Back to Blog
Compliance

EU AI Act Compliance Checklist for Companies Building AI (2026)

By Keyved Engineering Team··Updated ·8 min read

Short answer

The EU AI Act regulates AI by risk level. Prohibited practices have been banned since February 2025, general-purpose AI model rules applied from August 2025, and most other rules, including transparency duties and many high-risk requirements, were scheduled for 2 August 2026. To comply: inventory your AI systems, classify each by risk, confirm whether you are a provider or deployer, and implement the matching obligations.

Key takeaways

  • The Act applies to non-EU companies whose AI systems are used in the EU.
  • Obligations depend on risk category and on whether you are a provider or deployer.
  • Many business AI tools fall into limited or minimal risk — but transparency duties still apply.
  • High-risk compliance is largely engineering work: logging, oversight, testing, documentation.

The EU AI Act is the world's first comprehensive law regulating artificial intelligence, and its obligations are now arriving in stages. If your company builds or uses AI that touches people in the EU — even if you're based in the US, UK or India — it probably applies to you in some form.

The good news: for most business AI, obligations are manageable. The harder news: for high-risk uses, compliance is a substantial engineering and documentation effort that can't be done the week before a deadline.

This guide gives you a practical checklist. It's written by engineers, not lawyers, so treat it as a map for working with your legal counsel, not as legal advice. The official text is Regulation (EU) 2024/1689.

What is the EU AI Act?

The AI Act regulates AI systems according to the risk they pose to health, safety and fundamental rights. It entered into force on 1 August 2024 and applies in phases. It sets obligations for:

  • Providers: organisations that develop an AI system (or have one developed) and place it on the market or put it into service under their name
  • Deployers: organisations that use an AI system in their professional activities
  • Importers and distributors in the supply chain
  • Providers of general-purpose AI (GPAI) models, such as large language models

You can be both. If you build an AI product on top of a foundation model and sell it, you're typically a provider of that AI system. If you use it internally, you're a deployer.

Does the EU AI Act apply to non-EU companies?

Yes, in many cases. It applies to:

  • Providers placing AI systems or GPAI models on the EU market, wherever they are established
  • Deployers located in the EU
  • Providers and deployers outside the EU where the AI system's output is used in the EU

A US SaaS company selling an AI hiring tool to EU customers, or an Indian company running an AI system whose results are used by EU clients, should assume the Act is relevant.

What are the key EU AI Act deadlines?

DateWhat applies
1 August 2024Act enters into force
2 February 2025Prohibited practices banned; AI literacy obligations apply
2 August 2025Obligations for general-purpose AI models; governance and penalties framework
2 August 2026Most remaining provisions, including transparency obligations and requirements for high-risk systems listed in Annex III, as originally scheduled
2 August 2027Requirements for high-risk AI that is a safety component of regulated products (Annex I)

Timeline changes: in November 2025 the European Commission proposed a "Digital Omnibus" package that would link the start of high-risk obligations to the availability of standards and support tools, with later backstop dates. Check the current legislative status with counsel before planning around any delay. Prohibitions, AI literacy, GPAI duties and transparency obligations are not the focus of those proposed delays.

Step 1: Inventory your AI systems

You can't classify what you haven't listed. Create an inventory of every AI system you build or use, including:

  • What it does and who it affects
  • Whether it's used in, or produces output used in, the EU
  • Whether you built it, bought it or built it on a third-party model
  • What decisions it informs or makes
  • What data it uses

Include "shadow AI" — tools adopted by teams without central approval.

Step 2: Classify each system by risk

CategoryExamplesCore obligations
ProhibitedSocial scoring; manipulative techniques causing significant harm; exploiting vulnerabilities; untargeted scraping of facial images; emotion recognition in workplaces and schools (with exceptions); certain biometric categorisation and predictive policing usesBanned
High-riskAI in Annex III areas: biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services (e.g. credit scoring, some insurance pricing), law enforcement, migration, justice and democratic processes; plus safety components of regulated productsFull compliance regime (below)
Transparency obligationsChatbots and AI that interacts with people; AI-generated or manipulated content (deepfakes, synthetic audio, video, images and certain text); emotion recognition and biometric categorisationDisclosure and labelling
Minimal riskSpam filters, most internal productivity tools, recommendation engines in many contextsNo specific obligations beyond AI literacy; voluntary codes encouraged

Some Annex III systems are not considered high-risk if they don't pose a significant risk — for example, when they perform narrow procedural tasks or only improve the result of a previously completed human activity — but providers must document that assessment. AI that profiles individuals in Annex III areas remains high-risk.

Typical business AI — internal knowledge assistants, document processing, coding assistants, marketing content tools — usually lands in minimal or transparency categories. Employment, credit, insurance, education and healthcare-related uses deserve closer analysis.

Step 3: Determine your role

For each system, decide whether you're the provider, deployer or both. Note that a deployer can become a provider — for example by putting their name on a high-risk system or making a substantial modification to it.

Step 4: Meet the obligations for your category

For all organisations: AI literacy

Since February 2025, providers and deployers must take measures to ensure a sufficient level of AI literacy among staff dealing with AI systems. In practice: training appropriate to roles, plus documentation of what was done.

