus confirms that EU privacy and data-protection law continues to apply to personal data processed in connection with AI Act rights and obligations. AI Act compliance does not replace GDPR compliance.[^3]
Data-Protection Checklist
- Identify personal-data processing.
- Establish a GDPR legal basis.
- Assess special-category and biometric data.
- Provide privacy notices.
- Apply data minimisation.
- Define retention and deletion.
- Control international transfers.
- Assess automated decision-making rules.
- Conduct a DPIA where required.
- Address data-subject rights.
- Implement security controls.
- Review processor and controller roles.
- Coordinate DPIA and future FRIA work.
Fundamental-Rights Review
Assess potential effects involving:
- non-discrimination;
- privacy and data protection;
- freedom of expression;
- workers’ rights;
- access to services;
- consumer rights;
- children;
- persons with disabilities;
- due process;
- human dignity;
- democratic participation.
Record affected groups, foreseeable harms, controls, monitoring indicators, complaints, and remediation.
Checklist 10: Create Technical and Compliance Evidence
A policy stating “we use responsible AI” is not enough.
Evidence by Lifecycle Stage
Design
- intended-purpose statement;
- role and risk classification;
- affected-person analysis;
- requirements;
- prohibited-use screening;
- data-source record;
- architecture;
- human-oversight design.
Development
- model and version;
- training or configuration data;
- prompts and guardrails;
- evaluation datasets;
- test results;
- bias and subgroup testing;
- security testing;
- known limitations.
Release
- approval;
- user instructions;
- transparency notices;
- machine-readable marking;
- monitoring plan;
- rollback plan;
- vendor evidence;
- training completion.
Operation
- system logs;
- model changes;
- output review;
- complaints;
- errors;
- overrides;
- incidents;
- monitoring reports;
- periodic reassessment.
Retirement
- deactivation;
- user notification;
- data retention or deletion;
- record preservation;
- replacement-system review.
Evidence Quality Principles
Evidence should be:
- dated;
- versioned;
- attributable to an owner;
- linked to the system;
- reproducible where possible;
- protected against unauthorised alteration;
- retained for the required period;
- accessible to authorised reviewers.
Checklist 11: Establish Monitoring and Incident Response
AI behaviour can change because of model updates, data drift, integration changes, user behaviour, or attacks.
Monitoring Areas
Track:
- performance against intended purpose;
- error and failure rates;
- harmful or discriminatory outcomes;
- human overrides;
- user complaints;
- refusal behaviour;
- prohibited-content attempts;
- transparency failures;
- missing content markers;
- unauthorised use;
- security events;
- vendor changes;
- data drift;
- affected-group outcomes;
- latency or availability where safety-relevant.
AI Incident Procedure
Define:
- how an event is reported;
- severity levels;
- who investigates;
- when a system is suspended;
- evidence preservation;
- affected-person response;
- vendor escalation;
- regulator notification;
- serious-incident analysis;
- corrective and preventive action;
- lessons learned;
- governance reporting.
GPAI Serious Incidents
Providers of GPAI models with systemic risk need a process for reporting serious incidents to the AI Office under the applicable rules.
High-Risk Serious Incidents
Provider and deployer procedures should be ready before the postponed high-risk dates. Contracts must allow deployers to notify providers and providers to investigate and report.
Checklist 12: Prepare for Regulators and Enforcement
The AI Act uses a two-tier structure:
- national competent authorities oversee and enforce rules for AI systems;
- the European AI Office governs and enforces GPAI provider duties and certain systems within its competence.
Regulatory Response File
Prepare:
- organisation and contact details;
- AI inventory;
- legal-role analysis;
- risk classifications;
- prohibited-practice screening;
- Article 50 evidence;
- AI-literacy programme;
- GPAI documentation where applicable;
- vendor contracts;
- monitoring reports;
- complaints and incident records;
- corrective actions;
- internal audit results;
- board reporting.
