This checklist is for governance, compliance, risk, and legal teams at organizations that build, sell, or use AI systems that fall in scope of the EU AI Act as high-risk. It maps the obligations in Regulation (EU) 2024/1689 to specific actions you can check off, with the relevant article next to each one. Following the May 2026 political agreement, the Commission implementation timeline reports 2 December 2027 for Annex III high-risk rules and 2 August 2028 for high-risk systems embedded in Annex I regulated products. Confirm the final amending text before legal reliance.
It is general information, not legal advice. The AI Act sets different duties for providers and deployers, and smaller organizations get some procedural relief, so the exact obligations that apply to you depend on your role and your system. Confirm every item against the official text and, where the stakes are high, against qualified counsel.
Use it as a working document. Assign an owner to each item, record the date it was completed, and link the evidence that proves it: the risk file, the data sheet, the test result, the signed declaration. That evidence trail is what an auditor or market surveillance authority will ask to see.
01
Scope and risk classification Work out which of your systems are high-risk and which timeline applies.
Build an inventory of every AI system you develop, buy, or operate Record each system's intended purpose, who uses it, what decisions it informs, and what data it processes. You cannot classify what you have not listed. EU AI Act Art. 3 Check each system against the Annex III high-risk categories Annex III covers use cases such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and administration of justice. EU AI Act Art. 6, Annex III Check whether a system is a safety component of a regulated product Systems covered by the Union harmonization laws in Annex I can also be high-risk. The Commission implementation timeline reports 2 August 2028 following the May 2026 political agreement; confirm the final amending text. EU AI Act Art. 6(1), Annex I Document any Article 6(3) exemption you rely on An Annex III system may not be high-risk if it performs a narrow procedural task and does not pose a significant risk of harm. If you claim this, write down the assessment and keep it on file, and register the system. EU AI Act Art. 6(3) Confirm the application date that applies to your system The Commission implementation timeline reports 2 December 2027 for Annex III high-risk rules following the May 2026 political agreement. Confirm the final amending text and map each system to its applicable deadline. EU AI Act Art. 113 Flag any general-purpose AI models you provide Obligations for general-purpose AI models have applied since 2 August 2025 and are separate from the high-risk regime. Note where a general-purpose model feeds one of your high-risk systems. EU AI Act Art. 51-55 02
Roles: provider versus deployer Fix your role for each system, because the duties differ.
Decide, per system, whether you are the provider, the deployer, or both The provider develops or has a system developed and places it on the market under its own name. The deployer uses the system under its own authority. Many organizations are both, on different systems. EU AI Act Art. 3 Watch for the acts that turn a deployer into a provider Putting your name or trademark on a high-risk system, substantially modifying it, or changing its intended purpose so it becomes high-risk can make you a provider with the full set of provider duties. EU AI Act Art. 25 Appoint an EU authorized representative if you are a provider based outside the EU The representative must be established in the Union and hold a written mandate to act on your behalf toward authorities. EU AI Act Art. 22 List the full set of provider obligations you carry Article 16 gathers the provider duties in one place, from the quality management system through documentation, registration, and conformity. Use it as your master list. EU AI Act Art. 16 List the deployer obligations separately Deployer duties are set out on their own and do not mirror provider duties. Keep the two lists apart so nothing is assumed to be someone else's job. EU AI Act Art. 26 Put written agreements in place across the value chain Suppliers of tools, services, components, and data used in a high-risk system must give you the information and access you need to meet your obligations. Record this in contracts. EU AI Act Art. 25(4) 03
Risk management system Stand up a lifecycle risk process and keep it running.
