The EU AI Act is now in force and if your company builds or deploys AI systems in Europe, compliance is no longer optional. Most organizations know the regulations exist. Fewer know exactly what it will require of them.
We scanned the official EU AI Act documentation and its published guidance, identified what applies to AI businesses operating today, and compiled it into a 10-step checklist you can work through systematically.
This checklist complements legal advice by helping technical and compliance teams organize implementation work.
Key Takeaways:
- Article 50 transparency obligations apply from August 2, 2026, regardless of whether your system is high-risk.
- Start with a full AI inventory. Compliance documentation built on an incomplete inventory will not hold up under scrutiny.
- Vendor contracts signed before the AI Act likely do not extract the documentation your compliance program now legally needs.
- Logging under Article 12 requires engineering work across multiple sprints. Scope it before touching any other documentation.
- The Omnibus deadline extensions are preparation time, not permission to wait. Compliance frameworks take time to build properly.
A 10-Step EU AI Act Compliance Checklist for 2026
EU AI Act compliance is an ongoing operational program rather than a one-time exercise. It's a set of interconnected obligations that build on each other. Work through these steps in order, and you'll have a program that holds up to scrutiny.
Step 1: Build a Complete AI System Inventory
Before any classification or documentation work can begin, you need a full picture of every AI system your company builds, buys, or deploys. This is a foundational requirement, and it's also the step where most compliance programs fall short.
Teams tend to capture the systems engineering already knows about, while missing AI features embedded inside their SaaS tools.
Your ATS screening resumes, your CRM scoring leads, your support platform routing tickets, and your voice agent handling customer calls- all of these count, and they need to be in the inventory.
Regulation (EU) 2024/1689 does not define a mandatory inventory template, but Article 6 makes clear that any provider who considers a system not high-risk must document that assessment before the system goes to market. That documentation starts with knowing what you have.
Capture the following for each system:
- System name and a one-sentence description of its function
- Data inputs and outputs
- The population it affects, whether employees, job candidates, customers, or the public
- Internal system owner
- Whether the system is built in-house, vendor-provided, or both
- Deployment context, whether customer-facing, internal, or both
- Whether the system generates or manipulates synthetic audio, image, video, or text
Key considerations: Under Article 6(4) of Regulation (EU) 2024/1689, any provider who considers an AI system listed in Annex III not to be high-risk must document that assessment before the system is placed on the market or put into service.
They must provide that documentation to national competent authorities upon request.
Step 2: Classify Each System Against the EU AI Act's Risk Tiers
Once your inventory is complete, each system needs a risk classification. The main application date is August 2026, when most provisions, including requirements for high-risk AI systems under Articles 6 through 15, become mandatory. Classification determines which of those requirements apply to you.
The AI Act's primary compliance framework begins to apply on August 2, 2026, although certain high-risk AI obligations are subject to the revised implementation timeline under the 2026 Digital Omnibus agreement.
The regulation establishes four tiers: prohibited practices under Article 5; high-risk systems under Article 6 and Annex III; systems with limited transparency obligations under Article 50; and minimal-risk systems with no mandatory requirements.
Classification determines exactly how much compliance work sits on your plate, and each tier carries a different set of obligations.
- Prohibited systems cannot be deployed at all. Real-time biometric identification in public spaces and social scoring fall here
- High-risk systems trigger the full compliance stack, including documentation, logging, human oversight, and conformity assessment before market entry
- Minimal-risk systems carry no mandatory requirements, but the classification rationale still needs to be documented in writing
The practical starting point for most companies is Annex III, which lists the high-risk use-case categories.
Work through the following for each system:
- Check your system against all Annex III categories:
- Biometric identification
- Critical infrastructure
- Education and vocational training
- Employment and worker management
- Access to essential private services, including credit and insurance
- Law enforcement
- Migration and asylum
- Administration of justice
- Flag any system that touches these categories as high-risk pending legal review
- Document the classification rationale in writing for every system, including those you determine are not high-risk
- Check every system against Article 5 prohibited practices, including real-time remote biometric identification in public spaces and social scoring
Step 3: Build the Required Compliance Documentation for High-Risk Systems
Providers of high-risk AI systems must ensure compliance with the requirements set out in Articles 8 through 15 throughout the system's lifecycle. These are not policy-level commitments. Each one requires a distinct, maintained artifact.
