EU AI Act Compliance: Requirements, Risk Categories and Checklist

  • Jul 12, 2026
  • 9 min read
  • 232
EU AI Act Compliance: Requirements, Risk Categories and Checklist

The EU AI Act is the world's first comprehensive law regulating artificial intelligence, and EU AI Act compliance is now a live obligation — not a future one. Parts of the Act already apply, the first fines are legally possible, and the remaining deadlines are approaching on a published schedule. Yet many organisations still cannot answer the two questions the Act forces on them: does this law apply to us, and what exactly do we have to do, by when?

 

This guide answers both. It explains who falls within the Act's scope, how the risk-based categories work, what providers and deployers must each do, where the compliance timeline stands after the May 2026 "Digital Omnibus" agreement, and what the penalties are. It ends with a practical checklist you can use to assess where your organisation stands today.

 

One caution before we begin: this article is a structured overview for compliance planning, not legal advice. For binding detail, always work from the official text of Regulation (EU) 2024/1689 on EUR-Lex and consult qualified counsel for decisions specific to your systems.

Who the EU AI Act Applies To

The Act's reach is deliberately wide, and its extraterritorial effect catches many organisations that assume a European law cannot touch them.

Who the EU AI Act Applies To

You are within scope if you are a provider — you develop an AI system or general-purpose AI model and place it on the EU market under your own name, regardless of where your company is established. You are also within scope as a deployer — an organisation using an AI system in a professional capacity within the EU. And critically, the Act applies to providers and deployers located outside the EU whenever the output of their AI system is used in the EU.

 

That last clause is the one global businesses most often miss. A US software company selling an AI recruitment tool to a Madrid employer is in scope. A Bangladeshi outsourcing firm whose AI-generated analysis is delivered to clients in Germany can be in scope. An e-commerce business anywhere in the world using AI to profile EU customers can be in scope. Geography of incorporation does not decide the question; the EU market and EU-based people do.

 

The Act also assigns obligations to importers and distributors of AI systems, and it carves out exemptions — including AI used solely for military and national-security purposes, systems developed purely for scientific research, and personal, non-professional use.

The Four Risk Categories Explained

The Act's entire architecture rests on one idea: regulate AI according to the risk it poses to health, safety and fundamental rights. Every AI system falls into one of four tiers, and the tier determines everything that follows.

 

The Four Risk Categories Explained

Two practical notes on classification. First, the high-risk list is use-based, not technology-based: the same machine-learning model can be minimal risk in one application and high risk in another. Second, the prohibited list was extended in 2026 — the Digital Omnibus agreement adds a ban on AI systems whose purpose is generating non-consensual intimate imagery or child sexual abuse material, including so-called "nudifier" apps.

 

If you want to test a specific system against the Act's definitions, the AI Act Explorer maintained at artificialintelligenceact.eu is a widely used free tool for navigating the full text by article and annex.

Obligations for Providers vs Deployers

The Act splits responsibility along the AI value chain, and confusing the two roles is one of the most common compliance errors. Many organisations are both — a company that substantially modifies a purchased AI system, or markets it under its own brand, can become a provider with a provider's full obligations.

 

Providers of high-risk AI systems carry the heaviest load. They must operate a continuous risk-management system across the AI lifecycle; ensure training, validation and testing data meet quality and governance criteria; prepare and maintain technical documentation; build in automatic event logging; design the system for effective human oversight; achieve appropriate accuracy, robustness and cybersecurity; pass a conformity assessment and affix CE marking; register the system in the EU database; and run post-market monitoring with incident reporting to authorities.

 

Deployers of high-risk AI systems have a shorter but genuinely demanding list. They must use the system in accordance with the provider's instructions; assign human oversight to people with the competence, training and authority to exercise it; ensure input data they control is relevant and sufficiently representative; monitor operation and suspend use if serious risk emerges; keep the system's logs; inform affected workers before deploying workplace AI; and — for public bodies and certain private deployers such as banks and insurers — complete a fundamental rights impact assessment before first use.

