EU AI Act Requirements Checklist (2026)
Everything your company must do under the EU AI Act — who it applies to, what's in force right now, and the fines for getting it wrong.
On this page
1. Who must comply 2. Timeline & deadlines 3. Classify your system 4. Transparency obligations (in force now) 5. High-risk AI requirements 6. General-purpose AI (GPAI) obligations 7. Governance, enforcement & fines 8. Your 7-step action plan1. Who must comply
The EU AI Act (Regulation (EU) 2024/1689) applies far beyond the EU. It catches any company that supplies, deploys, imports, or represents AI systems used by people in the EU — regardless of where the company is based.
- Providers — companies that develop or place an AI system on the EU market.
- Deployers — companies that use an AI system in the course of their activity (even a chatbot built on OpenAI or Anthropic APIs).
- Importers & distributors — businesses that bring AI systems into the EU or resell them.
- Authorised representatives — any non-EU provider with customers in the EU must appoint one.
Yes — a US startup with European users, an Indian SaaS with EU clients, or a German consultancy chatbots are all in scope. This is why the Act affects an estimated 25 million businesses.
2. Timeline & deadlines
| Date | What became mandatory |
|---|---|
| 2 Feb 2025 | Prohibited AI practices (social scoring, manipulation, etc.) — already banned |
| 2 Aug 2025 | General-purpose AI (GPAI) model obligations — already in force |
| 2 Aug 2026 | Article 50 transparency + interoperability + most other provisions — IN FORCE NOW |
| 2 Dec 2027 | High-risk systems under Annex III (C-2 list) — moved to this date by the 2026 Omnibus |
| 2 Aug 2027 | High-risk AI as a safety component under sectoral EU law |
3. Classify your system
Your obligations depend on the risk tier your AI system falls into. This is the single most important classification step.
- Unacceptable risk — prohibited: social scoring by public authorities, subliminal manipulation, exploitation of vulnerable groups, untargeted facial scraping. Banning already in effect.
- High risk — Annex I (products under EU safety law) and Annex III (critical infrastructure, education, employment, credit, essential services, law enforcement, migration, justice, democracy). Subject to the heaviest requirements.
- GPAI / systemic risk — general-purpose models, with extra duties if they reach high impact capability (10^25 FLOPs or more).
- Limited risk — transparency obligations (chatbots, deepfakes, AI-generated content).
- Minimal risk — the vast majority of internal tools; encouraged to follow voluntary codes.
4. Transparency obligations (in force now)
These are the live obligations since August 2, 2026. If you operate any AI that interacts with people, you must check these today:
This is the area authorities can enforce right now. If your website has an AI assistant, a content generator, or deepfake/edit tools that are not labelled, you are exposed today — not in 2027.
5. High-risk AI requirements (Articles 8–15)
From December 2, 2027 (Annex III), high-risk systems must meet the full set of obligations. Even where deadlines moved, the smartest teams are building now — remediation takes months, and the proverbial "black box" audit is the classic failure mode.
6. General-purpose AI (GPAI) obligations
In force since August 2, 2025 for model providers:
- Provide detailed technical documentation and basic information to downstream providers.
- Respect the EU Copyright Directive — including a copyright policy (this is the rule behind major legal disputes over training data).
- Publish a sufficiently detailed summary of training content.
- If you have systemic risk (above the 10^25 FLOPs capability threshold): model evaluations, stress-testing, adversarial testing, incident reporting, cybersecurity protections, and compliance with the Code of Practice.
7. Governance, enforcement & fines
- Each EU country designates a market surveillance authority to investigate and fine companies.
- The Brussels-based AI Office oversees GPAI models and systemic-risk enforcement across the EU.
- EU users of prohibited high-risk systems can now file complaints; authorities can order product withdrawal and recall.
- Fines are tiered:
- €35M or 7% of global annual revenue (whichever is higher) — for prohibited practices.
- €15M or 3% — for most other violations (e.g. high-risk obligations).
- €7.5M or 1.5% — for supplying incorrect information to authorities.
8. Your 7-step action plan
- Inventory your AI — list every model, chatbot, generator, and automation you ship or use.
- Classify each system into unacceptable / high / GPAI / limited / minimal risk.
- Fix transparency now — label chatbots and AI-generated content, add watermarking. These are live obligations.
- Document everything — model cards, data lineage, oversight design, and logging.
- Close high-risk gaps (Articles 9–15) before the December 2027 deadline hits.
- Produce the technical file — EU declaration of conformity + conformity report.
- Monitor continuously — the rules are moving fast; treat compliance as a process, not a project.
More EU AI Act guides
• EU AI Act Fines in 2026 — what non-compliance really costs
• EU AI Act for Indian SaaS — the Act applies beyond EU borders
• EU AI Act Compliance for Startups — a practical starter guide
• Free Resources — download checklists and one-pagers
Skip the checklist — get your score in 5 minutes
Scan your codebase against a full EU AI Act requirements engine and get an instant 0–100% compliance score with a remediation plan. No signup required. Free.
Run Your Free Compliance Scan →Disclaimer: This article is informational guidance and does not constitute legal advice. Deadlines referenced reflect the EU AI Act as amended by the 2026 Omnibus regulation. Always verify obligations for your specific use case with counsel.