GovernanceCore
ChecklistUpdated 2026-07-17

EU AI Act High-Risk Readiness Checklist

This checklist turns the EU AI Act's high-risk requirements into concrete, evidence-backed actions. It distinguishes provider and deployer duties, reflects the Commission's current 2027–2028 high-risk timeline, and gives governance, compliance, risk, and legal teams a practical audit record.

What you’ll get

  • How to tell whether a system is high-risk under Annex III and the narrow Article 6(3) exemption
  • The split of duties between providers and deployers, and when a deployer becomes a provider
  • Article-by-article actions for risk management, data governance, documentation, logging, and human oversight
  • Accuracy, robustness, and cybersecurity requirements you have to test and declare
  • Conformity assessment, CE marking, and EU database registration steps
  • Post-market monitoring and serious-incident reporting you need to stand up
  • Deployer-specific duties, including the fundamental rights impact assessment
Checklist

EU AI Act High-Risk Readiness Checklist

This checklist is for governance, compliance, risk, and legal teams at organizations that build, sell, or use AI systems that fall in scope of the EU AI Act as high-risk. It maps the obligations in Regulation (EU) 2024/1689 to specific actions you can check off, with the relevant article next to each one. Following the May 2026 political agreement, the Commission implementation timeline reports 2 December 2027 for Annex III high-risk rules and 2 August 2028 for high-risk systems embedded in Annex I regulated products. Confirm the final amending text before legal reliance.

It is general information, not legal advice. The AI Act sets different duties for providers and deployers, and smaller organizations get some procedural relief, so the exact obligations that apply to you depend on your role and your system. Confirm every item against the official text and, where the stakes are high, against qualified counsel.

Use it as a working document. Assign an owner to each item, record the date it was completed, and link the evidence that proves it: the risk file, the data sheet, the test result, the signed declaration. That evidence trail is what an auditor or market surveillance authority will ask to see.

55 items
01

Scope and risk classification

Work out which of your systems are high-risk and which timeline applies.

02

Roles: provider versus deployer

Fix your role for each system, because the duties differ.

03

Risk management system

Stand up a lifecycle risk process and keep it running.

04

Data and data governance

Document your data sets and show they are fit for purpose.

05

Technical documentation and logging

Produce the Annex IV file and build in event logging.

06

Transparency and human oversight

Give deployers usable information and design in real oversight.

07

Accuracy, robustness, and cybersecurity

Test performance, resilience, and security, and declare the levels.

08

Quality management, conformity assessment, and registration

Formalize your quality system, prove conformity, and register.

09

Post-market monitoring, incidents, and deployer duties

Monitor systems in the field, report incidents, and meet deployer obligations.

This checklist is general information, not legal advice. The EU AI Act splits obligations between providers and deployers, gives smaller organizations some procedural relief, and leaves detail to be filled in by standards, guidance, and implementing acts that continue to develop. Confirm each item against the official text of Regulation (EU) 2024/1689 and, for high-stakes decisions, with qualified counsel before you rely on it.