 

Providers of general-purpose AI models (the foundation models behind generative AI) follow a separate track that has applied since August 2025: technical documentation, information for downstream providers, a copyright policy and a training-data summary, with additional obligations for models posing systemic risk. The European Commission's AI Act policy hub hosts the guidelines and the GPAI Code of Practice that operationalise this track, and the European AI Office supervises it.

The Compliance Timeline After the Digital Omnibus

The Act entered into force on 1 August 2024 with a staggered application schedule — and in May 2026 that schedule changed materially, so it is worth setting out the current position with care.

 

Already applying. The prohibitions on unacceptable-risk practices and the AI-literacy duty have applied since 2 February 2025. Obligations for general-purpose AI models have applied since 2 August 2025.

 

The May 2026 deferral. On 7 May 2026, the European Parliament and the Council of the EU reached a provisional agreement on the "Digital Omnibus on AI", a package of targeted amendments to the Act. Its headline change defers the high-risk compliance dates: obligations for stand-alone Annex III high-risk systems move from 2 August 2026 to 2 December 2027, and obligations for high-risk AI embedded in Annex I regulated products move to 2 August 2028. The agreement also adjusts certain Article 50 transparency mechanics, with machine-readable marking ("watermarking") duties for AI-generated content set for 2 December 2026, and adds the new prohibition on non-consensual intimate imagery noted above. Detailed practitioner summaries are available from Hogan Lovells and Gibson Dunn.

 

The critical caveat. As of this article's last review, the Omnibus remains a provisional political agreement. The new dates only take legal effect once the amending regulation is formally adopted and published in the Official Journal — expected before 2 August 2026, but not yet done. Until that happens, the original deadlines remain the law as written. Both EU institutions and legal commentators have been explicit on the second point: the deferral is breathing room for preparation, not permission to pause. The hardest parts of compliance — finding every AI system in the organisation and classifying each one — take months and do not get easier by waiting.

Penalties for Non-Compliance

The Act backs its obligations with administrative fines scaled to severity and to global revenue — deliberately echoing the GDPR's enforcement logic, with higher ceilings.

 

Engaging in a prohibited AI practice carries fines of up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Non-compliance with most other obligations — including the high-risk requirements for providers and deployers — carries fines of up to €15 million or 3% of worldwide turnover. Supplying incorrect, incomplete or misleading information to authorities carries fines of up to €7.5 million or 1% of turnover. For small and medium-sized enterprises, including start-ups, each fine is capped at the lower of the percentage or fixed amount rather than the higher.

 

Enforcement is shared: national market-surveillance authorities designated by each Member State handle most AI systems, while the European AI Office enforces the general-purpose AI rules centrally. Beyond fines, authorities can require systems to be withdrawn from the market — and for many organisations the operational and reputational cost of a forced withdrawal exceeds any fine.

EU AI Act Compliance Checklist

Use this checklist to assess your current position. It follows the order in which compliance work is best done; an honest "no" at an early step makes the later steps unreliable.

 

Stage 1 — Scope and inventory

  • We have confirmed whether the Act applies to us as a provider, deployer, importer or distributor — including the extraterritorial test (are our systems or their outputs used in the EU?)

  • We maintain a complete inventory of AI systems we develop, sell or use, including AI embedded in vendor software and staff use of generative AI tools

  • Each inventoried system has a named business owner

 

Stage 2 — Classification

  • Every system has been classified against the four risk tiers, with the reasoning documented

  • We have specifically checked our systems against the Article 5 prohibited-practices list, including the newly agreed prohibition on non-consensual intimate imagery

  • We have checked recruitment, HR, credit, education and customer-eligibility systems against Annex III — these are the categories organisations most often misclassify as harmless

  • For each high-risk system, we have determined whether our role is provider, deployer or both

 

Stage 3 — Immediate obligations (already in force)

  • No system we provide or use falls within a prohibited practice

  • We have an AI-literacy programme ensuring staff who operate AI systems have appropriate training (required since February 2025)

  • If we provide a general-purpose AI model: documentation, downstream information, copyright policy and training-data summary are in place (required since August 2025)

  • Chatbots and other systems interacting with people disclose that they are AI; our plan for machine-readable marking of AI-generated content is on track for the December 2026 date

