EU AI Act Compliance Checklist: Requirements, Deadlines, and Test Evidence (2026 Update)

EU AI Act Compliance Checklist: Requirements, Deadlines, and Test Evidence (2026 Update)

Updated September 2026 - what changed. This post first went out in August 2024, when the Act had just entered into force. We rewrote it. The timeline now reflects the Digital Omnibus on AI, which moved the high-risk deadlines to December 2027 and August 2028. We added the obligations for general-purpose AI models, the transparency rules that already apply, the penalty tiers, and the AI Office's first enforcement action. The checklist is now grouped by deadline, and the testing section maps each requirement to the evidence an auditor will ask for.

The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive law on artificial intelligence. It entered into force on 1 August 2024. Most of its rules took effect on 2 August 2026, with one large exception: the requirements for high-risk systems were deferred to 2027 and 2028. Also on 2 August 2026, the European Commission's AI Office gained the power to enforce the rules for general-purpose AI models, and within four weeks it sent its first formal requests for information to more than 30 model providers. The Act is no longer a future obligation. It is being enforced.

This guide covers what the Act requires, when each requirement applies, what non-compliance costs, and how a QA team turns those requirements into a checklist and a body of test evidence.

EU AI Act timeline: what applies now and what comes next

The Act phases in over four years. The Digital Omnibus on AI, adopted in 2026, pushed back the two high-risk deadlines. It also introduced new prohibitions, gave synthetic-content-generating systems already on the market a transition period for the Article 50(2) marking duty, softened the AI literacy duty, and made other targeted amendments.

DateWhat applies
1 Aug 2024Entry into force
2 Feb 2025Prohibited AI practices (Art. 5) and AI literacy duties (Art. 4)
2 Aug 2025Obligations for general-purpose AI model providers (Chapter V). Governance bodies in place
2 Aug 2026Most remaining rules, including the transparency obligations (Art. 50). Commission enforcement powers over general-purpose AI models begin
2 Dec 2026Two new prohibitions: AI systems that generate non-consensual intimate images, and AI systems that generate child sexual abuse material. End of the Art. 50(2) transition for synthetic-content-generating systems already on the market before 2 Aug 2026
2 Aug 2027General-purpose AI models placed on the market before 2 Aug 2025 must be compliant (Art. 111(3)). Member State AI regulatory sandboxes operational
2 Dec 2027Requirements for high-risk AI systems listed in Annex III (deferred from 2 Aug 2026)
2 Aug 2028Requirements for high-risk AI embedded in regulated products under Annex I (deferred from 2 Aug 2027)

Source: European Commission, AI Act implementation timeline.

The deferral is not a pause, and the new dates are fixed rather than tied to any trigger: the final text dropped the conditional mechanism the Commission had first proposed. The Article 5 prohibitions in force since February 2025, plus AI literacy, transparency, and the general-purpose AI rules, all apply today. The Omnibus added two prohibited practices rather than removing any, and both start on 2 December 2026.

Which high-risk date applies to you depends on the route in. A hiring tool or a credit scoring model is an Annex III system, so December 2027 is your planning horizon. A medical device with AI inside goes the Annex I route, because the Medical Devices Regulation is one of the product laws listed there, so its date is August 2028, provided the device needs a notified body. The same split applies to machinery and vehicles. Both dates are hard backstops, so whichever route you are on, the work starts now.

The four risk levels

The Act sorts AI systems by risk. The higher the risk, the heavier the obligations.

  1. Unacceptable risk. Banned outright. Examples: social scoring (by any actor, public or private) where the score leads to detrimental treatment in a context unrelated to where the data was collected, or to treatment that is unjustified or disproportionate, manipulative or deceptive techniques that cause significant harm, untargeted scraping of facial images to build facial recognition databases, and emotion recognition in workplaces and education institutions (except for medical or safety reasons).
  2. High risk. Allowed, but heavily regulated. Two routes in, and neither is as wide as it first looks. Both are set out below.
  3. Limited risk. Transparency duties only (Art. 50). Chatbots, synthetic media, deepfakes.
  4. Minimal risk. No system-specific obligations. Most spam filters and game AI sit here. This is not the same as nothing to do: the AI literacy duty in Article 4 falls on providers and deployers of any AI system, whatever its tier.

