EU AI Act · Compliance tooling

EU AI Act Compliance Checklist — 15 Requirements, Scanned Automatically

The EU AI Act asks for a lot of groundwork: risk-management systems, data governance, technical documentation, record-keeping, human oversight, accuracy and cybersecurity. Walking a team through all 15 requirement areas manually takes weeks. A scanner checks your actual code and configuration against them and tells you exactly which items pass and which are missing.

What is on the compliance checklist

The high-risk package covers: a risk-management system (Article 9); data-governance controls for training, validation and test data (Article 10); technical documentation (Article 11); automatic log-recording (Article 12); transparency and instructions (Article 13); human oversight, including a human who can override the system (Article 14); and accuracy, robustness and cybersecurity (Article 15). Providers also owe a quality-management system, an EU declaration of conformity and CE marking before market placement.

How an automated checklist is different

A manual spreadsheet becomes stale the moment your code changes. An automated scan re-runs the checklist against your codebase, config files and model definitions every time, so the evidence matches reality. The result is a scorecard per requirement — with the specific files and lines that satisfy each item, and the gaps that need work.

Getting from checklist to compliant

The checklist is step one. Fix gaps in priority order (high-risk gaps first), document each requirement with evidence, and re-scan so the report shows a closed loop. Regulators and auditors increasingly accept machine-generated evidence trails over hand-written claims.

Free EU AI Act Compliance Scan

See your score in 2 minutes. No signup, no code stored.

Scan Your Codebase Now

Frequently Asked Questions

Is the checklist free?

The first scan is free and takes about 2 minutes. Paid plans cover recurring scans, full dashboards and remediation planning.

Does it reflect the omnibus deferrals?

Yes. The rules engine reflects the current timelines under Regulation (EU) 2026/1744, including the December 2027 high-risk date.

What if we are not high-risk?

The scan still surfaces transparency duties such as chatbot disclosure and deepfake labelling, so limited-risk teams can close those cheap wins too.