EU AI Act compliance: a step-by-step guide and checklist
EU AI Act compliance sounds daunting, but it follows a clear sequence: know your systems, classify them, then meet each tier's obligations. This guide walks the process and gives you a checklist. Part of our guide to the EU AI Act.
AramGRC Team·AI Compliance & Assurance·September 11, 2026·9 min read
Where EU AI Act compliance starts
Compliance begins with visibility. You cannot classify or govern AI systems you haven't listed — so the first step is always an inventory of every AI system your organisation builds, buys or embeds, and which of them are placed on the market or used in the EU. Everything else follows from that list and each system's risk tier.
The EU AI Act compliance checklist
Inventory your AI systems — every system you build, deploy or embed, with owner and purpose, and flag which reach the EU.
Classify each system by risk tier — unacceptable, high, limited or minimal.
Exit any prohibited practices — stop using unacceptable-risk systems immediately; these have been banned since February 2025.
Meet transparency duties for limited-risk AI — tell people they're interacting with AI, and mark AI-generated and deepfake content.
Run a gap assessment for high-risk systems — measure each against the Act's requirements.
Build risk management and data governance — a lifecycle risk process and controls over training and input data.
Prepare technical documentation and logging — the Annex IV documentation and record-keeping the Act requires.
Implement human oversight and instructions for use — so a person can understand, oversee and intervene.
Complete conformity assessment and CE marking — self-assessment or, where required, via a notified body.
Set up post-market monitoring and keep evidence current — compliance is continuous, not a one-off filing.
If you provide or build on a general-purpose AI (foundation) model, separate GPAI obligations have applied since August 2025 — technical documentation, training-data transparency, and, for models with systemic risk, extra evaluation and mitigation. Factor these in alongside your system-level classification.
Provider vs deployer duties
Your obligations depend on your role. Providers (who develop and place a system on the market) carry the heaviest high-risk duties; deployers (who use it) must follow the instructions for use, maintain human oversight, monitor the system and, in some cases, run a fundamental-rights impact assessment. Many organisations are both, for different systems.
How ISO 42001 accelerates compliance
Most of the Act's high-risk requirements — inventory, risk and impact assessment, data governance, human oversight, monitoring — are exactly what an ISO/IEC 42001 management system delivers. Building on ISO 42001 turns EU AI Act compliance from a standalone scramble into a mapping exercise. See ISO 42001 certification.
How AramGRC helps
AramGRC runs EU AI Act conformity audits — classifying your systems, producing Annex IV technical documentation, and giving you a staged roadmap to each deadline. See EU AI Act conformity assessment.
Frequently asked questions
How do I comply with the EU AI Act?+
Inventory your AI systems, identify which reach the EU, classify each by risk tier, and meet that tier's obligations — for high-risk systems the full risk-management, documentation, human-oversight and conformity-assessment programme.
Is there an EU AI Act compliance checklist?+
Yes — the core steps are inventory, risk classification, exiting prohibited practices, transparency for limited-risk AI, and the full risk-management, documentation, oversight and conformity-assessment programme for high-risk systems.
What is a conformity assessment?+
The process by which a provider demonstrates a high-risk AI system meets the Act's requirements — by self-assessment or, for certain systems, through a notified body — before CE marking.
Do deployers of AI need to comply with the EU AI Act?+
Yes — deployers must use high-risk systems per the instructions, maintain human oversight, monitor them, and in some cases carry out a fundamental-rights impact assessment.