The EU AI Act compliance checklist

Twelve steps, in the order they make sense. Written by lawyers, free to use. Work through it and you will know which steps you have covered and which you have not.

You want to know where to start, not to read the regulation. This is the sequence we use with clients: what to establish first, what depends on what, and what you can safely leave until later.

First hour’s on us. No commitment.

Establish the basics

  1. Inventory every AI system you develop, buy, embed or use — including features inside tools you did not think of as AI, such as CV screening in your recruitment platform.
  2. Determine your role for each one. Provider, deployer, importer or distributor. Note where you hold more than one.
  3. Classify each system — prohibited, high-risk under Annex I or Annex III, transparency-only, or minimal risk. Write down the reasoning, not just the conclusion.

Deal with what is already in force

  1. Check for prohibited practices. In force since February 2025. Social scoring, certain biometric categorisation, emotion recognition at work and in education, and untargeted facial-image scraping among them.
  2. Meet the AI literacy obligation (Article 4). Everyone who operates or is affected by your AI systems needs a level of understanding appropriate to their role. Document what training you gave and to whom.
  3. Cover transparency duties. Tell people when they are interacting with an AI system. Label synthetic content. Disclose emotion recognition and biometric categorisation to the people subject to it.

Prepare for the high-risk obligations

  1. Build the risk management system — identification, evaluation and mitigation across the lifecycle, not a one-off assessment.
  2. Govern your data. Training, validation and testing sets need to be relevant, representative and examined for bias. This is where most projects find their real gaps.
  3. Write the technical documentation and set up automatic logging, so a system’s behaviour can be traced after the fact.
  4. Design human oversight into the workflow, not into the policy document. Someone identifiable must be able to intervene, and must be equipped to.

Make it hold

  1. Fix the contracts. Allocate obligations between provider and deployer explicitly. Check whether branding or fine-tuning has quietly made you a provider.
  2. Connect it to GDPR, DORA and NIS2. A DPIA, an ICT risk register and an AI risk assessment overlap substantially. Build one evidence base, not four.

How to use the checklist without over-building

Most companies who go through this find that two or three systems carry almost all the obligations, and the rest carry very few. The value of steps 1 to 3 is that they tell you where to stop. A company that classifies carefully and documents its reasoning is in a considerably better position than one that applies high-risk controls everywhere and can explain none of it.

Where the deadlines now sit

The prohibitions and the AI literacy obligation applied from February 2025. General-purpose AI model obligations applied from August 2025. The high-risk obligations under Annex III now apply from December 2027, and high-risk AI in regulated products from August 2028, following the amendments adopted in 2026.

Steps 1 to 6 are about today. Steps 7 to 10 are about the window you now have.

What this checklist does not do

It does not tell you whether a specific system is high-risk. Annex III is written in categories that require interpretation, and the difference between a system that makes decisions and one that assists a decision is exactly the kind of question that gets argued. Use the checklist to structure the work; get the classification of borderline systems reviewed.

Frequently asked questions

Is this checklist enough for compliance?

It is enough to know where you stand and what to do next. It is not a substitute for classifying your specific systems, which is a legal judgement.

What happens after step 12?

For most companies, an assessment of the two or three systems that turned out to carry real obligations. That is usually a matter of weeks, not months.

Does this cover the Swedish rules as well?

The AI Act applies directly across the EU, so the substance is the same in Sweden. Enforcement and the designated national authorities are the parts that differ by country.

Can you help us work through it?

Yes. Most companies use the checklist to find the two or three points they are unsure about, and bring those to a first conversation. That conversation is free.

Worked through it?

If two or three steps left you unsure, that is exactly what a first conversation is for — and the first hour is on us.

Who you’ll work with

Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.

Related