FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Checklist · 5 minute read

EU AI Act Compliance Checklist

EU AI Act compliance starts with determining whether your systems and role as provider or deployer fall within scope, classifying each system by risk, confirming no prohibited practices, and for high-risk systems implementing risk management, data governance, documentation, logging, transparency, human oversight, accuracy and robustness, and conformity processes, plus transparency duties for certain systems and obligations for general-purpose models.

By FISTA Solutions· AI-Native Engineering Team·
EU AI Act Compliance Checklist article cover

The EU AI Act is the most comprehensive AI regulation in force, and its reach extends to organizations outside Europe whose systems or outputs are used there. Its high-risk obligations are, in large part, the engineering practices this library recommends anyway: specifications, data governance, evaluation, logging, human oversight, and documentation. This checklist orients teams to the regulation's structure and the questions to answer. It complements eu ai act explained and eu ai act compliance for us companies. This is general guidance, not legal advice; confirm requirements with counsel and official guidance.

Who should use this checklist?

Compliance, legal, and risk leaders, product and engineering owners of AI systems, and governance bodies assessing exposure to the regulation.

Are you in scope, and in which role?

  1. Systems and outputs used in the EU are inventoried, including by customers and subsidiaries.
  2. For each system, your role is determined: provider, deployer, importer, distributor, or several.
  3. Exemptions (for example, certain research or purely personal uses) are assessed with counsel rather than assumed.
  4. Scope reasoning is documented per system.

Have you classified each system by risk?

CategoryQuestionAction
Prohibited practicesDoes the system perform any listed prohibited practice?Stop; redesign
High-riskDoes the use case fall within listed high-risk areas or product safety legislation?Full high-risk obligations
Transparency obligationsIs it a chatbot, synthetic content generator, emotion recognition, or biometric categorization system?Transparency duties
Minimal riskNone of the aboveVoluntary codes; general good practice
General-purpose AI modelDo you provide a general-purpose model?GPAI obligations; systemic-risk duties if applicable

Classification reasoning is documented and reviewed when use changes. Reference: ai in regulated industries.

Have you confirmed no prohibited practices?

  1. Systems are checked against the prohibited practices list (for example, certain manipulative techniques, exploitation of vulnerabilities, social scoring, and specified biometric uses).
  2. Findings are documented; any system implicated is stopped and redesigned with counsel.

For high-risk systems: are provider obligations met?

  1. A risk management system operates across the lifecycle.
  2. Data governance covers training, validation, and testing data: relevance, representativeness, error examination, and bias consideration.
  3. Technical documentation demonstrates compliance and is kept current.
  4. Automatic logging enables traceability over the system's lifetime.
  5. Transparency and instructions for deployers are provided.
  6. Human oversight measures are designed in and documented.
  7. Accuracy, robustness, and cybersecurity are achieved and evidenced.
  8. Quality management system, conformity assessment, registration, and post-market monitoring obligations are addressed.
  9. Serious incident reporting procedures exist.

Engineering alignment: the spec-driven development for AI whitepaper, the AI evaluation and testing whitepaper, how to build an ai audit trail, and ai human oversight requirements.

For high-risk systems: are deployer obligations met?

  1. Systems are used per provider instructions.
  2. Human oversight is assigned to competent, trained people with authority.
  3. Input data under your control is relevant and representative.
  4. Operation is monitored and the provider informed of risks or incidents.
  5. Logs are kept for the required period.
  6. Affected people are informed where required; fundamental rights impact assessments are conducted where applicable.
  7. Workplace and public-authority deployers address their additional duties.

Reference: ai record keeping requirements and ai transparency notices.

Are transparency obligations met?

  1. People interacting with chatbots or AI systems are informed, unless obvious from context.
  2. Synthetic audio, image, video, and text outputs are marked as required, including deepfake disclosures.
  3. Emotion recognition and biometric categorization subjects are informed where such systems are permitted.
  4. Marking and notice implementations are tested and documented.

Reference: ai content provenance and ai deepfake risk for enterprises.

For general-purpose model providers: are GPAI duties met?

  1. Technical documentation and information for downstream providers are prepared.
  2. Copyright policy and training content summary obligations are addressed.
  3. Models with systemic risk meet additional evaluation, risk mitigation, incident reporting, and cybersecurity duties.
  4. Applicable codes of practice are considered.

Are supporting structures in place?

  1. AI literacy measures for staff involved with AI systems.
  2. A register of systems with classification and obligations.
  3. Governance body and named owners.
  4. Vendor contracts allocate provider and deployer responsibilities and information flows.
  5. Incident and change processes cover regulatory triggers.

Reference: the ai governance checklist and ai acceptable use training.

Are you tracking timelines and guidance?

  1. The phased application dates for prohibited practices, GPAI duties, transparency obligations, and high-risk obligations are tracked.
  2. Harmonized standards, guidelines, and codes of practice are monitored as they are published.
  3. Counsel review confirms current obligations for your systems and roles.
  4. Interactions with other regulation (data protection, sector rules, product safety) are mapped.

Reference: ai regulation in the united states for the US comparison and ai and gdpr for the data-protection interface.

How should the results be used?

Prioritize by consequence: confirm no prohibited practices, then address high-risk systems' obligations by their application dates, then transparency duties, then supporting structures. Where high-risk obligations overlap with engineering practice you already follow, document the mapping rather than duplicating work.

How FISTA Solutions supports EU AI Act readiness

FISTA Solutions builds AI systems with the specifications, data governance, evaluation, logging, oversight, and documentation that high-risk obligations expect, and it helps organizations map those artifacts to the regulation's requirements alongside counsel. The AI enablement practice provides the platform for logging and evaluation, AI agents are delivered with oversight designed in, and forward deployed engineers work with your compliance and legal teams. The record behind the approach is 150+ projects across 12+ countries with 99.9% uptime.

This checklist is general guidance, not legal advice. To discuss EU AI Act readiness for specific systems, message FISTA on WhatsApp, or read ai explainability requirements for a related obligation area.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01Does the EU AI Act apply to non-EU companies?

It can. Providers placing AI systems on the EU market and deployers using systems in the EU are in scope, and providers and deployers outside the EU are covered where the system's output is used in the EU. Organizations should assess scope with counsel rather than assuming exemption.

02What are the EU AI Act risk categories?

Prohibited practices, high-risk systems defined by listed use cases and product safety legislation, systems with specific transparency obligations, and minimal-risk systems, plus separate obligations for general-purpose AI models including those with systemic risk.

03What must high-risk AI systems have?

A risk management system, data governance for training and testing data, technical documentation, automatic logging, transparency and instructions for deployers, human oversight measures, accuracy, robustness, and cybersecurity, plus conformity assessment, registration, and post-market monitoring obligations for providers.

04What do deployers of high-risk systems have to do?

Use systems per the provider's instructions, assign human oversight to competent people, ensure input data relevance where they control it, monitor operation, keep logs, inform affected people where required, and in certain cases conduct fundamental rights impact assessments. Specific duties should be confirmed with counsel.

05Is this checklist legal advice?

No. It is a general engineering and governance orientation to the regulation's structure. Obligations, timelines, and interpretations evolve; organizations should confirm their specific requirements with qualified counsel and official guidance.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project