Blog
5 September 2026/6 min read

EU AI Act Compliance: A Practical Starting Checklist (2026)

The EU AI Act risk-based structure explained, what compliance actually requires for high-risk systems, and a practical starting checklist. Not legal advice.

Adel Dahani
Author:Adel Dahani,CTO | Ex IBM
EU AI Act Compliance: A Practical Starting Checklist (2026)

Book a Free Strategy Call

Skip the read: talk to Walid in 30 min.

Free strategy call. We map your AI engineering team, you keep the notes.

The EU AI Act is the first comprehensive AI-specific regulation of its kind, and its requirements scale directly with how risky a given AI system is judged to be, from essentially no obligations for minimal-risk systems to strict requirements for anything classified as high-risk. Understanding where a specific system falls in that risk tiering is the necessary first step before any compliance work makes sense, since the requirements that actually apply depend entirely on that classification.

This guide covers the Act's risk-based structure, what compliance actually requires at each tier, and a practical starting checklist. This is general information, not legal advice, and any organization with real compliance exposure should get qualified legal counsel for their specific situation.

The Act's risk-based structure

Unacceptable risk. A narrow category of AI applications the Act prohibits outright, including systems using manipulative techniques that cause harm, certain forms of biometric categorization, and social scoring by public authorities. If a system falls into this category, the answer isn't a compliance checklist, it's that the system can't be deployed in the EU market at all.

High-risk. Systems used in specific sensitive contexts explicitly listed in the Act, including employment and worker management, access to essential services (like credit scoring), education and vocational training, law enforcement, and migration and border control. These carry the most substantial compliance obligations: risk management systems, data governance requirements, technical documentation, human oversight, and conformity assessment before market placement.

Limited risk. Systems with specific transparency obligations, most notably that users need to be informed they're interacting with an AI system rather than a human, relevant for chatbots and similar interactive systems, without the full high-risk compliance burden.

Minimal risk. The large majority of AI applications, spam filters, AI-enabled video game features, and similar low-stakes systems, which face no specific obligations under the Act beyond general legal requirements that would apply regardless of AI involvement.

What compliance actually requires for high-risk systems

A risk management system. An ongoing, documented process for identifying, evaluating, and mitigating risks throughout the system's lifecycle, not a one-time assessment before launch, similar in spirit to the ongoing process covered in our guide to AI risk assessment frameworks.

Data governance requirements. Training, validation, and testing data need to meet quality criteria and be examined for possible biases, connecting directly to the bias testing discipline for systems affecting consequential decisions.

Technical documentation. Detailed documentation of the system's design, development process, and performance characteristics, conceptually related to but more extensive than the documentation covered in model cards.

Human oversight. High-risk systems need to be designed so a human can effectively oversee their operation, including the ability to intervene or halt the system, not deployed as a fully autonomous black box making consequential decisions unchecked.

Conformity assessment before market placement. High-risk systems generally need to undergo a conformity assessment confirming compliance with the Act's requirements before being placed on the market or put into service.

Free weekly brief

Steal our production automations

The exact n8n flows, Claude Code setups, and prompts we ship for clients, broken down step by step. No spam, unsubscribe anytime.

A comparison by risk tier

Risk tierExampleCompliance burden
UnacceptableManipulative or social-scoring systemsProhibited outright
High-riskHiring tools, credit scoring, critical infrastructureRisk management, data governance, documentation, human oversight, conformity assessment
Limited riskCustomer-facing chatbotsTransparency obligation (disclose AI interaction)
Minimal riskSpam filters, low-stakes automationNo specific obligations

A practical starting checklist

Determine which risk tier your system actually falls into. This is the foundational step, since it determines everything else. Review the Act's specific listed high-risk categories against your actual use case rather than assuming based on general impressions of how sensitive the application feels.

If high-risk, inventory what documentation and processes you already have versus what's required. Compare your existing risk assessment, data governance, and technical documentation practices against the Act's specific requirements to identify concrete gaps.

If limited risk, confirm your transparency obligations are actually met. Check that users interacting with an AI-driven interface are clearly informed of that fact, a comparatively lighter but still explicit requirement.

Build ongoing compliance into your development process, not a one-time review. The Act's risk management requirement for high-risk systems is explicitly ongoing, which means compliance needs to be embedded into how the system is maintained and updated, not treated as a single pre-launch gate.

Get qualified legal counsel for your specific situation. This checklist is a starting orientation, not a substitute for legal review, particularly for any system with real exposure under the high-risk category, given the direct consequences of getting classification or compliance wrong.

FAQ

What is the EU AI Act?

The EU AI Act is a comprehensive regulation governing AI systems in the EU market, structuring obligations around a risk-based tiering system, from prohibited unacceptable-risk applications to no specific obligations for minimal-risk systems.

How do I know if my AI system is classified as high-risk under the EU AI Act?

The Act lists specific categories considered high-risk, including employment and worker management, access to essential services like credit scoring, education, law enforcement, and migration control. Reviewing your specific use case against these listed categories, ideally with legal counsel, determines classification.

What does compliance require for a high-risk AI system?

An ongoing risk management system, data governance meeting quality and bias-examination criteria, detailed technical documentation, human oversight capability, and conformity assessment before the system is placed on the market.

What transparency obligations apply to limited-risk AI systems like chatbots?

Users need to be informed they're interacting with an AI system rather than a human, a specific but comparatively lighter obligation than the full compliance burden required for high-risk systems.

Does the EU AI Act apply to AI systems outside the EU?

The Act's scope can extend to providers and deployers outside the EU whose AI systems are placed on the EU market or affect people within the EU, which is a jurisdiction question worth confirming with legal counsel for any organization operating internationally.

Is EU AI Act compliance a one-time process?

No, particularly for high-risk systems, where the risk management requirement is explicitly ongoing throughout the system's lifecycle, not a single assessment completed before launch and never revisited.


For the ongoing risk-management process this connects to, see our AI risk assessment framework guide. For the bias-testing and documentation practices that support compliance, read AI bias testing and AI model card documentation. Our AI strategy consulting service helps organizations build the ongoing governance processes EU AI Act compliance requires; this is not a substitute for qualified legal counsel on your specific situation.

Sources: EU AI Act (Regulation (EU) 2024/1689) public text, internal AY Automate AI governance and strategy consulting practice.

Book a Free Strategy Call

Building this in production?

Walid runs a 30-min call to map your AI engineering team. Free, no slides.

Free weekly brief

Steal our production automations

The exact n8n flows, Claude Code setups, and prompts we ship for clients, broken down step by step. No spam, unsubscribe anytime.

Share this article
#AI Governance#AI Compliance#AI Risk#EU AI Act
About the Author
Adel Dahani
Adel Dahani
CTO | Ex IBM

Ex-IBM AI engineer and enterprise architect. Adel owns the technical architecture behind every automation and AI agent system AY Automate ships.