- EU AI Act
- AI compliance
- AI governance
- checklist
EU AI Act Compliance Checklist
A step-by-step EU AI Act compliance checklist: classify your AI systems by risk, meet the obligations for each tier, and operationalize governance, documentation, and human oversight.
The short answer
To comply with the EU AI Act, classify each AI system by its risk tier, then apply the obligations that tier carries. Prohibited practices must be removed, high-risk systems require the full set of risk-management, data-governance, documentation, transparency, human-oversight, and robustness controls, limited-risk systems need transparency disclosures, and minimal-risk systems are largely unrestricted. The checklist below organizes that work.
For background on the regulation itself, see our EU AI Act pillar guide and the EU AI Act glossary entry.
Step 1 — Inventory your AI systems
You cannot classify what you have not catalogued. Build an inventory of every AI system you develop, deploy, or embed, recording for each:
- Its purpose and the decisions it influences
- Whether you act as a provider, deployer, or both
- The data it is trained on and operates over
- Where and to whom it is made available
This inventory is the foundation for every subsequent step and overlaps with the data mapping you may already maintain for GDPR.
Step 2 — Classify each system by risk tier
The Act applies obligations according to risk:
- Prohibited — practices such as certain manipulative or social-scoring uses are banned outright.
- High-risk — systems used in sensitive domains carry the most extensive obligations.
- Limited-risk — systems that interact with people (for example, chatbots) carry transparency duties.
- Minimal-risk — most other AI faces no specific obligations.
Document the rationale for each classification. The classification drives everything that follows, so it should be defensible and revisited when a system changes.
Step 3 — Eliminate prohibited practices
For any system that falls into a prohibited category, the only compliant path is to stop the practice. Confirm that none of your systems engage in banned uses, and record the assessment as evidence.
Step 4 — Meet high-risk obligations
High-risk systems require a coordinated control set. Use this as a working checklist:
- [ ] Risk management system — a continuous process to identify and mitigate risks across the lifecycle
- [ ] Data governance — controls over training, validation, and testing data quality and representativeness
- [ ] Technical documentation — sufficient detail to demonstrate conformity
- [ ] Record-keeping — automatic logging of system events for traceability
- [ ] Transparency — clear information enabling deployers to use the system correctly
- [ ] Human oversight — measures allowing meaningful human intervention
- [ ] Accuracy, robustness, and cybersecurity — appropriate performance and resilience measures
- [ ] Quality management system — organizational processes ensuring ongoing conformity
- [ ] Conformity assessment — completed before placing the system on the market, where required
Many of these map onto controls you already operate for security and privacy. Control mapping lets you reuse that work rather than duplicate it.
Step 5 — Apply transparency duties for limited-risk systems
Systems that interact with people generally must make clear that users are dealing with AI. Synthetic or manipulated content typically needs to be disclosed as such. Inventory where these duties apply and implement the corresponding notices.
Step 6 — Operationalize governance and oversight
The Act expects governance to be ongoing, not a one-time exercise. Align your program with a recognized framework such as the NIST AI RMF, which structures AI risk work into GOVERN, MAP, MEASURE, and MANAGE functions. Assign clear ownership, define human-oversight procedures, and schedule periodic review of each system's classification and controls.
Step 7 — Maintain continuous evidence
As with security frameworks, you must be able to demonstrate conformity, not just assert it. Maintain current documentation, event logs, risk assessments, and oversight records. Continuous evidence collection keeps this material up to date as systems evolve and makes a conformity assessment or regulator inquiry far less disruptive.
Bringing it together
The EU AI Act rewards organizations that treat AI governance as an extension of their existing compliance program rather than a separate silo. Inventory and classify first, apply tier-appropriate controls, reuse mapped controls across frameworks, and keep evidence continuous. To see how ComplyEasy AI supports this end to end, visit the EU AI Act framework page.