The EU AI Act Compliance Checklist for Enterprises
The EU AI Act is a risk-based regulation, in force since August 2024 and phasing in through 2027. It sorts AI into four tiers — unacceptable (banned), high-risk, limited-risk (transparency duties), and minimal-risk — and puts the heaviest obligations on high-risk systems, whose core requirements apply from 2 August 2026. Compliance comes down to knowing your tier, meeting the obligations for it, and being able to show the evidence.
Key takeaways
- The EU AI Act is risk-based: unacceptable (banned), high-risk (heavy obligations), limited-risk (transparency), minimal-risk (little to none).
- Key dates: prohibited practices applied Feb 2025, general-purpose AI obligations Aug 2025, most high-risk obligations 2 August 2026.
- Penalties reach €35M or 7% of global annual turnover for prohibited-use violations — the highest tier of fines.
- It applies extraterritorially: if your AI’s output is used in the EU, you’re likely in scope even from outside it.
- Auditors want evidence, not policies. The hard part is proving what your AI did — which is a logging and governance problem.
The EU AI Act stopped being a future problem a while ago. Prohibited practices have been enforceable since early 2025, general-purpose model rules since that August, and the big one — the core obligations for high-risk systems — lands on 2 August 2026. Most enterprises I talk to are further behind on it than they think, usually because they can’t answer the first question the Act asks: what AI are you actually running?
This is a working checklist, not a legal brief — confirm specifics with your counsel. But it will get your compliance and AI teams pointed at the right work.
What is the EU AI Act?
The EU AI Act is a risk-based regulation of artificial intelligence, in force since August 2024 and phasing in through 2027. It sorts AI systems into four tiers by the risk they pose and attaches obligations accordingly: unacceptable-risk uses are banned outright, high-risk uses carry a heavy obligation set, limited-risk uses owe transparency, and minimal-risk uses are largely unaffected. Get your tier right and the rest of the work follows from it.
The deadlines that matter
| Date | What applies |
|---|---|
| Aug 2024 | The Act enters into force |
| Feb 2025 | Prohibited (unacceptable-risk) practices banned |
| Aug 2025 | General-purpose AI (GPAI) model obligations apply |
| 2 Aug 2026 | Core high-risk system obligations apply |
| Aug 2027 | High-risk AI embedded in regulated products |
Which risk tier are you in?
Work top-down. Are you using AI for anything the Act prohibits — such as social scoring or certain biometric practices? Stop; that’s banned. If not, does your AI operate in a high-risk area — employment, credit and insurance, essential services, education, biometrics, critical infrastructure, or as a safety component of a regulated product? If so, the full obligation set applies. If your AI mainly interacts with people (a chatbot, or generated content), you likely owe transparency duties. Everything else is minimal-risk.
The compliance checklist
For high-risk systems, this is the core of what providers must have in place — and the evidence auditors will ask to see.
- Risk management system — a documented, ongoing process across the AI system’s lifecycle.
- Data governance — training, validation, and test data managed for quality, relevance, and bias.
- Technical documentation — enough to demonstrate conformity, kept current.
- Record-keeping / logging — automatic logs of the system’s operation, retained and traceable.
- Transparency and instructions — deployers given the information to use the system correctly.
- Human oversight — designed-in ability for people to intervene and override.
- Accuracy, robustness, cybersecurity — appropriate to the system’s purpose and risk.
- Conformity assessment + registration — assessed before market, registered in the EU database.
- Post-market monitoring — ongoing tracking and incident reporting after deployment.
If you’re a deployer rather than the provider, your list is shorter but real: use the system per instructions, ensure human oversight, monitor operation, keep the logs you generate, and — in many cases — run a fundamental-rights impact assessment.
The part most teams underestimate: evidence
Here’s the trap. Teams write policies, file documentation, and feel compliant — then an auditor asks the real question: show me exactly what the AI did. Which data did it see, what did it output, who approved the sensitive actions, and can you prove it? Policies describe intent. Auditors want the record.
That’s why AI Act readiness is, underneath the paperwork, a logging and governance problem. An immutable audit ledger of every request, decision, and approval is what turns “we have a policy” into “here is the evidence.” When governance is enforced in the request path rather than reviewed after the fact, the record is a byproduct of running the system, not a scramble before an audit — and it’s the same evidence base a GxP environment demands.
How to get ahead of it
Start where the Act does: with an inventory. You can’t classify, document, or govern AI you can’t see, and in most enterprises the real number of AI tools in use is far higher than IT’s official count — the shadow AI problem is the AI Act problem wearing different clothes. An inventory that finds every tool, contract, and shadow deployment is both the first compliance step and the fastest way to shrink your risk surface. Score where you stand with the Readiness Scorecard, and the deadline stops feeling like a cliff.
Frequently asked questions
When does the EU AI Act take effect?
What are the penalties under the EU AI Act?
Does the EU AI Act apply to companies outside the EU?
What counts as a high-risk AI system?
Start with the inventory the Act requires anyway.
The first obligation under the AI Act is knowing what AI you run. SphereIQ Governance enforces policy and keeps the audit ledger — and the AI Spend Diagnostic doubles as your EU AI Act inventory baseline.