EU AI Act compliance checklist for enterprise teams
EU AI Act readiness starts with the system's purpose and your organization's role. Inventory the system, assess prohibited and high-risk uses, identify applicable duties, then assign owners and evidence. Paul Okhrem's checklist supports that work. It is not legal advice, a complete statement of the law or proof that a system complies.
Which dates should the team verify?
The European Commission's implementation timeline, checked in September 2026, reflects the AI Omnibus amendments. Different duties have different dates.
| Milestone | Date | Planning point |
|---|---|---|
| Initial general provisions and prohibitions | 2 February 2025 | Already applicable; check later amendments |
| General-purpose AI model rules | 2 August 2025 | Check provider duties and transition provisions |
| Transparency rules under Article 50 | 2 August 2026 | Check the system and any specific transition |
| Specified new prohibitions and certain Article 50(2) transitions | 2 December 2026 | Not a blanket extension for all AI obligations |
| Annex III high-risk systems | 2 December 2027 | Check classification and exceptions |
| High-risk systems embedded in regulated Annex I products | 2 August 2028 | Coordinate AI and product compliance work |
The Commission's AI Omnibus notice also describes changes to AI-literacy provisions. Do not treat an old Article 4 summary as a current universal training rule. Qualified legal advisers should confirm the text, role-specific duties and transitions for your case.
Twelve checks to organize the work
For every item, record the actual decision and evidence. “Not applicable” needs a reason; “in progress” needs an owner and due date.
- Inventory. List purchased, embedded and internally built AI systems. Lead: system owner. Evidence: inventory with intended purpose and users.
- Role. Determine whether the organization is a provider, deployer or another actor for each system. Lead: legal and procurement. Evidence: written role assessment; contracts.
- Scope. Check where the rules apply, including affected users and markets. Lead: legal. Evidence: scope rationale and jurisdictions.
- Prohibitions. Screen the intended use against prohibited practices. Lead: legal and risk. Evidence: documented assessment; stop decision where needed.
- Risk classification. Assess whether the use falls into a high-risk category and document any exception rationale. Lead: legal and business owner. Evidence: classification with relevant legal references.
- Transparency. Identify required user notices and synthetic-content controls. Lead: product and legal. Evidence: notices, technical measures and tests.
- Supplier evidence. Obtain instructions, limitations, change notices and required documentation. Lead: procurement and technical owner. Evidence: supplier evidence file and contract terms.
- Data and security. Review data rights, privacy duties, access and security controls. Lead: privacy and security. Evidence: data-flow map and control evidence.
- Human oversight. Define who can review, override and stop the system. Lead: business owner. Evidence: operating process and role-appropriate training.
- Testing and documentation. Plan the evidence needed for the applicable role and risk category. Lead: technical and risk owners. Evidence: evaluation, records and any required conformity evidence.
- Monitoring and incidents. Set operating monitoring, record retention and reporting routes. Lead: operations and legal. Evidence: monitoring plan and tested escalation procedure.
- Dates and sign-off. Confirm application dates, transition rules and readiness decisions. Lead: accountable executive and legal. Evidence: dated obligation register with owners and deadlines.
Avoid three common planning mistakes
Do not classify only by the model name
A general-purpose model used in two workflows can create different risks and duties. Record intended use, users, affected people and the decisions the system supports.
Do not outsource accountability to a vendor badge
A supplier's certificate or security report may be relevant evidence. It does not establish that your particular use complies with all applicable rules.
Do not assume a later deadline means no action is needed
Other AI Act provisions, privacy rules, sector rules and contracts may already apply. Use an obligation register, not one launch date for everything.
Download the EU AI Act working checklist
Download the editable CSV checklist. The file leaves legal references and due dates for your qualified reviewers to confirm. It is an original planning aid, not the text of the regulation.
Pair it with the AI risk assessment, governance framework and staff AI policy template.
Implementation support from Paul Okhrem
Paul Okhrem's EU AI Act consulting supports inventory, governance design, evidence organization and implementation oversight. Legal counsel owns legal interpretation; specialist assessors handle formal assessments where required.
For a wider operating model, use AI governance consulting. Share the use case, current system stage and market scope rather than sending sensitive personal data in the enquiry form.
Questions about eu ai act compliance checklist for enterprise teams
Does this checklist cover every EU AI Act obligation?
No. It is a planning aid. Duties depend on your role, system, intended use, risk category and transition provisions. Use the current law and qualified legal advice.
Are all high-risk AI rules delayed to the same date?
No. The official amended timeline distinguishes Annex III systems from high-risk AI embedded in regulated Annex I products. Other provisions have separate application dates.
Can Paul Okhrem issue a compliance certificate?
No. Paul supports governance and implementation readiness. This service does not replace legal counsel, a conformity assessment or an authorized certification process.
Change log
- : Reviewed copy, source boundaries and supporting resources.
Send a private brief to Paul Okhrem

Paul Okhrem reads every brief personally and replies within two business days. Start with the decision, its owner and the deadline. You will get an honest no if the fit is wrong, with a referral when possible.
Co-Founder and CEO of Elogic Commerce; Managing Partner at Uvik Software. Company experience is not a guarantee of a consulting result. Read the background and published terms.