Guides
10 min read
The Ultimate August 2026 AI Act Compliance Checklist
Six months until the main enforcement deadline. Here's your comprehensive checklist covering high-risk systems, GPAI, transparency, and documentation requirements.
By AI Act Compass Editorial Team
·
Published
The Clock Is Ticking
August 2, 2026 is the compliance cliff for most AI Act obligations. Whether you're a provider, deployer, importer, or distributor, this checklist covers everything you need to have in place.
Part 1: AI Inventory & Classification
- Complete inventory of all AI systems developed, deployed, imported, or distributed
- Each system classified by risk tier (prohibited, high-risk, limited-risk, minimal)
- Article 6(3) filter exception assessments documented (where applicable)
- Your organization's role determined for each system (provider, deployer, importer, distributor)
- GPAI models identified and classified (standard vs. systemic risk)
Part 2: High-Risk AI Systems (Providers)
- Risk Management System established (Article 9)
- Data Governance framework in place (Article 10)
- Technical Documentation complete per Annex IV (Article 11)
- Automatic logging capabilities implemented (Article 12)
- Instructions for Use prepared for deployers (Article 13)
- Human Oversight mechanisms designed into system (Article 14)
- Accuracy, robustness, and cybersecurity requirements met (Article 15)
- Quality Management System documented (Article 17)
- Conformity Assessment completed (Article 43)
- EU Declaration of Conformity issued (Article 47)
- CE marking affixed (Article 48)
- Registration in EU database completed (Article 49)
- Post-market monitoring plan established
Part 3: High-Risk AI Systems (Deployers)
- Instructions for Use obtained from provider and followed (Article 26)
- Competent human oversight personnel assigned and trained
- Input data quality monitoring in place
- Automatic logs retained (minimum 6 months)
- Risk reporting procedures to provider/authorities established
- Workers informed before AI deployment (where applicable)
- Fundamental Rights Impact Assessment completed (public sector)
Part 4: GPAI Model Providers
- Technical documentation maintained (Article 53)
- Public training data summary published (using EU template)
- Copyright policy implemented with opt-out mechanism
- Instructions for downstream providers prepared
- Code of Practice signed (optional but recommended)
- For Systemic Risk GPAI: Systemic risk assessment completed, adversarial testing performed, incident reporting procedures in place, cybersecurity protections implemented, AI Office notification submitted
Part 5: Transparency Obligations
- Chatbot/conversational AI disclosures implemented
- Emotion recognition disclosures in place (where applicable)
- AI-generated content labeling implemented (deepfakes, synthetic media)
- EU common icon integration planned (when finalized)
- Technical watermarking considered for generated content
Part 6: Organizational Readiness
- AI literacy training completed for all relevant staff (Article 4)
- AI governance roles and responsibilities assigned
- Compliance budget allocated
- External legal/technical advisors engaged (if needed)
- National competent authority identified for your operations
- Incident response procedures documented
- Vendor contracts updated with AI Act compliance clauses
Don't Go It Alone
This checklist is comprehensive but not exhaustive. Each organization's situation is unique. Engage qualified legal and technical advisors to ensure you're fully compliant.
Need help finding a compliance expert? Search our verified directory of EU AI Act consultants.