Free resource

EU AI Act Compliance Checklist

36 practical checks covering every EU AI Act obligation that binds today, plus the deadlines still ahead. Updated for the Digital Omnibus amendments that took effect in July 2026, which most published checklists do not yet reflect.

Verified against the Official Journal text on 17 August 2026

The next deadline is 2 December 2026

Two new prohibitions begin to apply, and providers of synthetic-content systems that were already on the market before 2 August 2026 must meet the machine-readable marking duty by the same date. It is the nearest binding date, and it is missing from most timelines published before the Omnibus.

What binds, and when

DateWhat appliesStatus
2 Feb 2025Prohibited practices and AI literacy dutiesIn force
2 Aug 2025General-purpose AI model obligations, governance bodies, penaltiesIn force
27 Jul 2026The Digital Omnibus amendments take effectIn force
2 Aug 2026General application: transparency, registration, and the new enforcement powersIn force
2 Dec 2026Two new prohibitions, and machine-readable marking for pre-existing synthetic-content systemsUpcoming
2 Aug 2027Legacy GPAI models compliant; national regulatory sandboxes operationalUpcoming
2 Dec 2027High-risk obligations for stand-alone Annex III systemsUpcoming
2 Aug 2028High-risk obligations for AI in Annex I regulated productsUpcoming
2 Aug 2030Backstop for legacy high-risk systems used by public authoritiesUpcoming

The deferral of the high-risk obligations carries no standards-readiness trigger and no automatic extension, so the 2027 and 2028 dates bind whether or not harmonised standards are ready. For the full picture, read our EU AI Act compliance timeline.

The checklist: 36 items across 8 sections

0 of 36 complete

Progress is saved in this browser only. Nothing is uploaded.

1. Scope and inventory

0/5

2. Prohibited practices

0/7

3. AI literacy

0/2

4. Transparency duties

0/5

5. General-purpose AI models

0/4

6. High-risk classification

0/3

7. High-risk obligations

0/6

8. Registration, governance and enforcement

0/4

Frequently asked questions

Was the EU AI Act delayed?

Only partly. Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferred the high-risk obligations in Chapter III to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. Everything else kept its original date. The prohibited practices have bound since February 2025, general-purpose AI obligations since August 2025, and the transparency duties, registration and the new enforcement powers went live on 2 August 2026.

What happens on 2 December 2026?

Two new prohibitions in Article 5 begin to apply, covering AI that generates or manipulates non-consensual intimate imagery of an identifiable person and AI that generates child sexual abuse material. The same date is the deadline for providers of synthetic-content systems that were already on the market before 2 August 2026 to meet the machine-readable marking duty.

Does the AI Act apply to companies outside the EU?

Yes. It reaches providers and deployers established outside the Union where the output produced by the AI system is used in the EU, and non-EU providers of high-risk systems must appoint an authorised representative established in the Union.

Can using someone else's AI system make us a provider?

Yes, and this is the most commonly missed exposure. Under Article 25 you become a provider, inheriting the full high-risk obligation set, if you put your own name or trademark on a high-risk system already on the market, make a substantial modification to it, or change its intended purpose so that a system becomes high-risk. The name and trademark limb applies without prejudice to any contract allocating those obligations differently. Separately, the 2026 amendments put the original provider's duty to cooperate with that new provider, and to hand over documentation and technical access, into the penalty tier of up to 15 million euro or 3 percent of worldwide turnover, so that new exposure sits with the upstream supplier rather than the party that rebranded.

What are the penalties under the EU AI Act?

Breaching the prohibited practices carries fines of up to 35 million euro or 7 percent of total worldwide annual turnover, whichever is higher. Most other operator obligations carry up to 15 million euro or 3 percent, and supplying incorrect or misleading information to authorities up to 7.5 million euro or 1 percent. Since August 2026 the AI Office can also impose periodic penalty payments of up to 5 percent of average daily worldwide turnover per day within its area of exclusive competence.

Does AI literacy still apply after the 2026 amendments?

Yes. Article 4 was rewritten but not removed. Providers and deployers must still take measures to support the development of AI literacy among staff and others operating AI on their behalf. The current wording expressly does not require you to guarantee any particular level of competence in any individual, so the evidence of compliance is the programme you run and document.

About this checklist

Prepared from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the Official Journal. Note that the EUR-Lex HTML rendering of the amending regulation is truncated, and that several widely used reference sites still serve the unamended 2024 text, so dates found elsewhere may be out of date.

This is general information, not legal advice, and it does not create a lawyer-client relationship. Obligations depend on your specific systems, role and sector. Take advice from qualified counsel before relying on any point here, and confirm against the Official Journal text.

Track the AI Act against your own systems

TimeLaw monitors the EU AI Act and every amendment to it, mapped to the systems and sectors you actually operate in, and alerts you before each deadline lands.