Dec 2027EU AI Act compliance
    Browse all 14 resources
    Guide12 min read

    EU AI Act Compliance Checklist for 2026

    The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 with a staged implementation timeline. This guide breaks down every obligation by role, risk level, and deadline.

    Ticked 0 of 20

    Ticks stay in this browser only. Nothing is sent anywhere.

    Key Deadlines

    DateWhat Applies
    2 Feb 2025Prohibited AI practices (Article 5) and AI literacy (Article 4)
    2 Aug 2025GPAI model obligations, governance structure, confidentiality rules, penalties framework
    2 Aug 2026General date of application: the Regulation applies, except the parts in the other rows. This includes the transparency obligations of Article 50
    2 Dec 2026New Article 5 bans apply: points (ba) and (bb). Providers of generative AI systems placed on the market before 2 August 2026 must meet the Article 50(2) marking duty
    2 Dec 2027High-risk AI systems listed in Annex III: Articles 6 to 27 apply. They cover classification, requirements, provider and deployer obligations and the fundamental rights impact assessment
    2 Aug 2028High-risk AI systems under Article 6(1) and Annex I, such as safety components of regulated products: Articles 6 to 27 apply
    31 Dec 2030Legacy AI systems in large-scale EU IT systems (Annex X) must be brought into compliance

    Prohibited AI Practices (Article 5)

    The following AI practices are banned outright, with fines up to EUR 35 million or 7% of global annual turnover:

    • Subliminal manipulation or deceptive techniques causing significant harm
    • Exploitation of vulnerabilities due to age, disability, or social/economic situation
    • Social scoring of people, by public or private actors, that leads to detrimental treatment out of context or out of proportion
    • Real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions)
    • Untargeted scraping of facial images from the internet or CCTV for facial recognition databases
    • Emotion recognition in workplaces and educational institutions (with narrow exceptions)
    • Biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation
    • Individual predictive policing based solely on profiling
    • Generating or manipulating non-consensual intimate or sexually explicit material of an identifiable person — added by Reg. (EU) 2026/1744, banned from 2 December 2026
    • Generating or manipulating child sexual abuse material — added by Reg. (EU) 2026/1744, banned from 2 December 2026

    Provider Obligations (Article 16)

    Providers of high-risk AI systems bear the heaviest compliance burden. Before placing a system on the market or putting it into service, providers must:

    Deployer Obligations (Article 26)

    Organisations that use high-risk AI systems (deployers) have their own set of obligations:

    Take the checklist with you

    The same checklist as a DOCX file: tick it in Word or print it for a meeting.

    Free, no email asked. The file mirrors this page.

    Importer & Distributor Obligations

    Importers (Articles 23) must verify that the provider has completed the conformity assessment, prepared technical documentation, affixed CE marking, and appointed an authorised representative. They must not place a non-conforming system on the market.

    Distributors (Article 24) must verify CE marking, the EU declaration of conformity, and instructions for use are present. They must ensure storage and transport conditions don't jeopardise compliance.

    Penalty Structure (Article 99)

    ViolationMaximum Fine
    Prohibited AI practices (Art. 5)EUR 35M or 7% global turnover
    Provider, deployer, importer, distributor obligationsEUR 15M or 3% global turnover
    Incorrect or misleading information to authoritiesEUR 7.5M or 1% global turnover

    For SMEs and start-ups, fines are capped at the lower of the percentage or fixed amount. Mitigating factors include self-reporting, degree of cooperation, and technical measures already implemented.

    Frequently asked questions

    Is there a free EU AI Act checklist file?

    Yes. The DOCX on this page mirrors the checklist and is free, with no email asked. Tick it in Word or print it.

    Does the Article 4 AI-literacy duty apply to deployers?

    Yes. Article 4 has applied since 2 February 2025 to providers and deployers of every AI system. They take measures to support the AI literacy of the staff who operate or use the systems. The law does not require any specific level of AI literacy.

    When do the high-risk obligations apply?

    For high-risk AI systems listed in Annex III, from 2 December 2027. For high-risk AI systems under Article 6(1) and Annex I, such as safety components of regulated products, from 2 August 2028.

    Related resources

    Bottom line: The EU AI Act is not optional. If you develop, deploy, import, or distribute AI systems in the EU, you need to map your obligations now. The prohibited practices and AI-literacy rules already apply, and so do the transparency obligations of Article 50 since 2 August 2026. The high-risk obligations apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems. The Digital Omnibus (Regulation (EU) 2026/1744) moved both dates later.

    This checklist is an orientation, not legal advice. It was checked against the consolidated text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

    LandingRed automates all of this

    Stop managing compliance in spreadsheets. Classify, document, assess, and monitor your AI systems from one platform.