Regulatory Response Process
- Designate a response owner.
- Verify authority and scope of request.
- Preserve relevant records.
- Coordinate legal, security, privacy, and technical teams.
- Supply accurate and complete information.
- Track deadlines.
- Maintain privilege where legally applicable.
- Correct known inaccuracies promptly.
- Record all submissions and decisions.
The supply of incorrect, incomplete, or misleading information can itself trigger penalties.
A 30-Day Remediation Plan
Because the August 2026 milestone has already arrived, organisations with gaps should use a risk-prioritised remediation plan.
Days 1–5: Contain Immediate Risk
- Appoint an executive owner.
- Create an emergency AI inventory.
- Suspend suspected prohibited practices.
- Identify public-facing chatbots and generative-content systems.
- Identify whether the organisation provides a GPAI model.
- Escalate high-impact uncertainties to counsel.
Days 6–10: Fix Article 50 Gaps
- Add AI interaction notices.
- add deepfake and public-interest content disclosure.
- confirm emotion-recognition and biometric notices.
- assess machine-readable marking.
- identify systems eligible for the December 2, 2026 transition.
- decide whether to sign the Transparency Code of Practice.
Days 11–15: Address GPAI and Vendors
- complete GPAI provider classification;
- gather technical documentation;
- review copyright policies;
- publish or prepare training summaries;
- review systemic risk;
- send vendor evidence requests;
- identify contract gaps.
Days 16–20: AI Literacy
- issue a minimum mandatory training module;
- add role-specific sessions;
- brief executives;
- train content, HR, procurement, product, and security teams;
- record attendance and materials.
Days 21–25: Evidence and Monitoring
- create system compliance files;
- preserve transparency screenshots and tests;
- establish incident reporting;
- create monitoring indicators;
- define change control.
Days 26–30: Independent Review
- conduct a legal and control gap review;
- test a sample of AI systems;
- report residual risk to executives;
- approve a funded roadmap for high-risk readiness;
- schedule quarterly reassessment.
This plan is a practical prioritisation framework, not an official grace period.
EU AI Act Compliance Evidence Checklist
A mature organisation should be able to produce the following evidence without an extensive reconstruction exercise.
Governance
- AI policy
- accountability matrix
- committee minutes
- risk appetite
- escalation process
- internal audit plan
Inventory and Classification
- complete inventory
- AI-system definition analysis
- role classification
- Article 5 screening
- Article 50 classification
- GPAI classification
- high-risk assessment
- legal exceptions
AI Literacy
- needs assessment
- training materials
- attendance
- role-specific modules
- refreshers
- effectiveness review
Transparency
- chatbot notices
- deepfake labels
- public-interest text disclosures
- emotion and biometric notices
- machine-readable marking specification
- detection testing
- Code of Practice decision
GPAI
- technical documentation
- downstream information
- copyright policy
- training-content summary
- authorised representative
- systemic-risk assessment
- evaluation and mitigation records
- incident reporting
- cybersecurity framework
Privacy and Rights
- privacy assessment
- DPIA
- legal basis
- notices
- retention
- data rights process
- fundamental-rights analysis
Operations
- monitoring plan
- incident records
- complaints
- overrides
- model changes
- vendor changes
- corrective actions
- retirement records
Common Compliance Mistakes
Mistake 1: Believing All Requirements Were Delayed
Only most high-risk requirements were postponed. Article 50, GPAI enforcement, AI literacy, and existing prohibited-practice rules still matter in August 2026.
Mistake 2: Treating Every AI Tool as Minimal Risk
A familiar SaaS feature can be high-risk or subject to transparency duties because of its intended use.
Mistake 3: Assuming the Vendor Is Solely Responsible
A customer can be a deployer or become a provider through branding, integration, intended-purpose changes, or substantial modification.
Mistake 4: Using a Spreadsheet Without Evidence
An inventory is not compliance unless each entry links to classification, controls, tests, notices, and ownership.