Article 9 — Risk Management System:
- Document a risk management process covering hazard identification, risk evaluation, mitigation measures, and residual risk acceptance
- Tie the process to each lifecycle stage: design, training, validation, deployment, and post-market monitoring
- Establish a review cadence and record it
Article 10 — Data and Data Governance:
- Document the provenance of training, validation, and testing datasets
- Record known representativeness gaps and the steps taken to address them
- For vendor-provided models, extract this documentation from the supplier contractually
Article 11 and Annex IV — Technical Documentation:
- Produce a structured file describing the system, its components, its development process, and its testing methodology, following the schema in Annex IV of the regulation
Article 12 — Record-Keeping and Logging:
- Instrument the system to generate logs that support post-market monitoring and incident reconstruction
- Confirm logs are retained in a format that allows audit access
Article 14 — Human Oversight:
- Design and document a human oversight layer with the authority to override or pause the system
- For a hiring screen, this is the recruiter override. For a fraud detection system, this is a human review step before any consequential action is taken
- Do not treat this as a policy statement. It must be a designed and testable function within the system
Article 15 — Accuracy, Robustness, and Cybersecurity:
- Run quantitative testing covering normal operation, edge cases, and adversarial inputs
- Document the system's security posture against the cybersecurity requirements
Key considerations: Logging under Article 12 consistently has the longest lead time. If your system is not already instrumented, it will require engineering work across multiple sprints.
This should be scoped and started before any other documentation work.
If your AI system creates synthetic voices, the documentation should cover more than model behavior and test results.
If your organization develops synthetic voice systems, documentation should extend beyond model performance to include identity enrollment, provenance, watermarking, and deployment controls.
Resemble AI supports these workflows through Identity Enrollment and multimodal watermarking, helping compliance teams document how synthetic voice is verified and governed.
Step 4: Conduct Vendor Due Diligence and Update Contracts
The harshest realization in most 2026 compliance programs is that vendor contracts signed before the AI Act do not extract the documentation the deployer now needs.
If you are using third-party AI in a high-risk deployment context, your vendor relationship is part of your compliance posture. Contracts that predate the regulation will not reflect that.
Although the EU AI Act focuses primarily on providers and deployers of high-risk AI systems, it also imposes targeted obligations on other actors in the AI value chain. Article 25 of Regulation (EU) 2024/1689 sets out the responsibilities along the AI value chain, including what deployers can require of providers.
Due diligence questions to put to every AI vendor:
- Can you provide technical documentation for this system as required under Article 11 and Annex IV?
- How have you classified this system under the EU AI Act, and on what basis?
- Will you cooperate with incident reporting within the 15-day window required under Article 73?
- Do prompts or outputs from our deployment enter your training pipelines?
- Do you have EU representation in place if you are a non-EU company, as required under Article 22?
- Who are your sub-processors and what data do they access?
Contract updates to make:
- Add data governance and documentation extraction rights tied to Articles 10 and 11
- Add incident reporting cooperation clauses with timelines aligned to Article 73
- Confirm contractual liability allocation for high-risk system failures
- Require notification if the vendor reclassifies a system or materially changes its design
Key considerations: A vendor who cannot provide technical documentation for a system you have classified as high-risk is a compliance risk, not a supplier relationship issue. That finding needs to drive a decision, not a follow-up email.
Step 5: Implement Transparency and Disclosure Obligations Under Article 50
Article 50 works differently from the high-risk provisions. Its transparency obligations apply broadly to any AI system used in the four situations it covers.
An organization with no high-risk AI may still have significant obligations under Article 50. For companies building or deploying voice AI and synthetic media systems, this is one of the most directly applicable provisions in the regulation.
Unlike the high-risk requirements, Article 50 transparency obligations apply based on how an AI system is used, not whether it is classified as high-risk.
For systems that interact directly with users (Article 50(1)):
- Confirm that the system discloses AI interactions at the point of first contact, in a manner that meets accessibility requirements
- Review customer-facing product copy and onboarding flows for compliance
- Document which systems carry this disclosure and how it is implemented
For systems generating synthetic audio, image, video, or text (Article 50(2)):
- Implement machine-readable marking of synthetic outputs across all relevant modalities
- Confirm the marking approach meets the interoperability and robustness standard in Article 50(2)
- Do not rely on a single watermarking method. The draft Code of Practice indicates that a multi-layered approach is expected
For deployers publishing deepfake content (Article 50(4)):
- Disclose that the content has been artificially generated or manipulated, clearly and distinguishably
- Confirm that this disclosure is present in the content itself, not just in terms of service
Key considerations: Article 50 specifically addresses AI systems that generate or manipulate audio, video, image, and text content. Understanding where your AI system falls within the risk classification is the first step.
But Article 50 obligations apply regardless of whether a system is classified as high-risk. Even if none of your systems end up in Annex III, Article 50 very likely still applies.
