EU AI Act Compliance: A 10-Step Triage Guide for 2026 and Beyond

Most EU AI Act guidance - including most of ours - explains one article at a time. That is useful once you know which articles apply to you. It is close to useless on day one, when the question is simply: what do we actually owe, and by when?
This checklist runs the other direction. It starts from your systems and routes you to the obligations, in an order where each step depends on the one before it. Ten steps. Work them in sequence.
One note before you start: the dates changed days ago. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Stand-alone Annex III high-risk obligations now apply from 2 December 2027, and Annex I embedded high-risk from 2 August 2028. Article 50 transparency was not deferred and applies from 2 August 2026. Any checklist you find that still counts down to a 2 August 2026 high-risk deadline predates this week.
Step 1: Build the AI system inventory
Everything downstream depends on a list of what you have. Almost everyone skips it, or does it badly. A 2026 readiness report found 83% of organisations had no formal inventory of their AI systems - a private survey finding rather than an official EU figure, but consistent with what most compliance leads describe.
Capture, for each item: name, purpose, who built it, who uses it, what data it touches, and whether it reaches EU users or is placed on the EU market.
Cast the net wider than the models your engineers built. Include vendor tools, AI features switched on inside SaaS you already licence, and the AI capabilities quietly added to products you bought years ago. Shadow AI is not an edge case; it is usually the majority of the list.
You're done with this step when someone outside the AI team could read the inventory and know what the organisation runs.
Step 2: Confirm each item is actually an "AI system"
Not everything in that inventory is in scope. The Article 3(1) definition has specific elements, and plenty of rules engines, deterministic scripts and ordinary statistical models fall outside it.
This step usually shrinks the list, which is exactly why it comes early - there is no point classifying the risk tier of something the Act does not reach. Our guide to the Article 3(1) definition walks through each element.
You're done when every inventory row is marked in-scope or out-of-scope, with a one-line reason.
Step 3: Establish your role for each system
The AI Act assigns duties by role, not by organisation. For each in-scope system, decide whether you are the provider, deployer, importer, distributor or authorised representative.
Two things trip people up. First, you will hold different roles for different systems - provider of the thing you built, deployer of the thing you bought. Second, the roles are not permanent. Substantially modifying a third-party high-risk system, or putting your own name or trademark on it, can convert you from deployer to provider, with the far heavier obligation set that entails.
You're done when every in-scope system has a named role and, where you are the deployer, a note on whether anything you do to it risks flipping that role.
Step 4: Check whether the Act reaches you at all
The AI Act applies extraterritorially. It catches organisations outside the EU that place systems on the EU market, and - importantly - those whose system output is used in the EU, even where the system itself never crosses the border.
If you are a non-EU provider of a high-risk system, Article 22 requires you to appoint an EU authorised representative by written mandate before you go live. That is a contract to negotiate, not a form to file, so it belongs early in the plan.
You're done when you can say, per system, whether it is in territorial scope and whether an authorised representative is required.
Step 5: Screen for Article 5 prohibitions
Do this before any risk classification work, because it is a hard stop. Prohibited practices have no compliance pathway - no conformity assessment, no CE mark, no documentation that makes them lawful. The answer is to stop.
These have applied since 2 February 2025 and carry the highest penalty tier, up to €35 million or 7% of global turnover.
The Omnibus added one: AI systems generating non-consensual intimate imagery ("nudifiers") and child sexual abuse material, with a transitional period to 2 December 2026. If you provide general-purpose image or video generation, note that the test is not only intent - it reaches systems where such output is a reasonably foreseeable and reproducible outcome absent adequate safeguards.
You're done when every in-scope system has been screened against all Article 5 categories and the screening is written down.
Step 6: Classify the risk tier
Three possible answers per system: Annex I route (AI as a safety component in a regulated product), Annex III route (stand-alone listed use case), or neither.
The Article 6(3) exception matters here. A system that looks like an Annex III use case can fall back out if it does not pose a significant risk of harm to health, safety or fundamental rights. But this is not a quiet decision:
- you must document the Article 6(3) assessment before placing the system on the market or putting it into service;
- you must still register the system in the EU database - the Omnibus simplified the Annex VIII information requirements but did not remove the obligation;
- national competent authorities may request that assessment.
