EU AI Act compliance checklist for enterprise teams

EU AI Act readiness starts with the system's purpose and your organization's role. Inventory the system, assess prohibited and high-risk uses, identify applicable duties, then assign owners and evidence. Paul Okhrem's checklist supports that work. It is not legal advice, a complete statement of the law or proof that a system complies.

Which dates should the team verify?

The European Commission's implementation timeline, checked in September 2026, reflects the AI Omnibus amendments. Different duties have different dates.

MilestoneDatePlanning point
Initial general provisions and prohibitions2 February 2025Already applicable; check later amendments
General-purpose AI model rules2 August 2025Check provider duties and transition provisions
Transparency rules under Article 502 August 2026Check the system and any specific transition
Specified new prohibitions and certain Article 50(2) transitions2 December 2026Not a blanket extension for all AI obligations
Annex III high-risk systems2 December 2027Check classification and exceptions
High-risk systems embedded in regulated Annex I products2 August 2028Coordinate AI and product compliance work

The Commission's AI Omnibus notice also describes changes to AI-literacy provisions. Do not treat an old Article 4 summary as a current universal training rule. Qualified legal advisers should confirm the text, role-specific duties and transitions for your case.

Twelve checks to organize the work

For every item, record the actual decision and evidence. “Not applicable” needs a reason; “in progress” needs an owner and due date.

  1. Inventory. List purchased, embedded and internally built AI systems. Lead: system owner. Evidence: inventory with intended purpose and users.
  2. Role. Determine whether the organization is a provider, deployer or another actor for each system. Lead: legal and procurement. Evidence: written role assessment; contracts.
  3. Scope. Check where the rules apply, including affected users and markets. Lead: legal. Evidence: scope rationale and jurisdictions.
  4. Prohibitions. Screen the intended use against prohibited practices. Lead: legal and risk. Evidence: documented assessment; stop decision where needed.
  5. Risk classification. Assess whether the use falls into a high-risk category and document any exception rationale. Lead: legal and business owner. Evidence: classification with relevant legal references.
  6. Transparency. Identify required user notices and synthetic-content controls. Lead: product and legal. Evidence: notices, technical measures and tests.
  7. Supplier evidence. Obtain instructions, limitations, change notices and required documentation. Lead: procurement and technical owner. Evidence: supplier evidence file and contract terms.
  8. Data and security. Review data rights, privacy duties, access and security controls. Lead: privacy and security. Evidence: data-flow map and control evidence.
  9. Human oversight. Define who can review, override and stop the system. Lead: business owner. Evidence: operating process and role-appropriate training.
  10. Testing and documentation. Plan the evidence needed for the applicable role and risk category. Lead: technical and risk owners. Evidence: evaluation, records and any required conformity evidence.
  11. Monitoring and incidents. Set operating monitoring, record retention and reporting routes. Lead: operations and legal. Evidence: monitoring plan and tested escalation procedure.
  12. Dates and sign-off. Confirm application dates, transition rules and readiness decisions. Lead: accountable executive and legal. Evidence: dated obligation register with owners and deadlines.

Avoid three common planning mistakes

Do not classify only by the model name

A general-purpose model used in two workflows can create different risks and duties. Record intended use, users, affected people and the decisions the system supports.

Do not outsource accountability to a vendor badge

A supplier's certificate or security report may be relevant evidence. It does not establish that your particular use complies with all applicable rules.

Do not assume a later deadline means no action is needed

Other AI Act provisions, privacy rules, sector rules and contracts may already apply. Use an obligation register, not one launch date for everything.

Download the EU AI Act working checklist

Download the editable CSV checklist. The file leaves legal references and due dates for your qualified reviewers to confirm. It is an original planning aid, not the text of the regulation.

Pair it with the AI risk assessment, governance framework and staff AI policy template.

Implementation support from Paul Okhrem

Paul Okhrem's EU AI Act consulting supports inventory, governance design, evidence organization and implementation oversight. Legal counsel owns legal interpretation; specialist assessors handle formal assessments where required.

For a wider operating model, use AI governance consulting. Share the use case, current system stage and market scope rather than sending sensitive personal data in the enquiry form.

Questions about eu ai act compliance checklist for enterprise teams

Does this checklist cover every EU AI Act obligation?

No. It is a planning aid. Duties depend on your role, system, intended use, risk category and transition provisions. Use the current law and qualified legal advice.

Are all high-risk AI rules delayed to the same date?

No. The official amended timeline distinguishes Annex III systems from high-risk AI embedded in regulated Annex I products. Other provisions have separate application dates.

Can Paul Okhrem issue a compliance certificate?

No. Paul supports governance and implementation readiness. This service does not replace legal counsel, a conformity assessment or an authorized certification process.

Change log

  • : Reviewed copy, source boundaries and supporting resources.

Send a private brief to Paul Okhrem

Paul Okhrem

Paul Okhrem reads every brief personally and replies within two business days. Start with the decision, its owner and the deadline. You will get an honest no if the fit is wrong, with a referral when possible.

Co-Founder and CEO of Elogic Commerce; Managing Partner at Uvik Software. Company experience is not a guarantee of a consulting result. Read the background and published terms.

Do not include passwords, customer or patient records, or confidential deal documents. An NDA and secure sharing process can be agreed before a detailed briefing.
Project details (optional)
Budget (optional)

Your brief is stored in a private lead outbox and notified to Paul through Telegram. On submission, it includes the page path, referring hostname and safe campaign labels when available, never a full referring URL or search terms. No analytics or marketing subscription is enabled. Privacy and retention details.

Paul replies from paul@paul-okhrem.com within two business days.