EU AI Act Compliance Checklist: What Developers and IT Leaders Must Do Now

With enforcement deadlines approaching, organisations deploying AI in Europe face steep penalties — here is a practical, step-by-step guide to getting compliant

EU AI Act Compliance Checklist: What Developers and IT Leaders Must Do Now

Why EU AI Act Compliance Is No Longer Optional

The European Union's Artificial Intelligence Act — the world's first comprehensive legal framework for AI — is now in force, and organisations across the continent are scrambling to understand exactly what it demands of them. For developers, IT decision-makers, privacy professionals, and small business owners who build, deploy, or use AI systems, EU AI Act compliance is no longer a distant regulatory concern. Enforcement timelines are real, and the financial consequences of non-compliance are severe: fines can reach up to €35 million or 7% of global annual turnover for the most serious violations.

Unlike the GDPR, which primarily targeted data handlers, the AI Act casts a wider net — covering AI providers, deployers, importers, and distributors. Whether you are running a customer-facing chatbot, using AI-powered recruitment software, or integrating a generative AI tool into your SaaS product, you are likely within scope. According to analysis published by the European Parliament, the regulation applies to any AI system placed on the EU market or used within the EU, regardless of where the developer or company is based. This extraterritorial reach mirrors the GDPR's approach and will affect companies worldwide.

Understanding the Four-Tier Risk Classification System

AI systems and compliance frameworks visualised on a digital interface
The EU AI Act's risk-based structure determines how organisations must govern and document their AI systems

The cornerstone of the AI Act is its risk-based classification framework. Not all AI systems carry the same obligations — but understanding where your system sits in the hierarchy is the mandatory first step of any compliance checklist.

  • Unacceptable risk (banned): Systems such as social scoring by governments, real-time biometric surveillance in public spaces, and AI that exploits psychological vulnerabilities. These are prohibited outright.
  • High risk: AI used in critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. These face the strictest requirements, including mandatory risk management systems, data governance practices, technical documentation, transparency obligations, and human oversight mechanisms.
  • Limited risk: Systems such as chatbots must inform users they are interacting with AI. Transparency obligations apply.
  • Minimal risk: Most AI tools, including spam filters and AI-enabled video games, face no specific legal obligations — though the Commission encourages voluntary codes of conduct.

For most developers and enterprise IT leaders, the high-risk category is the most consequential. The European Commission's own guidance identifies sectors including HR, credit scoring, and medical diagnostics as areas where the burden of compliance will be heaviest. A practical compliance journey must begin with a clear-eyed assessment of which category your AI systems fall into.

The 10-Step EU AI Act Compliance Checklist

€35MMax fine for prohibited AI use
7%Global turnover penalty (worst case)
24+Months of phased implementation
€15MFine for high-risk non-compliance

The following checklist is structured to move organisations from initial awareness through to operational readiness. Each step builds on the previous one and reflects the obligations set out in the Act itself, as well as guidance from the EU AI Office, which was established to oversee enforcement.

Step 1 — Conduct an AI inventory audit. Before anything else, map every AI system your organisation uses, builds, or procures. This includes third-party tools integrated into your workflows. Many organisations using off-the-shelf AI products from vendors may still carry deployer-level obligations under the Act.

Step 2 — Classify each system by risk tier. Apply the EU AI Act's four-tier framework to each item on your inventory. If in doubt, legal counsel with AI regulation expertise should be consulted. The Act provides detailed criteria, and the European Commission has published sector-by-sector guidance to assist.

Step 3 — Establish a risk management system. For high-risk systems, you are legally required to implement and maintain a documented risk management process throughout the AI lifecycle — from design to deployment and beyond. This must identify, analyse, and mitigate foreseeable risks.

Step 4 — Implement robust data governance. Training, validation, and testing datasets used for high-risk AI must meet quality standards: they must be relevant, representative, and free of errors as far as possible. This requirement directly intersects with existing GDPR obligations around lawful data processing and data minimisation. Organisations that have already invested in GDPR compliance infrastructure will find this step more straightforward, as noted in analysis published by IAPP (the International Association of Privacy Professionals).

Step 5 — Produce technical documentation. High-risk AI providers must generate detailed technical documentation before placing a system on the market. This documentation must demonstrate that the system complies with the requirements of the Act and must be kept up to date throughout the system's operational lifecycle.

Step 6 — Enable logging and audit trails. The Act mandates automatic logging of events throughout the operation of high-risk AI systems. These logs must be retained in a way that enables post-deployment auditing by authorities. Think of this as the AI equivalent of financial audit trails — a requirement that many enterprises will need to build into system architecture from the ground up.