The Annex I route (Art. 6(1)) needs both conditions to hold. The AI is a safety component of a product, or is itself a product, covered by one of the EU product laws listed in Annex I (machinery, medical devices, vehicles, and so on), and that product already has to undergo a third-party conformity assessment under that law. A product the manufacturer self-certifies does not take this route. The Omnibus also narrowed what counts as a safety component, so AI that only assists a user or optimises performance is outside it when a failure creates no health or safety risk.

The Annex III route (Art. 6(2)) is filtered by Art. 6(3). Annex III covers AI used in one of eight areas: biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, and justice. Article 6(3) then lets you conclude that a listed system is not high-risk, if it poses no significant risk of harm and does no more than one of these: a narrow procedural task, an improvement on a completed human activity, flagging deviations from earlier decision patterns without replacing human review, or a preparatory task. An Annex III system that performs profiling of natural persons is always high-risk. If you do rely on the exemption, you still register the system in the EU database.

General-purpose AI models are a separate track. A large language model is regulated as a model (Chapter V), and the systems built on it are then classified by risk like any other system.

Requirements for high-risk AI systems (Articles 9-15)

Chapter III, Section 2 lists seven requirements. Each one produces artefacts that a notified body, a market surveillance authority, or an internal auditor will ask to see. The evidence is listed next to each.

  • Risk management system (Art. 9). A continuous, documented process across the whole lifecycle: identify risks, estimate them, adopt measures, test them. Evidence: risk register, test plans and results for each mitigation, review log.
  • Data and data governance (Art. 10). Training, validation, and test datasets must be relevant, representative, and as error-free and complete as possible, with documented design choices and a bias check. Evidence: dataset datasheets, bias assessment reports, data lineage.
  • Technical documentation (Art. 11). Drawn up before market placement and kept current, following Annex IV. Evidence: the Annex IV file itself, under version control.
  • Record-keeping (Art. 12). Automatic logging over the system's lifetime, enough to trace operation, identify risk situations, and support post-market monitoring. Evidence: log schema, retention policy, sample exports.
  • Transparency and information to deployers (Art. 13). Instructions for use that state capabilities, limitations, accuracy levels, and human oversight measures. Evidence: the instructions for use, plus the tests that back the stated accuracy figures.
  • Human oversight (Art. 14). People must be able to understand, monitor, override, and stop the system. Evidence: oversight design document, and test cases that prove a stop or override works.
  • Accuracy, robustness, and cybersecurity (Art. 15). Declared accuracy metrics, resilience to errors and to adversarial inputs, protection against data poisoning and model manipulation. Evidence: accuracy benchmarks, robustness tests, adversarial and red-team test reports.

Deployers have their own duties (Art. 26): use the system as the instructions describe, assign competent human oversight, check that input data is relevant, keep the logs the system generates for at least six months, and, for public bodies and some private deployers, complete a fundamental rights impact assessment (Art. 27).

Obligations for general-purpose AI models

If you train and release a general-purpose model, Chapter V has applied to you since 2 August 2025. Models already on the market before that date have until 2 August 2027 to comply (Art. 111(3)).

Fine-tuning someone else's model rarely makes you a provider. The Commission's July 2025 guidelines give an indicative, non-binding criterion: you are likely to become the provider of the modified model when the compute used for your modification is more than one third of the compute used to train the original. It guides a case-by-case assessment rather than settling it, but ordinary fine-tuning and adaptation sit well under that line. If you do cross it, you document the modification itself, meaning what you changed and the new training data, not the whole model.

GPAI providers (Art. 53) must keep technical documentation, give downstream providers the information they need to comply, put a copyright policy in place, and publish a summary of the content used for training, using the AI Office template. Models released under a free and open-source licence, with weights, architecture, and usage information publicly available, are exempt from the first two of those (Art. 53(2)). The copyright policy and the training-content summary still apply, and the exemption is not available to models with systemic risk.

A model is presumed to carry systemic risk when the compute used to train it exceeds 10²⁵ floating point operations (Art. 51(2)). Providers of those models (Art. 55) must also run state-of-the-art model evaluations including adversarial testing, assess and mitigate systemic risks, report serious incidents to the AI Office, and ensure adequate cybersecurity. The General-Purpose AI Code of Practice, published in July 2025, is the voluntary route to demonstrating compliance.

