Back to blog
AI Capability

AI Act checklist for the board

No explanation of the regulation, just the list. Twelve points in the order they should be done, with the deadline that applies to each and an honest note on which ones most companies have not started.

Radical AI Team25 August 20264 min read
Someone ticking items off a checklist. Twelve points, each one either done or not done.

This is a checklist, not an explanation. If you want the reasoning behind the risk classes, read the decision tree first and then come back. What follows is twelve points in the order they should be done.

One caveat before you start: this list is written for a company that uses AI systems rather than one that builds and sells them. If you develop AI products for the market, you are a provider as well as a deployer and you have a longer list than this one.

A hand working through a to-do list. Most companies can close the first six points in a week.A hand working through a to-do list. Most companies can close the first six points in a week.

Work through in this order

1. List every AI system in use, including the ones nobody approved. Start with what people actually use, not with what was procured. Shadow usage is the norm rather than the exception and it counts. Deadline: now, because nothing below is possible without it.

2. Per system, name what decision it makes or supports. One sentence each. This is the input for point 3 and it is where most of the thinking happens.

3. Classify each system against Article 5 first, then the high-risk lists. Prohibited, high-risk, transparency-only, or minimal. Most systems in a normal company land in the bottom two. Deadline: now.

4. For anything that touches hiring, firing, promotion or monitoring of staff: treat it as high-risk until proven otherwise. Annex III names employment decisions explicitly. This is the single most common place a mid-sized company has an obligation it does not know about.

5. Check that chatbots and AI-generated content disclose what they are. Article 50. This has applied since 2 August 2026, so it is not a future item. Deadline: passed.

6. Arrange AI literacy for the people who work with these systems. Article 4 places this on the organisation, not on the individual. In force since 2 February 2025. Deadline: passed.

7. Write down which decisions may never be fully automated. Not a legal requirement in itself, but it is what makes points 4 and 8 enforceable inside your own company.

8. For each high-risk system, ensure a named person reviews and can explain the outcome. Article 26 requires the people assigned to oversight to have the competence, training and authority to do it. A name in a document who has never seen the system does not satisfy this.

9. Check that you can keep the logs for at least six months. Also Article 26, where the logs are under your control. If your supplier deletes them after thirty days, this is a contract conversation, not an internal one.

10. If you deploy a high-risk system in the workplace, inform staff and their representatives before you start using it. Article 26 again. Frequently missed and awkward to fix retroactively.

11. Review your supplier contracts for documentation access, model-change notification and an exit. Details in AI Act en je leveranciers.

12. Put a date in the diary to redo this list. The regulation is still moving. The Digital Omnibus already shifted the Annex III deadline once.

The deadlines, in one place

ObligationApplies fromStatus today
Prohibited practices (Article 5)2 February 2025In force
AI literacy (Article 4)2 February 2025In force
GPAI provider obligations2 August 2026In force
Transparency for chatbots and AI content (Article 50)2 August 2026In force
High-risk, Annex III including employment2 December 2027Extended by the Digital Omnibus
High-risk embedded in certified products, Annex I2 August 2028Not yet

The four points most companies have open

Being honest about where the gaps usually are is more useful than a list that assumes you are starting from zero on all twelve.

Point 1 is almost never complete, because shadow usage is invisible by definition until you ask. Point 6 is often assumed to be covered by a single all-staff email, which it is not. Point 9 is rarely checked, because nobody thinks about log retention until they need a log. And point 10 is regularly skipped entirely, usually not deliberately but because the system was introduced as a small efficiency tool rather than as something requiring notification.

If you close only four things this quarter, close those four.

About this page

Article numbers and dates are taken from the AI Act text, with the Annex III date reflecting the extension under the Digital Omnibus Regulation (EU) 2026/1744. The Article 26 details on oversight competence, six-month log retention and worker notification were verified against the article itself. This is a checklist for deployers, not legal advice, and it does not cover the additional obligations that apply if you also build and market AI systems. Last reviewed on the publication date; the regulation is still changing, so check the date at the top before relying on this.

Frequently asked questions

Prohibited practices and AI literacy since 2 February 2025, and transparency for chatbots and AI-generated content plus GPAI provider obligations since 2 August 2026.

Sources

  1. EU AI Act, Article 26 (obligations of deployers)artificialintelligenceact.eu
  2. EU AI Act, Article 50 (transparency obligations)artificialintelligenceact.eu
  3. EU AI Act, Annex III (high-risk use cases)artificialintelligenceact.eu
Looking for AI talent?

Tell us what you need.

We respond within 24 hours, from a real human.

Get in touch

Related reads

Pallets stacked outside and going nowhere. AI projects rarely fail loudly, they simply stop moving.
AI Capability

Why AI projects run aground in mid-sized companies

They do not crash. They go quiet. Five places an AI project runs aground in a mid-sized company, and why more technology fixes none of them.

4 August 20269 min read
A team around one laptop. The gap between mid-sized and large companies is twenty-one percentage points.
AI Capability

Five signals that your AI ambition is stalling on your organisation

Cost is named by 3 per cent as the reason for not using AI. Lack of experience inside the company by 11 per cent. Here is what that looks like on your own floor.

10 August 20269 min read
A calculator on a desk. The real cost is not on the invoice.
AI Capability

What AI really costs, and the budget nobody plans for

A licence of six hundred euro a month against twenty-eight thousand in staff hours. The ratio nobody puts in a business case, and how to budget it yourself.

12 August 20268 min read