Step 7 — Ensure transparency and user information. Deployers and providers of high-risk systems must provide users with meaningful information about the system's capabilities and limitations. For general-purpose AI tools with generative capabilities, additional transparency requirements apply — including disclosure of AI-generated content under the Act's provisions for GPAI models.

Step 8 — Design for human oversight. High-risk systems must be designed to allow effective human oversight. This is not just a UI checkbox — it means real operational controls that allow qualified individuals to monitor, intervene, and override AI decisions when necessary. This requirement has direct implications for software architecture decisions.

Step 9 — Conduct conformity assessments and register systems. Certain high-risk AI systems must undergo a conformity assessment before deployment — either self-assessed or via a notified third-party body, depending on the application area. Following assessment, high-risk systems must be registered in the EU's public database via the EUID system.

Step 10 — Appoint an EU representative and establish post-market monitoring. Non-EU providers offering AI systems in the European market must designate an authorised representative within the EU. All high-risk system operators must also establish a post-market monitoring plan to track real-world performance and report serious incidents to national authorities.

How AI Act Obligations Overlap With GDPR — and Where They Diverge

Cybersecurity and data compliance concept with network and legal frameworks
Organisations must navigate both GDPR and the EU AI Act simultaneously, as the frameworks overlap in significant areas

One of the most pressing practical challenges for privacy professionals and IT compliance teams is navigating where the AI Act overlaps with — and where it diverges from — the GDPR. Both regulations apply simultaneously, and adherence to one does not guarantee compliance with the other.

Key areas of overlap include data quality requirements, transparency obligations, and accountability structures. The AI Act's emphasis on data governance for training sets maps closely onto GDPR's requirements for lawful processing, purpose limitation, and data minimisation. Organisations that have already appointed a Data Protection Officer (DPO) and conducted Data Protection Impact Assessments (DPIAs) will find analogous obligations in the AI Act's risk management and conformity assessment requirements.

However, the AI Act introduces obligations that go beyond the GDPR's scope. Human oversight requirements, technical robustness standards, and the mandatory registration of high-risk systems are AI-specific obligations with no direct GDPR equivalent. Privacy professionals will need to expand their compliance repertoire significantly.

"The AI Act is not simply a GDPR for algorithms — it introduces an entirely new governance architecture that requires organisations to think about AI risk management as a continuous operational discipline, not a one-time compliance exercise."

— AI governance specialist, European compliance sector

Research published by the Future of Life Institute has highlighted that many European SMEs remain underprepared for this dual compliance burden. Small business owners and startup founders, in particular, should note that while the Act includes some lighter-touch provisions for smaller organisations, the core high-risk obligations apply regardless of company size when systems fall within regulated categories.

Enforcement Timeline: What Applies When

PhaseTimelineKey Obligations
Prohibited AI bans6 months after entry into forceCease use of all banned AI systems (e.g. social scoring, subliminal manipulation)
GPAI model rules12 months after entry into forceTransparency and copyright compliance for general-purpose AI providers
High-risk AI systems (Annex I)24 months after entry into forceFull compliance with high-risk obligations including conformity assessments
High-risk AI systems (Annex II)36 months after entry into forceExtended deadline for certain high-risk product categories

The phased rollout gives organisations time to prepare, but the window is tighter than it appears. Building compliant AI governance infrastructure — documentation systems, audit logging, human oversight controls, and risk management workflows — takes months of engineering and organisational work. Waiting until the final months before each deadline is a recipe for rushed, inadequate compliance.

Industry observers, including those tracking regulatory developments at the Centre for AI and Digital Policy, have noted that enforcement agencies are likely to prioritise high-profile cases and high-risk system categories in their initial oversight activities. However, smaller organisations should not interpret this as a reason to delay — national competent authorities across EU member states will eventually broaden their enforcement scope.

Building an Internal AI Governance Programme That Lasts

Beyond the checklist, sustainable EU AI Act compliance requires embedding AI governance into the fabric of how organisations build and procure technology. This means assigning clear ownership — whether through an AI governance officer, an expanded DPO mandate, or a cross-functional compliance team — and establishing internal review processes that activate every time a new AI tool is introduced or an existing system is significantly updated.

Developers should note that the Act's obligations attach to the system throughout its lifecycle. A system that was compliant at launch may fall out of compliance if its training data changes, its capabilities are updated, or its deployment context shifts. Continuous monitoring and version control documentation are essential engineering disciplines under this regulation.

Compliance Readiness by Sector (Estimated)

Financial Services

Originally reported by EU Digital Policy (Google News). Summarised and curated by European Purpose.