Enforcement has started. The Commission gained its enforcement powers over general-purpose models on 2 August 2026. By the end of that month the AI Office had sent formal requests for information to more than 30 providers based in different regions of the world. One set of requests covers model security, independent external evaluations, and post-market monitoring. A second set went to providers that had not published their training content summaries and had not joined the AI Office's compliance dialogues. Executive Vice-President Henna Virkkunen described them as "a first step in enforcing the AI Act", and said the goal is "to ensure that AI in Europe is developed, released and used safely and transparently." A request for information is not a finding of non-compliance, but an incomplete or misleading answer is finable on its own.

Transparency rules that already apply (Article 50)

Article 50 has applied since 2 August 2026, and it reaches far beyond high-risk systems:

  • People must be told when they interact with an AI system, unless it is obvious from the context.
  • Providers of systems that generate synthetic audio, image, video, or text must mark the output in a machine-readable way, detectable as artificially generated or manipulated. This does not bite where the system performs an assistive function for standard editing, or does not substantially alter the input data or its semantics.
  • Deepfakes must be labelled as artificially generated or manipulated.
  • People exposed to emotion recognition or biometric categorisation must be informed.
  • AI-generated text published to inform the public on matters of public interest must be disclosed, unless a human reviewed it and someone holds editorial responsibility.

Providers of synthetic-content-generating systems, general-purpose AI systems included, that were already on the market before 2 August 2026 have until 2 December 2026 to implement the Art. 50(2) marking. The transition covers those systems only, not everything already on the market.

Penalties for non-compliance

Article 99 sets three tiers. In each case the fine is the higher of the two figures.

ViolationMaximum fine
Prohibited practices (Art. 5)EUR 35 million or 7% of worldwide annual turnover
Other obligations, including the high-risk requirements and Art. 50EUR 15 million or 3%
Supplying incorrect, incomplete, or misleading information to authoritiesEUR 7.5 million or 1%

Smaller companies pay less. SMEs and start-ups take the lower of the two figures on all three tiers. Small mid-cap enterprises, a category the Omnibus added, take the lower figure on the second and third tiers, but not on the prohibited-practices tier.

Providers of general-purpose AI models face fines of up to EUR 15 million or 3% under Article 101, imposed directly by the Commission.

EU AI Act compliance checklist

Grouped by the deadline that drives each item.

Already required (since February 2025, August 2025, and August 2026)

  1. Inventory every AI system you provide or deploy. Record its purpose, its provider, and the model behind it.
  2. Classify each system: prohibited, high-risk (Annex I or III), transparency-only, or minimal. Apply the Art. 6(3) filter before you call an Annex III system high-risk, and write down the reasoning either way.
  3. Confirm nothing you run falls under Article 5. If it does, stop it. Note that the two new prohibitions, on AI that generates non-consensual intimate images and on AI that generates child sexual abuse material, are also Article 5 practices, but they do not bite until 2 December 2026.
  4. Support AI literacy for staff who operate or oversee AI systems, and keep records of the training you provide. The Omnibus softened Article 4: you support the development of literacy rather than guarantee a set level.
  5. Implement the Article 50 disclosures: chatbot notices, machine-readable content marking, deepfake labels.
  6. If you provide a general-purpose model: technical documentation, a downstream information pack, a copyright policy, and a published training content summary. Check first whether you are the provider at all: fine-tuning rarely crosses that line, with the Commission's indicative criterion sitting above a third of the original training compute, and an open-source release drops the first two duties. If you cross the systemic risk threshold: evaluations, incident reporting, cybersecurity measures.
  7. Decide who owns AI compliance. Name the role. Give it a budget.

By 2 December 2027 (Annex III high-risk systems)

  1. Set up the Article 9 risk management system and connect it to your test management process.
  2. Document datasets and run bias assessments (Art. 10).
  3. Build the Annex IV technical documentation file and keep it under version control (Art. 11).
  4. Implement lifetime logging and a retention policy (Art. 12).
  5. Write the instructions for use, with accuracy figures backed by tests (Art. 13).
  6. Design and test human oversight: monitoring, override, stop (Art. 14).
  7. Benchmark accuracy, robustness, and cybersecurity, including adversarial testing (Art. 15).
  8. Prepare the conformity assessment and the EU declaration of conformity. Register the system in the EU database before placing it on the market. Critical infrastructure systems (Annex III point 2) go on a national register instead (Art. 49(5)).
  9. Set up post-market monitoring (Art. 72) and a serious incident reporting process (Art. 73).
  10. As a deployer: complete a fundamental rights impact assessment where required (Art. 27), and retain logs for six months. If you are an employer putting a high-risk system into service or using one at the workplace, inform workers' representatives and the affected workers first (Art. 26(7)).

