Guides 10 min read

Countdown to August 2026: The Complete High-Risk AI Compliance Checklist

With less than a year until the main high-risk AI deadline, here's the definitive guide to provider obligations under Articles 9-17, conformity assessment, and registration requirements.

By Jessica Chen · Published

The Big Deadline Approaches

August 2, 2026 is the compliance cliff for most high-risk AI systems under Annex III. If you're a provider of AI used in biometrics, critical infrastructure, employment, education, essential services, or law enforcement, your countdown has begun.

The 10 Provider Obligations

1. Risk Management System (Article 9)

  • Identify and analyze known/foreseeable risks
  • Estimate and evaluate risks from intended use
  • Assess risks from reasonably foreseeable misuse
  • Continuous iterative process throughout AI lifecycle

2. Data Governance (Article 10)

  • Training, validation, testing datasets must be relevant and representative
  • Datasets must be free from errors (to best extent possible)
  • Data governance practices to prevent bias

3. Technical Documentation (Article 11, Annex IV)

  • General system description, intended purpose, hardware requirements
  • Detailed development process (design specs, training methodology)
  • Risk management documentation
  • Validation/testing procedures and metrics
  • Human oversight measures assessment
  • List of harmonized standards applied

4. Record-Keeping & Logging (Article 12)

  • Automatic event recording throughout lifecycle
  • Enable identification of risks and substantial modifications
  • Logs kept minimum 6 months by deployers

5. Transparency & Instructions (Article 13)

  • Provide clear instructions for use to deployers
  • Enable deployers to understand system outputs
  • Information to support GDPR impact assessments

6. Human Oversight (Article 14)

Design systems to allow humans to understand system capabilities and limitations, monitor operation and detect anomalies, intervene or interrupt system operation, and decide not to use or disregard system output.

7. Accuracy, Robustness & Cybersecurity (Article 15)

  • Achieve appropriate accuracy levels
  • Robust against errors, faults, inconsistencies
  • Resilient to adversarial attacks
  • Adequate cybersecurity protection

8. Quality Management System (Article 17)

  • Documented system ensuring AI Act compliance
  • Covers design, development, quality control, post-market monitoring

9. Conformity Assessment (Article 43)

  • Most Annex III systems: Internal control (self-assessment)
  • Certain biometrics/regulated products: Notified Body required

10. CE Marking, Declaration & Registration (Articles 47-49)

  • Issue EU Declaration of Conformity
  • Affix CE marking to system/packaging/documentation
  • Register in EU database before market placement

Deployer Obligations (Article 26)

Organizations using high-risk AI must: follow provider's instructions, assign competent human oversight personnel, monitor input data relevance, keep automatically generated logs (minimum 6 months), report identified risks immediately, inform workers before deployment, conduct Fundamental Rights Impact Assessment (public sector).

Don't Wait for Guidance

The Commission will publish detailed implementation guidelines—but that's too late to start. Begin your compliance journey now, and refine as guidance emerges.