EU AI ACT GUIDE

EU AI Act Requirements Checklist (2026)

Everything your company must do under the EU AI Act — who it applies to, what's in force right now, and the fines for getting it wrong.

The law is live. Enforcement of the EU AI Act's core transparency obligations started August 2, 2026. Authorities can now investigate, impose fines, and order AI products off the market. The checklist below tells you exactly where you stand.

1. Who must comply

The EU AI Act (Regulation (EU) 2024/1689) applies far beyond the EU. It catches any company that supplies, deploys, imports, or represents AI systems used by people in the EU — regardless of where the company is based.

Yes — a US startup with European users, an Indian SaaS with EU clients, or a German consultancy chatbots are all in scope. This is why the Act affects an estimated 25 million businesses.

2. Timeline & deadlines

DateWhat became mandatory
2 Feb 2025Prohibited AI practices (social scoring, manipulation, etc.) — already banned
2 Aug 2025General-purpose AI (GPAI) model obligations — already in force
2 Aug 2026Article 50 transparency + interoperability + most other provisions — IN FORCE NOW
2 Dec 2027High-risk systems under Annex III (C-2 list) — moved to this date by the 2026 Omnibus
2 Aug 2027High-risk AI as a safety component under sectoral EU law
Note on the 2026 Omnibus: the June 2026 simplification package delayed high-risk obligations in Annex III to December 2, 2027 and raised the SME exemption threshold. But the transparency and GPAI rules were not delayed — treats, chatbots, deepfakes, and AI-generated content are fully regulated since August 2, 2026.

3. Classify your system

Your obligations depend on the risk tier your AI system falls into. This is the single most important classification step.

Common mistake: companies assume their internal RAG chatbot is "minimal risk." If it touches employment decisions, credit scoring, or student assessment, it is high risk — with a much heavier compliance burden.

4. Transparency obligations (in force now)

These are the live obligations since August 2, 2026. If you operate any AI that interacts with people, you must check these today:

Chatbot disclosure (Article 50(1)). Anyone interacting with an AI system — including a chatbot — must be told they are talking to a machine, unless it is obvious.
Synthetic content labels (Article 50(2)). Audio, video, or image content generated or manipulated by AI must be marked as AI-generated or deepfake.
Machine-readable watermarking (Article 50(4)). Outputs must be detectable as machine-generated to allow tamper-evident identification.
Emotional recognition / biometric categorisation disclosures (Article 50(5)). Individuals exposed to such systems must be informed — with a limited public-safety exception.
Provision of this information. You must supply transparency info to downstream deployers so they can comply too.

This is the area authorities can enforce right now. If your website has an AI assistant, a content generator, or deepfake/edit tools that are not labelled, you are exposed today — not in 2027.

5. High-risk AI requirements (Articles 8–15)

From December 2, 2027 (Annex III), high-risk systems must meet the full set of obligations. Even where deadlines moved, the smartest teams are building now — remediation takes months, and the proverbial "black box" audit is the classic failure mode.

Risk management system (Art. 9). Continuous risk identification, analysis, and mitigation throughout the lifecycle.
Data & data governance (Art. 10). Relevant, representative, error-free training/validation data; bias-compliant design; documented lineage.
Technical documentation (Art. 11). Full documentation proving compliance — available for authorities on request.
Record-keeping & logging (Art. 12). Automatic event logs covering the system's full lifecycle.
Human oversight (Art. 14). Measures that let humans supervise, interpret, and override the system's output.
Accuracy, robustness & cybersecurity (Art. 15). Documented performance metrics, resilience to errors and adversarial attacks.
Conformity assessment (Art. 43) + EU Declaration (Art. 47). Self-assessment or notified-body assessment depending on the use case; CE marking.
Registration in the EU database (Art. 49). High-risk systems must be registered before market placement.
Post-market monitoring (Art. 72) and serious-incident reporting to national authorities.

6. General-purpose AI (GPAI) obligations

In force since August 2, 2025 for model providers:

7. Governance, enforcement & fines

8. Your 7-step action plan

  1. Inventory your AI — list every model, chatbot, generator, and automation you ship or use.
  2. Classify each system into unacceptable / high / GPAI / limited / minimal risk.
  3. Fix transparency now — label chatbots and AI-generated content, add watermarking. These are live obligations.
  4. Document everything — model cards, data lineage, oversight design, and logging.
  5. Close high-risk gaps (Articles 9–15) before the December 2027 deadline hits.
  6. Produce the technical file — EU declaration of conformity + conformity report.
  7. Monitor continuously — the rules are moving fast; treat compliance as a process, not a project.

More EU AI Act guides

EU AI Act Fines in 2026 — what non-compliance really costs

EU AI Act for Indian SaaS — the Act applies beyond EU borders

EU AI Act Compliance for Startups — a practical starter guide

Free Resources — download checklists and one-pagers

Skip the checklist — get your score in 5 minutes

Scan your codebase against a full EU AI Act requirements engine and get an instant 0–100% compliance score with a remediation plan. No signup required. Free.

Run Your Free Compliance Scan →

Disclaimer: This article is informational guidance and does not constitute legal advice. Deadlines referenced reflect the EU AI Act as amended by the 2026 Omnibus regulation. Always verify obligations for your specific use case with counsel.