By 2 August 2028 (Annex I product-embedded AI)

Align the AI requirements with the existing product conformity procedure (medical devices, machinery, vehicles). The two assessments are designed to run together.

Test cases that produce compliance evidence

The Act does not say "run these tests." It says what the system must be and asks you to prove it. Testing is how you prove it. The ISTQB CT-AI v2.0 syllabus covers techniques relevant to demonstrating regulatory compliance; we covered that in our CT-AI v2.0 guide. Here is how the requirements map to test work:

RequirementTests and evidence
Accuracy (Art. 15)Benchmark suites against the declared metrics, per segment and per release. Keep the metric reports per version and the pass/fail record against thresholds.
Robustness (Art. 15)Perturbation and noise tests, out-of-distribution inputs, drift monitoring. Keep the robustness reports and the drift alerts with their responses.
Cybersecurity (Art. 15)Adversarial testing, prompt injection, data poisoning, model extraction attempts. Keep the red-team reports and the remediation tickets.
Data governance (Art. 10)Bias and fairness tests across protected attributes, data quality checks. Keep the fairness reports and the dataset datasheets.
Human oversight (Art. 14)Scenario tests: can an operator detect, override, and stop the system in time? Keep the test runs with screenshots and timings.
Transparency (Arts. 13, 50)Verify that disclosures appear and that content marking is present and machine-readable. Keep the UI test evidence and the marking validation results.
Record-keeping (Art. 12)Verify that logs capture the required events and survive the retention period. Keep the log samples and the retention test results.
Risk management (Art. 9)Every mitigation in the risk register has a test that shows it works. Keep the requirement-to-test traceability.

Three practices make this hold up under scrutiny:

  • Traceability. Every requirement, whether it lives in Jira, GitLab, or Azure DevOps, maps to the test cases that cover it, and the gaps are visible. A requirements traceability matrix is the simplest way to show an auditor that Article 14 was not just designed but tested.
  • Evidence capture. Screenshots, logs, and run history captured automatically, so a passing result is something you can inspect rather than something you take on faith. See our guide to building a test evidence strategy that scales.
  • A release decision. One view where AI test results, open defects, and coverage roll up into a go or no-go call, with the release readiness decision recorded. That record is what you hand over when a regulator asks how a version was approved.

A request for information comes with a deadline. Evidence you cannot retrieve quickly is evidence you do not have.

Integrating the checklist into your workflow

  • Cross-functional ownership. Legal, engineering, data, and QA share the checklist. QA owns the evidence.
  • Automate the repeatable tests. Accuracy, robustness, and transparency checks run in the pipeline on every model or prompt change. Manual scenario tests cover human oversight.
  • Monitor after release. Post-market monitoring is a legal duty for high-risk systems. Drift detection and incident logging feed the risk register.
  • Review on a schedule. Re-classify systems when their purpose changes. Re-run the checklist when the Commission publishes new guidelines or harmonised standards.

Frequently asked questions

What are the main requirements of the EU AI Act?
Do not deploy prohibited systems. Support the development of AI literacy among relevant staff. Disclose AI interaction and AI-generated content. For high-risk systems: risk management, data governance, technical documentation, logging, transparency to deployers, human oversight, and accuracy, robustness, and cybersecurity, followed by a conformity assessment and registration. For general-purpose models: documentation, a copyright policy, and a public training content summary, with extra duties for systemic-risk models.

When do the high-risk obligations apply?
2 December 2027 for the Annex III use cases and 2 August 2028 for AI embedded in Annex I products. Both dates were set by the Digital Omnibus on AI in 2026.

What are the penalties for non-compliance?
Up to EUR 35 million or 7% of worldwide turnover for prohibited practices, EUR 15 million or 3% for most other violations, and EUR 7.5 million or 1% for misleading regulators. SMEs and start-ups pay the lower of the two figures on all three tiers, and small mid-caps do on the second and third.

Does the Act apply to companies outside the EU?
Yes, if you place a system on the EU market or its output is used in the EU. The AI Office's first requests for information went to providers based in different regions of the world, not only to those in Europe.

Sources