Skip to main content
← All posts·
Regulatory Compliance

EU AI Act Compliance Checklist: 55-Point Guide for High-Risk AI Systems [2026]

Complete EU AI Act compliance checklist for high-risk AI systems. 55 action items covering risk classification, risk management, data governance, technical documentation, transparency, human oversight, accuracy, and conformity assessment. December 2027 deadline (postponed from August 2026).

Luca Berton14 min read

How to Use This Checklist

This 55-point checklist covers the requirements for high-risk AI systems under the EU AI Act. The main compliance deadline is 2 December 2027, postponed from the original 2 August 2026 date by the EU's 2026 Digital Omnibus. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented). Focus on risk classification first — if your system isn't high-risk, many requirements don't apply.

Phase 0: Risk Classification (5 items)

Determine Your Obligations

  1. Complete AI system inventory — all AI systems deployed or in development are catalogued
  2. Each AI system classified against Annex III risk categories (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice)
  3. Prohibited AI practices reviewed — confirm no systems fall under Article 5 prohibitions
  4. Role determined for each system — are you provider, deployer, importer, or distributor?
  5. GPAI model obligations assessed — do any systems use or provide general-purpose AI models?

Phase 0 Score: ___ / 10

Phase 1: Risk Management System (Article 9) — 8 items

  1. Risk management system established as a continuous, iterative process throughout the AI system lifecycle
  2. Known and reasonably foreseeable risks identified and documented
  3. Risks estimated and evaluated, including risks from reasonably foreseeable misuse
  4. Risk mitigation measures adopted — technical, organisational, or both
  5. Residual risks documented and communicated to deployers
  6. Testing procedures defined to ensure risk management measures are effective
  7. Risk management system reviewed and updated when significant changes occur
  8. Risk management documentation maintained for regulatory inspection

Phase 1 Score: ___ / 16

📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

Phase 2: Data Governance (Article 10) — 7 items

  1. Training, validation, and testing datasets are subject to appropriate data governance practices
  2. Data relevance, representativeness, and accuracy assessed and documented
  3. Possible biases in datasets identified and addressed
  4. Data gaps or shortcomings identified with mitigation measures
  5. Special category data processing (Article 10(5)) justified and documented where used for bias detection
  6. Statistical properties of datasets documented, including intended purpose and limitations
  7. Data retention policies defined and implemented for training data

Phase 2 Score: ___ / 14

Phase 3: Technical Documentation (Article 11) — 7 items

  1. General description of the AI system including intended purpose, developer identity, and system version
  2. Detailed description of system elements: algorithms, data, training methodologies, key design choices
  3. Information on monitoring, functioning, and control of the system
  4. Description of the computational resources used (hardware, compute, training time)
  5. Validation and testing procedures documented with results
  6. Cybersecurity measures documented
  7. Technical documentation kept up-to-date throughout the system lifecycle

Phase 3 Score: ___ / 14

🎓 Course

Automating Azure DevTest Labs

Automate lab management and integrate with CI/CD pipelines.

Start on Pluralsight →

Phase 4: Record-Keeping & Logging (Article 12) — 5 items

  1. Automatic logging of events enabled throughout the AI system's operation
  2. Logging captures: operating period, reference database, input data, identity of persons involved in verification
  3. Log retention period defined (appropriate to intended purpose, at least 6 months unless regulated otherwise)
  4. Logs accessible to deployers for monitoring and post-market surveillance
  5. Logging design enables traceability of AI system decisions

Phase 4 Score: ___ / 10

Phase 5: Transparency & Information (Article 13) — 5 items

  1. Instructions for use provided to deployers — clear, accessible, and comprehensive
  2. Intended purpose and foreseeable misuse scenarios documented
  3. Level of accuracy, robustness, and cybersecurity declared with metrics
  4. Known limitations communicated, including conditions where system may not perform as intended
  5. Human oversight measures documented in instructions for use

Phase 5 Score: ___ / 10

📋 Free Resource

AI Readiness Checklist

50-point interactive checklist covering strategy, data, infrastructure, governance, and people. Score your organisation's AI readiness.

Get Free Checklist →

Phase 6: Human Oversight (Article 14) — 5 items

  1. Human oversight measures designed into the system (human-in-the-loop, human-on-the-loop, or human-in-command)
  2. Oversight persons can fully understand the AI system's capabilities and limitations
  3. Oversight persons can correctly interpret outputs and decide not to use the system
  4. Ability to override or reverse AI system decisions is implemented
  5. Ability to interrupt or stop the AI system via a "stop" button or similar procedure

Phase 6 Score: ___ / 10

Phase 7: Accuracy, Robustness & Cybersecurity (Article 15) — 5 items

  1. Accuracy levels declared and tested with appropriate metrics and benchmarks
  2. System is resilient to errors, faults, and inconsistencies in the environment
  3. Technical redundancy solutions implemented (including backup and fail-safe plans)
  4. Cybersecurity measures protect against vulnerabilities, manipulation of training data, model poisoning, and adversarial examples
  5. System resilient to attempts to alter use or performance by exploiting vulnerabilities

Phase 7 Score: ___ / 10

Phase 8: Conformity Assessment & Market Placement (Articles 16-17, 43-49) — 8 items

  1. Conformity assessment procedure identified (self-assessment for most, third-party for biometric and critical infrastructure)
  2. Quality management system established covering compliance strategy, design control, testing, and post-market monitoring
  3. EU declaration of conformity drawn up
  4. CE marking affixed to the AI system
  5. Registration in the EU database for high-risk AI systems completed
  6. Post-market monitoring system established and documented
  7. Serious incident reporting procedure established (reporting to market surveillance authorities)
  8. All documentation retained for 10 years after the AI system is placed on the market

Phase 8 Score: ___ / 16

Scoring Guide

  • 90-110: Compliance-ready. Proceed to conformity assessment.
  • 70-89: Strong foundation. Address gaps in Phases 3-4 (documentation, logging) and Phase 8 (conformity).
  • 50-69: Significant work needed. Prioritise Phase 1 (risk management) and Phase 2 (data governance) — they underpin everything else.
  • 30-49: Early stage. Focus on Phase 0 (classification) first — you may have fewer obligations than you think.
  • 0-29: Pre-compliance. The December 2027 deadline still requires immediate programme mobilisation — the extension buys time, not room for complacency.
EU AI Act
compliance checklist
high-risk AI
conformity assessment
AI governance
regulatory compliance

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →