EU AI Act checklist
EU AI Act checklist for companies
A practical checklist for companies organizing AI inventory, policy, literacy, ownership, and risk records before formal EU AI Act review.
For teams ready to implement rather than only compare options, the related template is EU AI Act Readiness Operating Checklist and the public sample is available in the sample library.
Buyer
EU-facing companies, operations teams, legal operations, and AI governance owners
Problem
Teams often discuss AI Act readiness before they have the basic facts: what AI is used, who owns it, what data is involved, and how employees are trained.
What to look for
- Inventory of AI systems used, bought, embedded, or piloted.
- Policy, AI literacy, restricted-use, vendor-review, and management-action records.
- Clear owner assignments before involving counsel or outside compliance support.
Red flags
- The company discusses compliance without an AI inventory.
- Employee AI literacy has no owner or completion record.
- AI vendors are approved without data-use or training-use evidence.
Compare related options
EU AI Act readiness checklist
Use when: The team needs organized facts before legal or compliance review.
Next step: Inventory AI systems and collect policy, training, owner, vendor, and risk evidence.
AI risk register
Use when: The team must prioritize workflows by exposure, impact, controls, and residual risk.
Next step: Record risk statements, controls, owners, decisions, and review cadence.
AI vendor questionnaire
Use when: Externally supplied AI tools need evidence before approval.
Next step: Review training use, retention, deletion, subprocessors, enterprise controls, and contract status.
Implementation steps
- Create an AI inventory covering tools, embedded AI features, owners, users, purpose, data categories, and output use.
- Assign owners for employee AI policy, approved tools, AI literacy, vendor review, risk review, and management action.
- Separate low-risk productivity use from sensitive, customer-facing, employment, regulated, or high-impact workflows.
- Collect evidence for training, policy acknowledgement, vendor review, tool approval, and risk decisions.
- Bring the organized facts to qualified legal, compliance, privacy, or regulatory reviewers before making legal conclusions.
Template preview
What the paid product adds
Readiness before legal conclusions
A practical EU AI Act checklist should organize facts before the company asks counsel or compliance specialists for conclusions. It should not claim that a workflow is compliant, low-risk, or exempt by itself. The first value is making AI use visible enough for qualified review.
Inventory and ownership
Start by identifying AI systems used directly by employees, embedded inside SaaS tools, piloted by departments, or purchased for customer workflows. Each entry should have an owner, user group, purpose, data category, vendor, output use, and review date. Ownership prevents readiness work from becoming an unmanaged spreadsheet.
AI literacy and employee controls
The checklist should ask whether employees have practical AI literacy training, whether completion is recorded, and whether employee rules explain restricted data, human review, approved tools, and escalation. Training evidence matters because policy language alone does not show that employees understand the expected behavior.
Vendor and procurement evidence
For externally supplied AI tools, teams should collect evidence about model-training use, retention, deletion, subprocessors, audit logs, enterprise controls, and contract status. This evidence helps reviewers understand whether the proposed use case matches the vendor controls and terms.
When to escalate
Escalate for qualified review when AI affects employment, eligibility, regulated services, safety, legal rights, customer-facing decisions, sensitive personal data, or automated decisions. The checklist should identify these triggers without trying to replace legal or regulatory judgment.
FAQ
Is a checklist enough for EU AI Act compliance?
No. A checklist helps organize internal facts and gaps before legal or compliance review.
What should companies do first?
Inventory AI systems, define owners, establish employee rules, document training, and identify high-risk or sensitive uses.
Related next steps
AI risk register template
How to create an AI risk register that shows use cases, owners, data categories, decision impact, controls, and residual risk.
Read the related guideAI vendor questionnaire
Questions to ask AI vendors about prompts, files, outputs, training use, retention, deletion, subprocessors, and enterprise controls.
Read the related guideAI literacy training for employees
What baseline AI literacy training should cover for employees using generative AI in everyday work.
Read the related guideAI Governance Readiness Pack
Risk, readiness, vendor review, and management-system checklists for teams moving beyond first policy rollout.
Review the pack