Mistake 5: Giving Everyone the Same AI Training
Article 4 is contextual. Product engineers, HR staff, content teams, procurement teams, and executives need different knowledge.
Mistake 6: Hiding AI Disclosure in a Privacy Policy
Article 50 duties require operational transparency. A general legal notice may not adequately inform a person at the relevant interaction or exposure.
Mistake 7: Calling Ordinary Metadata a Machine-Readable Mark
The organisation must assess whether its solution meets the legal requirement and Commission guidance for effective, interoperable, robust, and reliable detection as far as technically feasible.
Mistake 8: Assuming Human Review Automatically Solves Everything
Human review must be real, competent, and documented. It does not automatically remove other provider, deployer, privacy, or safety obligations.
Mistake 9: Ignoring Model Updates
A vendor model change can alter performance, risk, transparency, or classification.
Mistake 10: Waiting Until 2027 for High-Risk Work
The postponed dates are implementation deadlines, not recommended project start dates.
EU AI Act Penalties
Member States must establish effective, proportionate, and dissuasive penalties. The Regulation sets maximum thresholds, and the final amount depends on the infringement and relevant circumstances.
The Commission summarises the thresholds as follows:[^4]
| Infringement | Maximum Threshold |
|---|---|
| Prohibited practices or specified non-compliance with data requirements | Up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, subject to the Regulation’s company-size rules |
| Other AI Act requirements or obligations | Up to €15 million or 3% of total worldwide annual turnover |
| Incorrect, incomplete, or misleading information supplied to notified bodies or national authorities | Up to €7.5 million or 1% of total worldwide annual turnover |
| GPAI provider non-compliance enforced by the Commission | Up to €15 million or 3% of total worldwide annual turnover |
For SMEs, the applicable maximum for each category is generally the lower of the fixed amount and percentage. The Digital Omnibus also added proportionality provisions for small mid-cap enterprises in specified penalty categories.[^3][^4]
Penalties are not the only risk. Organisations may face corrective orders, system withdrawal, market restrictions, contractual disputes, reputational damage, employment claims, consumer claims, privacy enforcement, or sector-specific action.
Frequently Asked Questions
Is the August 2026 EU AI Act deadline still valid?
Yes. The general application date was August 2, 2026. The Digital Omnibus postponed most high-risk system requirements, but Article 50 transparency requirements, GPAI enforcement, AI literacy, and existing prohibited-practice rules were not generally postponed.
Do high-risk AI requirements apply in August 2026?
Most requirements in Chapter III Sections 1, 2, and 3 were postponed. Annex III high-risk rules are scheduled for December 2, 2027, while high-risk AI integrated into products under Annex I is scheduled for August 2, 2028.
Must a chatbot say it is AI?
Providers of systems directly interacting with people must design them so people are informed that they are interacting with AI when Article 50 applies, subject to exceptions in the Regulation and Commission guidance.
Is watermarking AI-generated content mandatory?
Article 50(2) requires providers of relevant systems to mark synthetic outputs in a machine-readable format and make them detectable as artificially generated or manipulated, subject to technical feasibility and legal exceptions. The law is broader and more technical than merely adding a visible watermark.
Must deepfakes be labelled?
Deployers must disclose that qualifying deepfake content was artificially generated or manipulated, subject to applicable exceptions and tailored disclosure rules.
Does AI-generated text require a label?
It can. Deployers must disclose specified AI-generated or manipulated text published to inform the public on matters of public interest unless an exception applies, including the human-review and editorial-responsibility conditions in Article 50.
Is the Transparency Code of Practice mandatory?
No. It is voluntary. The Commission and AI Board assessed it as an adequate means to facilitate compliance. A non-signatory remains responsible for proving compliance through alternative adequate measures.
Does the AI Act apply to companies outside the EU?
It can. The rules apply to relevant actors outside the EU that place systems or GPAI models on the EU market, put systems into service or use them in the EU, or meet the Act’s output-related territorial scope.