 

Stage 4 — High-risk readiness (deadline December 2027 / August 2028, pending formal adoption)

  • Providers: risk-management system, data-governance criteria, technical documentation, logging, human-oversight design, accuracy and robustness testing, conformity-assessment route and EU database registration are planned with dates and owners

  • Deployers: instructions-for-use compliance, trained human overseers with real authority, input-data controls, log retention, worker notification and (where applicable) a fundamental rights impact assessment are planned with dates and owners

  • Contracts with AI vendors allocate AI Act responsibilities, information flows and audit rights between the parties

 

Stage 5 — Sustain

  • AI Act compliance has a named programme owner and board-level visibility

  • The inventory and classifications are reviewed on a defined cycle and whenever a system materially changes

  • We monitor official guidance from the European Commission and our national authority, and we have diarised the formal adoption of the Digital Omnibus to confirm the final deadlines

 

A score below complete on Stages 1–3 means the priority is not the 2027 deadline — it is the obligations that already apply today.

 

The EU AI Act rewards organisations that start early and punishes those that treat the deferred deadlines as a snooze button. The inventory, classification and governance work in Stages 1 and 2 of the checklist is slow, unglamorous and entirely independent of which final dates apply — which is exactly why it is the right work to be doing now.

 

Frequently Asked Questions

Yes, in two main situations: when they place AI systems or models on the EU market, and when the output of their AI systems is used in the EU. A provider or deployer with no EU establishment can still be fully in scope and may need to appoint an EU authorised representative.

Two routes lead there. A system is high risk if it is a safety component of a product covered by the EU product-safety legislation listed in Annex I, or if it falls within an Annex III use case — including recruitment and worker management, credit scoring, education, essential public and private services, law enforcement, migration and justice. Classification depends on the use, and providers can document a limited derogation where an Annex III system demonstrably poses no significant risk.

Up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for most other violations; up to €7.5 million or 1% for misleading authorities — with lower caps for SMEs. National authorities and the European AI Office share enforcement.

Partially, and provisionally. The May 2026 Digital Omnibus agreement defers the high-risk obligations to December 2027 (Annex III) and August 2028 (Annex I), but the prohibitions, AI-literacy duty and general-purpose AI rules already apply unchanged, and the new dates only become law on formal adoption. Compliance preparation should continue against the obligations as they stand.

A provider develops or places an AI system on the EU market under its own name, while a deployer uses an AI system in a professional setting. Providers usually carry heavier duties, especially for high-risk systems, including technical documentation, conformity assessment and post-market monitoring. Deployers must use the system correctly, assign trained human oversight, monitor operation, keep logs where required and act if serious risks appear.

The best starting point is an AI inventory. List every AI system the organisation develops, buys or uses, including vendor tools and employee use of generative AI. Then classify each system against the Act’s risk tiers, identify whether the organisation is a provider, deployer or both, and assign a named owner. Without inventory and classification, later compliance work becomes unreliable.

The AI literacy duty requires organisations to ensure staff involved with AI systems have appropriate knowledge, skills and understanding. This does not mean every employee needs technical AI training. Instead, training should match the person’s role, the AI system they use and the risks involved. Staff should understand what the system can do, where its limits are and when human judgement is required.

Yes, chatbots can fall under the Act’s transparency duties. People must generally be informed when they are interacting with an AI system rather than a human. The aim is simple: users should not be misled about who or what they are communicating with. Organisations using customer service bots, internal assistants or AI support tools should check that clear disclosure is built into the user experience.

High-risk AI compliance usually requires strong documentation throughout the system lifecycle. This may include risk management records, data governance evidence, technical documentation, logging arrangements, human oversight procedures, accuracy and robustness testing, conformity assessment records and post-market monitoring plans. Deployers should also keep instructions for use, oversight records, logs and impact assessment evidence where required.

Yes, in some situations. An organisation that substantially modifies a purchased AI system or places it on the market under its own name may take on provider responsibilities. This is why vendor management is important under the EU AI Act. Contracts should clearly define responsibilities, documentation access, audit rights, information sharing and who handles compliance duties if the system changes.