Establish a documented risk management system for the system's whole lifecycle It must be a continuous, planned process that runs from design through post-market use, not a one-time review. EU AI Act Art. 9(1-2) Identify and analyze known and reasonably foreseeable risks Cover risks to health, safety, and fundamental rights that the system can pose when used as intended and under reasonably foreseeable misuse. EU AI Act Art. 9(2) Adopt risk measures and confirm residual risk is judged acceptable Design out risks where you can, mitigate what remains, and provide information and training for the rest. Document why the residual risk is acceptable. EU AI Act Art. 9(5) Test the system against defined metrics before and during use Testing must confirm the system performs as intended and that measures work. Run it at points through development and before placing on the market. EU AI Act Art. 9(6-8) Assess impact on people under 18 and other vulnerable groups Where the system is likely to affect children or vulnerable people, the risk system has to take that into account. EU AI Act Art. 9(9) Review and update the risk management system on a regular basis New information from use, monitoring, and incidents should feed back into the risk file and the measures. EU AI Act Art. 9(2) 04
Data and data governance Document your data sets and show they are fit for purpose.
Document the training, validation, and test data sets Record their origin, how they were collected, and the data preparation steps such as labeling, cleaning, and aggregation. EU AI Act Art. 10(2) Examine the data for possible bias Look for bias that could affect health, safety, or fundamental rights, or that could lead to prohibited discrimination, and record what you find. EU AI Act Art. 10(2)(f-g) Confirm data sets are relevant, representative, and as error-free as possible Check that data has the right properties for the intended purpose and is sufficiently representative of the people and settings the system will act on. EU AI Act Art. 10(3) Record data gaps and shortcomings and how you handle them No data set is perfect. Document known limitations and the steps you take to manage them. EU AI Act Art. 10(2) Document safeguards if you process special-category data to correct bias The Act allows processing sensitive data to detect and correct bias, but only with specific protections in place. Record those protections. EU AI Act Art. 10(5) Account for the setting the system will operate in Consider the geographic, contextual, behavioral, or functional setting the system is intended for when judging whether the data fits. EU AI Act Art. 10(4) 05
Technical documentation and logging Produce the Annex IV file and build in event logging.
Draw up technical documentation before the system goes to market It has to demonstrate that the system meets the high-risk requirements and give authorities the information they need to assess it. EU AI Act Art. 11, Annex IV Cover every element Annex IV lists This includes the general description, the design and development detail, the monitoring and control information, and the risk management steps taken. EU AI Act Annex IV Keep the documentation current and retain it for 10 years Providers must keep the technical documentation at the disposal of authorities for 10 years after the system is placed on the market or put into service. EU AI Act Art. 18 Design the system to record events automatically over its lifetime High-risk systems must technically allow the automatic recording of logs while operating. EU AI Act Art. 12 Confirm logging supports traceability and incident review Logs need to be detailed enough to identify situations that may create risk, support post-market monitoring, and help investigate incidents. EU AI Act Art. 12(2) Retain the logs under your control as a provider Keep the automatically generated logs for a period appropriate to the intended purpose, at least six months unless other law says otherwise. EU AI Act Art. 19 06
Transparency and human oversight Give deployers usable information and design in real oversight.
Write instructions for use that reach deployers Provide concise, clear instructions in a language the deployer understands, containing the information Article 13 requires. EU AI Act Art. 13 State purpose, accuracy, limitations, and foreseeable misuse in the instructions Include the intended purpose, the accuracy and relevant metrics, known limitations, and any use that could create risk. EU AI Act Art. 13(3) Make the system transparent enough for deployers to interpret output Design and develop the system so its operation is sufficiently clear for deployers to understand and use the results correctly. EU AI Act Art. 13(1) Build in human oversight measures matched to the risks Provide the tools and design features that let assigned people oversee the system while it is in use. EU AI Act Art. 14 Enable oversight staff to understand, monitor, and intervene Oversight people must be able to grasp the system's capacity and limits, stay alert to automation bias, interpret output, decide not to use it, and stop the system. EU AI Act Art. 14(4) Apply the two-person rule for relevant biometric identification For certain remote biometric identification systems, no action may be taken unless the result is verified and confirmed by at least two competent people. EU AI Act Art. 14(5) 07
Accuracy, robustness, and cybersecurity Test performance, resilience, and security, and declare the levels.