Teams reviewing publicly available AI-generated content may also benefit from browser-based detection during investigation workflows. Resemble AI's Chrome Deepfake Detector can help analysts flag suspicious synthetic audio, image, and video content for further review.
It helps teams scan AI-generated images, videos, and audio content in the browser, so compliance and trust teams can flag media that may need closer inspection.
Suggested read: Complete Guide to EU AI Act Watermarking Requirements for Generative AI
Step 6: Establish a Quality Management System Under Article 17
A quality management system (QMS) under the EU AI Act is not a general ISO-style process that you can repurpose from an existing certification.
Article 17 of Regulation (EU) 2024/1689 requires the QMS to include a strategy for regulatory compliance, techniques and procedures for design control and design verification, and systematic actions covering the full lifecycle of the high-risk AI system.
It is a structured, documented management function that sits above the six technical artifacts and governs their maintenance and updates over time.
Build the QMS to cover the following:
- A written regulatory compliance strategy, including how you manage modifications to the system over time
- Documented design control and verification procedures tied to each development stage
- Data management procedures consistent with Article 10 requirements
- Testing protocols for accuracy, robustness, and cybersecurity under Article 15
- A post-market monitoring plan that feeds back into the risk management system under Article 9
- Corrective action procedures under Article 20, covering how identified problems are resolved and reported
- Records retention procedures under Article 18, including how long documentation is kept and who has access
Key considerations: The QMS is the governing layer over everything in Step 3. If documentation in Step 3 is updated but the QMS does not capture that update, the system's compliance posture degrades over time.
Build the QMS well before the relevant compliance milestones so documentation and operational controls mature together.
Step 7: Complete the Conformity Assessment and Register in the EU Database
Before a high-risk AI system can be placed on the market or put into service, it must go through a conformity assessment under Article 43 of Regulation (EU) 2024/1689.
For most Annex III high-risk systems, this is a self-assessment. For certain categories, including biometric identification systems, involvement of a notified body is required.
Once conformity is confirmed, the system must be registered in the EU database, and the provider must issue an EU declaration of conformity under Article 47 and affix CE marking under Article 48.
Conformity assessment checklist:
- Determine whether your high-risk system requires self-assessment or a notified body assessment under Article 43
- Complete the conformity assessment against the requirements in Articles 8 through 15
- Issue an EU Declaration of Conformity under Article 47, signed by an authorized representative
- Affix CE marking under Article 48 before placing the system on the market
- Register the system in the EU database for high-risk AI systems under Article 49 and Annex VIII
- If operating as a deployer of a third-party high-risk system, confirm that the system is registered before use, as required under Article 26(8)
Key considerations: Deployers of high-risk AI systems that are public authorities must comply with the registration obligations in Article 49.
If they find that a high-risk system they intend to use has not been registered in the EU database, they must not use that system and must inform the provider or distributor.
Even if your organization is a deployer rather than a provider, checking registration status before deployment is a direct legal obligation.
Step 8: Conduct a Fundamental Rights Impact Assessment
For specific AI systems, a fundamental rights impact assessment is required, detailing oversight measures and other risk mitigation strategies to protect individuals or groups from harm under Article 27.
Under Article 27, the assessment must include a description of the deployer's processes in which the high-risk AI system will be used.
This obligation applies to deployers that are bodies governed by public law, private entities providing public services, and deployers of employment and credit-related systems under Annex III, points 5(b) and 5(c).
Carry out the following:
- Determine whether your organization falls within the scope of Article 27 as a deployer
- Map each high-risk system to the specific population categories it affects
- Identify and document the specific risks of harm for each affected group
- Document the human oversight measures in place, aligned to Article 14 requirements
- Record the remediation steps available if identified risks materialize
- Submit the completed assessment to the relevant market surveillance authority using the template provided under Article 27(5)
- If a GDPR data protection impact assessment is already in place for the same system, check whether it covers the Article 27 requirements, as the regulation allows the two to be combined rather than duplicated
Key considerations: Once the assessment is complete, the deployer must notify the market surveillance authority of its results and submit the completed template with the notification.
If, during use of the system, any of the assessed elements change or become outdated, the deployer must update the information. This is a living document, not a one-time submission.
Step 9: Build Post-Market Monitoring and Incident Reporting Infrastructure
The August 2, 2026, date marks the start of post-market obligations.
Article 72 requires providers of high-risk AI systems to operate a documented, proportionate post-market monitoring system after the system is placed on the market or put into service.
The compliance posture shifts from demonstrating conformity at a point in time to maintaining control over performance and risk in real operating conditions.
