Get a demo →Book a meeting
Blog
GovernanceCompliance

The EU AI Act Compliance Checklist for Enterprises

In short

The EU AI Act is a risk-based regulation, in force since August 2024 and phasing in through 2027. It sorts AI into four tiers — unacceptable (banned), high-risk, limited-risk (transparency duties), and minimal-risk — and puts the heaviest obligations on high-risk systems, whose core requirements apply from 2 August 2026. Compliance comes down to knowing your tier, meeting the obligations for it, and being able to show the evidence.

Key takeaways

  • The EU AI Act is risk-based: unacceptable (banned), high-risk (heavy obligations), limited-risk (transparency), minimal-risk (little to none).
  • Key dates: prohibited practices applied Feb 2025, general-purpose AI obligations Aug 2025, most high-risk obligations 2 August 2026.
  • Penalties reach €35M or 7% of global annual turnover for prohibited-use violations — the highest tier of fines.
  • It applies extraterritorially: if your AI’s output is used in the EU, you’re likely in scope even from outside it.
  • Auditors want evidence, not policies. The hard part is proving what your AI did — which is a logging and governance problem.

The EU AI Act stopped being a future problem a while ago. Prohibited practices have been enforceable since early 2025, general-purpose model rules since that August, and the big one — the core obligations for high-risk systems — lands on 2 August 2026. Most enterprises I talk to are further behind on it than they think, usually because they can’t answer the first question the Act asks: what AI are you actually running?

This is a working checklist, not a legal brief — confirm specifics with your counsel. But it will get your compliance and AI teams pointed at the right work.

What is the EU AI Act?

The EU AI Act is a risk-based regulation of artificial intelligence, in force since August 2024 and phasing in through 2027. It sorts AI systems into four tiers by the risk they pose and attaches obligations accordingly: unacceptable-risk uses are banned outright, high-risk uses carry a heavy obligation set, limited-risk uses owe transparency, and minimal-risk uses are largely unaffected. Get your tier right and the rest of the work follows from it.

The deadlines that matter

DateWhat applies
Aug 2024The Act enters into force
Feb 2025Prohibited (unacceptable-risk) practices banned
Aug 2025General-purpose AI (GPAI) model obligations apply
2 Aug 2026Core high-risk system obligations apply
Aug 2027High-risk AI embedded in regulated products

Which risk tier are you in?

Work top-down. Are you using AI for anything the Act prohibits — such as social scoring or certain biometric practices? Stop; that’s banned. If not, does your AI operate in a high-risk area — employment, credit and insurance, essential services, education, biometrics, critical infrastructure, or as a safety component of a regulated product? If so, the full obligation set applies. If your AI mainly interacts with people (a chatbot, or generated content), you likely owe transparency duties. Everything else is minimal-risk.

The compliance checklist

For high-risk systems, this is the core of what providers must have in place — and the evidence auditors will ask to see.

  • Risk management system — a documented, ongoing process across the AI system’s lifecycle.
  • Data governance — training, validation, and test data managed for quality, relevance, and bias.
  • Technical documentation — enough to demonstrate conformity, kept current.
  • Record-keeping / logging — automatic logs of the system’s operation, retained and traceable.
  • Transparency and instructions — deployers given the information to use the system correctly.
  • Human oversight — designed-in ability for people to intervene and override.
  • Accuracy, robustness, cybersecurity — appropriate to the system’s purpose and risk.
  • Conformity assessment + registration — assessed before market, registered in the EU database.
  • Post-market monitoring — ongoing tracking and incident reporting after deployment.

If you’re a deployer rather than the provider, your list is shorter but real: use the system per instructions, ensure human oversight, monitor operation, keep the logs you generate, and — in many cases — run a fundamental-rights impact assessment.

The part most teams underestimate: evidence

Here’s the trap. Teams write policies, file documentation, and feel compliant — then an auditor asks the real question: show me exactly what the AI did. Which data did it see, what did it output, who approved the sensitive actions, and can you prove it? Policies describe intent. Auditors want the record.

That’s why AI Act readiness is, underneath the paperwork, a logging and governance problem. An immutable audit ledger of every request, decision, and approval is what turns “we have a policy” into “here is the evidence.” When governance is enforced in the request path rather than reviewed after the fact, the record is a byproduct of running the system, not a scramble before an audit — and it’s the same evidence base a GxP environment demands.

How to get ahead of it

Start where the Act does: with an inventory. You can’t classify, document, or govern AI you can’t see, and in most enterprises the real number of AI tools in use is far higher than IT’s official count — the shadow AI problem is the AI Act problem wearing different clothes. An inventory that finds every tool, contract, and shadow deployment is both the first compliance step and the fastest way to shrink your risk surface. Score where you stand with the Readiness Scorecard, and the deadline stops feeling like a cliff.

Frequently asked questions

When does the EU AI Act take effect?
It entered into force in August 2024 and phases in over time. Prohibited practices applied from February 2025, general-purpose AI model obligations from August 2025, and the core obligations for high-risk systems apply from 2 August 2026, with certain high-risk systems embedded in regulated products following in 2027. The dates are staggered by risk tier, so your relevant deadline depends on what kind of AI you run.
What are the penalties under the EU AI Act?
Fines are tiered. Using AI for a prohibited purpose can draw up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Most other obligation breaches reach up to €15 million or 3% of turnover, and supplying incorrect or misleading information to authorities up to €7.5 million or 1%. These are among the steepest penalties in technology regulation.
Does the EU AI Act apply to companies outside the EU?
Often, yes. Like GDPR, it has extraterritorial reach: it applies to providers and deployers outside the EU when the output of their AI system is used within the EU. A US or UK company whose AI serves EU users or informs EU decisions can be in scope, which is why non-EU enterprises can’t treat it as someone else’s problem.
What counts as a high-risk AI system?
High-risk covers AI used as a safety component of regulated products, and AI in specified sensitive areas — such as employment and worker management, access to essential services, credit and insurance, education, biometrics, critical infrastructure, and law enforcement. If your AI materially influences decisions in those areas, plan on the full high-risk obligation set: risk management, data governance, documentation, logging, human oversight, and conformity assessment.

Start with the inventory the Act requires anyway.

The first obligation under the AI Act is knowing what AI you run. SphereIQ Governance enforces policy and keeps the audit ledger — and the AI Spend Diagnostic doubles as your EU AI Act inventory baseline.