Declare accuracy levels and relevant metrics in the instructions for use State the levels the system is designed to achieve and the metrics used to measure them. EU AI Act Art. 15(3) Test that the system performs consistently across its lifecycle The system has to achieve an appropriate level of accuracy and perform consistently throughout its use. EU AI Act Art. 15(1) Build resilience against errors, faults, and inconsistencies Address faults that can arise within the system or its environment, using technical measures such as backup or fail-safe plans where appropriate. EU AI Act Art. 15(4) Manage feedback loops in systems that keep learning Systems that continue to learn after deployment must be designed to reduce the risk of biased outputs from feedback loops, with mitigation in place. EU AI Act Art. 15(4) Protect the system against attempts to exploit vulnerabilities Put cybersecurity measures in place so the system resists attempts to alter its use, output, or performance. EU AI Act Art. 15(5) Guard against data poisoning, model poisoning, and adversarial attacks Where relevant, measures should address data or model poisoning, adversarial examples, model evasion, and attacks on confidentiality. EU AI Act Art. 15(5) 08
Quality management, conformity assessment, and registration Formalize your quality system, prove conformity, and register.
Put a documented quality management system in place Providers must operate a quality management system covering the strategies, procedures, resources, and responsibilities Article 17 lists. EU AI Act Art. 17 Stand up a single system of record with a live inventory linked to its evidence Keep a current inventory of your AI systems where each one links to its documentation, logs, test results, and assessments, so evidence is ready when asked for rather than reassembled under pressure. EU AI Act Art. 17 Carry out the conformity assessment that applies to your system Depending on the system, this is either an internal control procedure or an assessment involving a notified body. Complete it before placing on the market. EU AI Act Art. 43 Draw up and sign the EU declaration of conformity The declaration states that the system meets the requirements. Keep it for 10 years and provide it to authorities on request. EU AI Act Art. 47 Affix the CE marking The CE marking shows the high-risk system conforms with the AI Act. Apply it visibly, or in digital form where the system has no physical product. EU AI Act Art. 48 Register the system and yourself in the EU database Before placing an Annex III high-risk system on the market or putting it into service, the provider registers it and the required data in the EU database. EU AI Act Art. 49, Art. 71 09
Post-market monitoring, incidents, and deployer duties Monitor systems in the field, report incidents, and meet deployer obligations.
Set up a post-market monitoring system Collect and review data on how the system performs in the field throughout its life, and feed findings back into the risk system. EU AI Act Art. 72 Establish a serious-incident reporting procedure Providers must report serious incidents to the relevant market surveillance authority within the deadlines the Act sets, and know who is responsible for filing. EU AI Act Art. 73 Prepare corrective actions and a withdrawal or recall route Where a system does not conform, you must be able to bring it into conformity, withdraw it, or recall it, and inform the relevant parties. EU AI Act Art. 20 As a deployer, use the system per the instructions and assign competent oversight Deployers must operate the system in line with the instructions for use and assign human oversight to people with the competence, training, and authority to do it. EU AI Act Art. 26(1-2) As a deployer, keep logs and monitor operation Keep the automatically generated logs under your control for at least six months, and monitor the system, alerting the provider or authority when you spot a risk or a serious incident. EU AI Act Art. 26(5-6) As a deployer at work, inform workers and their representatives Before putting a high-risk system into use in the workplace, tell affected workers and their representatives that they will be subject to it. EU AI Act Art. 26(7) Complete a fundamental rights impact assessment where required Certain deployers, including public bodies and providers of public services, and deployers of specified Annex III systems such as creditworthiness and insurance risk assessment, must complete a fundamental rights impact assessment before first use. EU AI Act Art. 27 This checklist is general information, not legal advice. The EU AI Act splits obligations between providers and deployers, gives smaller organizations some procedural relief, and leaves detail to be filled in by standards, guidance, and implementing acts that continue to develop. Confirm each item against the official text of Regulation (EU) 2024/1689 and, for high-stakes decisions, with qualified counsel before you rely on it.