On incident reporting, the timelines are short by design. Under Article 73, reports must be made within 15 days. After the provider or deployer becomes aware of a serious incident.
In the event of widespread infringement or a serious incident that poses a significant risk, the report must be provided immediately, no later than 2 days after becoming aware.
In the event of the death of a person, the report must be provided no later than 10 days after awareness.
Build the following before these obligations take effect.
- Define what constitutes a serious incident for each high-risk system in your portfolio
- Document a 15-day reporting process to the relevant market surveillance authority, with named owners and escalation paths
- Set up performance dashboards with review cadences documented in the post-market monitoring plan
- Establish a feedback loop between monitoring findings and the Article 9 risk management system
- Run at least one internal tabletop exercise simulating a serious incident before the August deadline
- Confirm that deployers of your systems know their own obligation under Article 26 to inform you of issues they identify during operation
Key considerations: Weak monitoring increases the chance that incidents are detected late or not at all, which becomes a compliance problem in itself. The first incident a company handles without a pre-built process is typically the one that becomes a regulatory event.
For teams handling synthetic media risk after deployment, Resemble Detect can support the review layer around suspicious audio, video, and image files.
It provides authenticity signals, supporting evidence, explainable outputs, and chain-of-custody context to assist investigation workflows.
Use it as part of the monitoring workflow, alongside internal escalation rules, incident records, and legal review where needed.
Step 10: If You Provide a General-Purpose AI Model
If your company allows a general-purpose AI model, a separate set of obligations applies under Chapter V of Regulation (EU) 2024/1689.
The governance rules and obligations for GPAI models became applicable on August 2, 2025. If your organization has not addressed these yet, they are already overdue.
Article 53 requires GPAI providers to submit technical documentation, transparency information, and systemic risk evaluations.
Non-compliance can result in fines of up to €15 million or 3% of global annual turnover, whichever is higher. This is imposed by the European Commission directly via the AI Office, not by Member State authorities.
Obligations for all GPAI model providers under Article 53:
- Prepare and maintain technical documentation following the schema in Annex XI of the regulation
- Prepare transparency information for downstream providers who integrate the model, following Annex XII
- Establish and publish a copyright policy that complies with EU copyright law
- Register the model in the EU database maintained by the AI Office
Additional obligations for GPAI models with systemic risk under Article 55:
- Assess and mitigate systemic risks, including through model evaluations and adversarial testing
- Report serious incidents involving the model to the AI Office without undue delay
- Implement cybersecurity protections proportionate to the level of systemic risk identified
If you integrate a GPAI model rather than provide one:
- Confirm that the GPAI model provider has complied with Article 53 obligations
- Obtain Annex XII transparency information from the provider for your own documentation
- Apply Article 50 transparency obligations to the downstream systems you build on top of the model, as these apply to the deployer regardless of the underlying model's compliance status
Key consideration: If you deploy a chatbot powered by a GPAI model, both articles apply. Article 50 requires users to be informed when interacting with AI systems, and Article 53 requires the model provider to submit documentation to the AI Office.
The obligations on the provider and on the deployer run in parallel, and neither substitutes for the other.
Penalties for Non-Compliance With the EU AI Act
The EU AI Act's fine structure under Article 99 is tiered by violation type, and the numbers are significant enough to make compliance a financial priority, not just a legal one.
What the 2026 Omnibus Amendments Mean for Your Compliance Timeline
Following the Digital Omnibus political agreement reached on May 7, 2026, the implementation timeline for certain EU AI Act obligations has been extended. Assuming the agreement proceeds through formal adoption, the updated milestones are as follows:
- Annex III high-risk AI systems now have until December 2, 2027. This is a 16-month extension from the original August 2026 date
- Annex I high-risk AI systems covering regulated products like medical devices and radio equipment move from August 2027 to August 2028
- For synthetic content systems already on the EU market before August 2, 2026, the machine-readable marking requirement under Article 50(2) is pushed to December 2, 2026
- Systems placed on the market after August 2, 2026, must meet Article 50(2) obligations from the date they go live, with no grace period
- The extended timelines are not an invitation to pause. A compliance framework takes time to build properly, and organizations should treat this window as preparation time
How Resemble AI Can Help AI Companies Prepare for EU AI Act Compliance
EU AI Act readiness is easier when teams can integrate policy, product behavior, and media evidence into a single practical workflow.
Resemble AI enables enterprises to verify and detect synthetic media across voice, image, and video. Its platform supports teams that need stronger control over AI-generated content, deepfake risk, and provenance signals.
