AI Act checklist for the board
No explanation of the regulation, just the list. Twelve points in the order they should be done, with the deadline that applies to each and an honest note on which ones most companies have not started.
This is a checklist, not an explanation. If you want the reasoning behind the risk classes, read the decision tree first and then come back. What follows is twelve points in the order they should be done.
One caveat before you start: this list is written for a company that uses AI systems rather than one that builds and sells them. If you develop AI products for the market, you are a provider as well as a deployer and you have a longer list than this one.
A hand working through a to-do list. Most companies can close the first six points in a week.
Work through in this order
1. List every AI system in use, including the ones nobody approved. Start with what people actually use, not with what was procured. Shadow usage is the norm rather than the exception and it counts. Deadline: now, because nothing below is possible without it.
2. Per system, name what decision it makes or supports. One sentence each. This is the input for point 3 and it is where most of the thinking happens.
3. Classify each system against Article 5 first, then the high-risk lists. Prohibited, high-risk, transparency-only, or minimal. Most systems in a normal company land in the bottom two. Deadline: now.
4. For anything that touches hiring, firing, promotion or monitoring of staff: treat it as high-risk until proven otherwise. Annex III names employment decisions explicitly. This is the single most common place a mid-sized company has an obligation it does not know about.
5. Check that chatbots and AI-generated content disclose what they are. Article 50. This has applied since 2 August 2026, so it is not a future item. Deadline: passed.
6. Arrange AI literacy for the people who work with these systems. Article 4 places this on the organisation, not on the individual. In force since 2 February 2025. Deadline: passed.
7. Write down which decisions may never be fully automated. Not a legal requirement in itself, but it is what makes points 4 and 8 enforceable inside your own company.
8. For each high-risk system, ensure a named person reviews and can explain the outcome. Article 26 requires the people assigned to oversight to have the competence, training and authority to do it. A name in a document who has never seen the system does not satisfy this.
9. Check that you can keep the logs for at least six months. Also Article 26, where the logs are under your control. If your supplier deletes them after thirty days, this is a contract conversation, not an internal one.
10. If you deploy a high-risk system in the workplace, inform staff and their representatives before you start using it. Article 26 again. Frequently missed and awkward to fix retroactively.
11. Review your supplier contracts for documentation access, model-change notification and an exit. Details in AI Act en je leveranciers.
12. Put a date in the diary to redo this list. The regulation is still moving. The Digital Omnibus already shifted the Annex III deadline once.
The deadlines, in one place
| Obligation | Applies from | Status today |
|---|---|---|
| Prohibited practices (Article 5) | 2 February 2025 | In force |
| AI literacy (Article 4) | 2 February 2025 | In force |
| GPAI provider obligations | 2 August 2026 | In force |
| Transparency for chatbots and AI content (Article 50) | 2 August 2026 | In force |
| High-risk, Annex III including employment | 2 December 2027 | Extended by the Digital Omnibus |
| High-risk embedded in certified products, Annex I | 2 August 2028 | Not yet |
The four points most companies have open
Being honest about where the gaps usually are is more useful than a list that assumes you are starting from zero on all twelve.
Point 1 is almost never complete, because shadow usage is invisible by definition until you ask. Point 6 is often assumed to be covered by a single all-staff email, which it is not. Point 9 is rarely checked, because nobody thinks about log retention until they need a log. And point 10 is regularly skipped entirely, usually not deliberately but because the system was introduced as a small efficiency tool rather than as something requiring notification.
If you close only four things this quarter, close those four.
About this page
Article numbers and dates are taken from the AI Act text, with the Annex III date reflecting the extension under the Digital Omnibus Regulation (EU) 2026/1744. The Article 26 details on oversight competence, six-month log retention and worker notification were verified against the article itself. This is a checklist for deployers, not legal advice, and it does not cover the additional obligations that apply if you also build and market AI systems. Last reviewed on the publication date; the regulation is still changing, so check the date at the top before relying on this.
Frequently asked questions
Sources
- EU AI Act, Article 26 (obligations of deployers)— artificialintelligenceact.eu ↗
- EU AI Act, Article 50 (transparency obligations)— artificialintelligenceact.eu ↗
- EU AI Act, Annex III (high-risk use cases)— artificialintelligenceact.eu ↗
Tell us what you need.
We respond within 24 hours, from a real human.
Get in touch