For transparency-obligation systems

  • Tell people they're interacting with AI unless it's obvious from context — relevant to chatbots and voice agents
  • Mark AI-generated synthetic content (audio, image, video, text) in a machine-readable way where required
  • Disclose deepfakes and AI-generated text published to inform the public on matters of public interest, with some exceptions
  • Inform people exposed to emotion recognition or biometric categorisation

For high-risk systems: provider obligations

RequirementWhat it means in engineering terms
Risk management systemA documented, ongoing process to identify, evaluate and mitigate risks across the lifecycle
Data and data governanceTraining, validation and test data that are relevant, representative and examined for bias, with documented provenance
Technical documentationDetailed description of the system, design, data, testing and performance
Record-keeping (logging)Automatic logs of events to enable traceability and monitoring
Transparency to deployersClear instructions for use, capabilities, limitations and accuracy levels
Human oversightDesign that lets people understand, monitor, override and stop the system
Accuracy, robustness and cybersecurityTested performance; resilience to errors and attacks, including AI-specific attacks
Quality management systemDocumented processes for design, development, testing and post-market monitoring
Conformity assessment, CE marking and EU database registrationBefore placing on the market
Post-market monitoring and incident reportingOngoing monitoring; report serious incidents

For high-risk systems: deployer obligations

  • Use the system according to the provider's instructions
  • Assign human oversight to competent, trained people
  • Ensure input data under your control is relevant and representative
  • Monitor operation and report risks and serious incidents
  • Keep logs generated by the system for an appropriate period (at least six months in many cases)
  • Inform workers before using high-risk AI in the workplace, and inform affected individuals where required
  • Carry out a fundamental rights impact assessment where required (for example, public bodies and certain uses such as credit scoring and life and health insurance pricing)

For general-purpose AI model providers

If you train or substantially modify a general-purpose model and place it on the market, obligations include technical documentation, information for downstream providers, a copyright policy and a summary of training content — with additional duties for models with systemic risk. Most companies building on top of models from Anthropic, OpenAI or Google are not GPAI model providers.

What are the penalties?

ViolationMaximum fine
Prohibited practicesEUR 35 million or 7% of worldwide annual turnover, whichever is higher
Most other obligationsEUR 15 million or 3%
Incorrect or misleading information to authoritiesEUR 7.5 million or 1%

For SMEs and startups, the lower of the two amounts applies in each case.

How does compliance translate into engineering work?

A lot of the high-risk requirements map directly onto good production engineering:

AI Act requirementEngineering practice
Record-keepingEnd-to-end tracing and audit logs (LLM observability)
Human oversightApproval workflows, override and stop controls (AI agent guardrails)
Accuracy and robustnessEvaluation sets, regression testing, monitoring (evaluating LLM apps)
CybersecurityThreat modelling, prompt injection defences (LLM security guide)
Data governanceData lineage, versioning, bias analysis in pipelines
Technical documentationArchitecture docs, model and prompt version history, test reports
TransparencyUI disclosures, labelled outputs, clear user instructions

Systems built this way from the start are far easier to bring into compliance than systems retrofitted later.

EU AI Act compliance checklist

  • Inventory every AI system you build or use, including third-party tools
  • Identify which systems are used in the EU or produce output used there
  • Classify each system: prohibited, high-risk, transparency, minimal
  • Document your role (provider, deployer or both) for each
  • Stop or redesign anything that could fall under prohibited practices
  • Deliver and document AI literacy training
  • Add AI disclosure to chatbots, voice agents and other interactive systems
  • Label AI-generated content where required
  • For high-risk systems: risk management, data governance, logging, human oversight, accuracy testing, cybersecurity, technical documentation and a quality management system
  • For high-risk deployments: oversight assignments, log retention, worker information and impact assessments where required
  • Review contracts with AI vendors for documentation and cooperation duties
  • Track the legislative status of timeline changes and guidance from the AI Office
  • Align with complementary frameworks (GDPR, ISO/IEC 42001, NIST AI RMF) to avoid duplicate work

How we help at Keyved

We're engineers, not lawyers — we work alongside your counsel. What we bring is the technical side of compliance: systems with audit logging, human oversight controls, evaluation and monitoring, security testing and documentation built in from day one, on our platform foundation.

If you're building an AI system that may be high-risk — in fintech, healthcare or employment, for example — or need to bring an existing one up to standard, see our AI agents service, our projects, or talk to our team.

This article is for general information and is not legal advice. Requirements depend on your specific system and circumstances, and the timeline may change; consult qualified legal counsel.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. It applies to providers placing AI systems or general-purpose AI models on the EU market, and to providers and deployers outside the EU when the output of their AI system is used in the EU, as well as to deployers located in the EU.

What are the risk categories in the EU AI Act?

The Act defines prohibited (unacceptable-risk) practices, high-risk AI systems, systems with specific transparency obligations (often called limited risk), and minimal-risk systems. It also has separate obligations for general-purpose AI models.

What counts as a high-risk AI system?

High-risk systems include AI used as a safety component of products covered by EU product safety laws, and AI used in areas listed in Annex III, such as biometrics, critical infrastructure, education, employment and worker management, access to essential services including credit scoring, law enforcement, migration and the administration of justice.

What are the penalties under the EU AI Act?

Fines can reach up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, up to EUR 15 million or 3% for many other violations, and up to EUR 7.5 million or 1% for supplying incorrect information to authorities, with lower caps for SMEs and startups in some cases.

Are chatbots regulated under the EU AI Act?

Most chatbots are not high-risk, but they are subject to transparency obligations: people must be informed that they are interacting with an AI system unless it is obvious from the context. AI-generated content such as synthetic audio, images and video must also be marked as such in certain cases.

Want to see how we build these systems for clients?

Let's Talk

Keep reading