- Mark synthetic media at the source: Resemble Watermarker embeds imperceptible watermarks into audio, video, and images, helping teams create machine-readable provenance signals for generated content.
- Review suspicious media after deployment: Resemble Detect analyzes audio, video, and image files and returns a verdict, explanation, and chain-of-custody context.
- Add browser-level review: Resemble AI’s Deepfake Detector for Chrome enables teams to scan AI-generated text, images, videos, and audio while browsing online.
- Identity Enrollment: Resemble AI's Identity Enrollment and Protection verifies trusted speakers before synthetic voice generation and authentication workflows.
- Support compliance review with evidence: Resemble Intelligence adds forensic explanations, fraud classification, liveness status, and audit-ready reports for legal, compliance, and trust teams.
Thousands of developers and enterprises already use Resemble AI, making it a practical partner for teams turning EU AI Act readiness into daily product, security, and compliance work.
Build EU AI Act Readiness Into Every AI Workflow
EU AI Act compliance in 2026 will depend on what teams can show, not only on what their policies say. AI companies need a repeatable way to classify systems, document decisions, mark synthetic outputs, monitor risk, and respond when evidence is needed.
Strong programs will turn these requirements into product, security, and governance habits before deadlines arrive.
Resemble AI supports enterprise AI trust workflows through identity enrollment, multimodal watermarking, and multimodal deepfake detection. Taken together, rather than treating detection as a standalone control, organizations can establish trusted identities, maintain provenance of generated media, review suspicious content, and generate evidence to support security, compliance, and governance requirements.
For teams working with voice, image, and video AI, this provides compliance and trust teams with clearer signals to inspect and act on.
Book a demo today to see how Resemble AI can support your EU AI Act readiness.
Frequently Asked Questions
- Who needs to comply with the EU AI Act?
Any company that builds, deploys, or imports AI systems used by people in the European Union must comply. This applies regardless of where your company is headquartered. If your AI output reaches EU residents, the regulation applies to you.
- What is the primary compliance deadline for high-risk AI systems?
Following the May 2026 Omnibus agreement, Annex III high-risk AI systems now have until December 2, 2027. Annex I product-regulated systems have until August 2, 2028. Article 50 transparency obligations still apply from August 2, 2026.
- What counts as a high-risk AI system under the EU AI Act?
Annex III of the regulation lists the specific use case categories that qualify as high-risk. These include employment screening, credit scoring, biometric identification, education, and law enforcement. Any system touching these areas needs a formal risk assessment.
- What is the difference between a provider and a deployer?
A provider builds and places an AI system on the market. A deployer uses a third-party AI system within their own products or operations. Providers carry heavier documentation and conformity obligations, but deployers also have meaningful legal responsibilities.
- Does the EU AI Act apply to voice AI and synthetic audio systems?
Yes. Article 50 specifically covers AI systems that generate or manipulate audio, video, image, and text content. Any voice AI system interacting with users must disclose its AI nature clearly at first contact.
- What are the Article 50 transparency obligations for synthetic content?
AI systems generating synthetic audio or other content must mark their outputs in a machine-readable format. For systems already on the EU market before August 2, 2026, this obligation applies from December 2, 2026. Systems launched after August 2026 must comply from day one.
- What documentation does a high-risk AI system require?
Providers must produce a technical documentation file, a risk management record, data governance documentation, logging infrastructure, and evidence of human oversight design. Each artifact needs to be maintained across the system's full lifecycle.
- What happens if a vendor cannot provide the required technical documentation?
A vendor that cannot supply technical documentation for a system you have classified as high-risk represents a direct compliance risk. That finding needs to drive a sourcing decision, not just a follow-up conversation.
- Are small and mid-sized companies treated differently under the EU AI Act?
The Omnibus agreement extended simplified compliance provisions to companies with up to 750 employees and €150 million in annual revenue. Benefits include reduced fine thresholds, simplified guidance, and access to regulatory sandboxes.
- What is a Fundamental Rights Impact Assessment, and when is it required?
A Fundamental Rights Impact Assessment documents how a high-risk AI system may affect specific groups of people and what oversight measures are in place. It is required for public bodies, companies providing public services, and deployers of certain employment and credit systems under Annex III.
- What are the incident reporting timelines under the EU AI Act?
Providers and deployers must report serious incidents to the relevant market surveillance authority within 15 days of becoming aware. Incidents involving death require reporting within 10 days. Widespread infringements involving significant risk must be reported within two days.
- Does the EU AI Act apply to general-purpose AI models like large language models?
Yes. Chapter V of the regulation covers GPAI model providers separately. These obligations have been in effect since August 2, 2025.