Does using a third-party AI API make us a provider?
Not automatically. You may be a deployer, a downstream AI-system provider, or another operator depending on how you integrate, brand, modify, and use the service. Role classification must be performed for the specific system.
Is GDPR compliance enough?
No. GDPR and the AI Act apply alongside each other. An AI project may require both AI Act controls and GDPR measures such as a legal basis, transparency, data minimisation, security, rights handling, and a DPIA.
What is required for AI literacy?
Providers and deployers must take context-appropriate measures to support the development of AI literacy among staff and other persons operating or using AI systems on their behalf. The amended Article 4 does not impose one universal level for every person.
When can GPAI providers be fined?
The Commission’s enforcement powers for GPAI provider obligations apply from August 2, 2026. Models placed on the market before August 2, 2025 have a transition until August 2, 2027.
Are small companies exempt?
No general small-business exemption removes all AI Act duties. The Regulation includes proportionality, support, simplified pathways, and penalty rules for SMEs and certain small mid-cap enterprises, but obligations can still apply.
Final Readiness Test
Score each statement:
- 0: Not started
- 1: Identified
- 2: Control designed
- 3: Implemented
- 4: Tested and evidenced
| Readiness Area | Score 0–4 |
|---|---|
| Executive accountability | |
| AI inventory | |
| Legal-role mapping | |
| Prohibited-practice screening | |
| AI literacy | |
| Article 50 interaction notices | |
| Synthetic-content marking | |
| Deepfake and public-interest labels | |
| GPAI provider compliance | |
| Vendor due diligence | |
| Privacy and fundamental-rights review | |
| High-risk classification | |
| Documentation and records | |
| Monitoring and incidents | |
| Regulatory response |
Interpreting the Score
- 50–60: Strong programme; focus on independent testing and changing guidance.
- 35–49: Material controls exist, but evidence or coverage is incomplete.
- 20–34: Significant compliance gaps; prioritised remediation is needed.
- Below 20: Immediate executive intervention is advisable.
This scoring model is an internal management tool, not an official EU assessment.
Conclusion
The key August 2026 compliance question is not whether every AI system has become high-risk.
It is whether your organisation can demonstrate that it:
- knows where AI is used;
- understands its legal roles;
- has stopped prohibited practices;
- supports AI literacy;
- meets Article 50 transparency duties;
- complies with GPAI obligations where applicable;
- controls vendors and downstream integrations;
- respects privacy and fundamental rights;
- records decisions and evidence;
- monitors systems after release; and
- has a funded roadmap for the postponed high-risk requirements.
The Digital Omnibus gave organisations more time for high-risk-system compliance. It did not create a general pause.
As of August 4, 2026, the most defensible approach is to close immediate transparency, GPAI, literacy, and prohibited-use gaps while using the extended high-risk timeline to build controls that are technically real, contractually supported, and auditable.
Official Sources
[^1]: EUR-Lex, Regulation (EU) 2024/1689—the Artificial Intelligence Act.
[^2]: European Commission, Navigating the AI Act, updated July 27, 2026.
[^3]: EUR-Lex, Regulation (EU) 2026/1744—the Digital Omnibus on AI, in force from July 27, 2026.
[^4]: European Commission, Navigating the AI Act: scope, high-risk obligations, governance, and penalties.
[^5]: European Commission, Guidelines on prohibited artificial-intelligence practices.
[^6]: European Commission, AI Literacy—Questions and Answers.
[^7]: European Commission, Repository of AI literacy practices.
[^8]: European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, July 20, 2026.
[^9]: European Commission, Opinion on the Code of Practice on Transparency of AI-Generated Content, July 9, 2026.
[^10]: European Commission, Guidelines for providers of general-purpose AI models.
[^11]: European Commission, Guidelines on obligations for General-Purpose AI providers—Q&A.
[^12]: European Commission, Guidelines for providers and deployers of AI high-risk systems.