Also worth re-checking post-Omnibus: the definition of "safety component" narrowed. AI used solely for non-safety aspects - user assistance, performance optimisation, service efficiency, convenience, quality control - no longer becomes high-risk merely by sitting inside a regulated product, unless its failure would endanger health and safety.
You're done when each system has a tier, and every Article 6(3) call has a written assessment behind it.
Step 7: Apply Article 50 transparency to everything customer-facing
This is the step most readers need first, and it is independent of risk tier. Article 50 catches ordinary companies doing ordinary things: a support chatbot, a voice agent, AI-drafted marketing copy, a synthetic product image.
From 2 August 2026 you must disclose that a person is interacting with an AI system, mark synthetic audio, image, video and text in machine-readable form, notify people subject to emotion recognition or biometric categorisation, and disclose deepfakes and AI-generated text on matters of public interest.
The grace period is narrow: only the Article 50(2) machine-readable marking duty, and only for systems placed on the market before 2 August 2026, defers to 2 December 2026. Systems placed on the market on or after 2 August 2026 comply immediately. Breaches sit in the tier up to €15 million or 3% of worldwide turnover.
You're done when every customer-facing AI surface has a disclosure, and you know each system's market-placement date.
Step 8: If you provide a GPAI model, run the Articles 51-56 track
General-purpose AI model obligations have applied since 2 August 2025 and run on their own clock, entirely independent of the high-risk timeline. If you train and release foundation models, this track is already live and the systemic-risk rules may apply on top.
You're done when you know whether you are a GPAI model provider and, if so, whether the systemic-risk threshold is met.
Step 9: Stand up governance before you need it
The same 2026 readiness report found 74% of organisations had no designated internal owner for AI compliance. That is the gap that makes every other gap permanent, because nobody is accountable for closing it.
The minimum viable governance layer:
- a named internal owner, with time actually allocated;
- an AI policy that says what teams may and may not deploy;
- Article 4 AI literacy measures - note the Omnibus softened this to a duty to support literacy rather than guarantee a "sufficient level" per person, so documented training and awareness programmes suffice, without certifying individuals;
- an intake process so newly purchased AI lands in the inventory automatically rather than being discovered later.
One caveat: deployers of high-risk systems still owe the more specific competence and training duties in Article 26(2). The softening does not reach those.
You're done when a new AI tool bought by a team outside engineering would reach the inventory without anyone remembering to tell you.
Step 10: Build the documentation pack
Only now - with an inventory, roles, tiers and an owner - is it worth assembling artefacts. Against the 2 December 2027 date for Annex III systems, providers of high-risk AI need:
| Artefact | Source |
|---|---|
| Risk management file, maintained across the lifecycle | Article 9 |
| Data governance records for training, validation and test sets | Article 10 |
| Technical documentation | Article 11 and Annex IV |
| Automatically generated logs and retention policy | Article 12 |
| Instructions for use for deployers | Article 13 |
| Human oversight design and evidence it is effective | Article 14 |
| Accuracy, robustness and cybersecurity evidence | Article 15 |
| Quality management system | Article 17 |
| Post-market monitoring plan | Article 72 |
| Serious incident reporting procedure | Article 73 |
Deployers have a shorter but real list under Article 26, plus a Fundamental Rights Impact Assessment under Article 27 where in scope.
The readiness report found 61% of organisations had no process for producing high-risk technical documentation. Note the wording: not "no documents" - no process. A one-off technical file that nobody refreshes as the model changes is not compliance, it is an artefact of a moment.
You're done when each artefact has an owner, a location and a review cadence.
Which deadline is actually yours
| If you are... | Nearest binding date | Obligation set |
|---|---|---|
| Any company with a customer-facing chatbot or publishing AI-generated content | 2 August 2026 | Article 50 transparency |
| A provider of a stand-alone Annex III high-risk system | 2 December 2027 | Articles 9-17, 22, 43, 49, 72, 73 |
| A provider of AI embedded in an Annex I regulated product | 2 August 2028 | Articles 9-17 plus sectoral law |
| A deployer of a high-risk system | 2 December 2027 | Article 26, Article 27 FRIA where in scope |
| A GPAI model provider | Already applicable since 2 Aug 2025 | Articles 51-56 |
| Running only internal, low-risk AI | 2 August 2026 for anything customer-facing; otherwise Articles 4 and 5 | AI literacy, prohibition screening |
The failure mode to avoid
The Omnibus bought roughly sixteen months for high-risk work. It bought exactly zero months for Article 50.
The common mistake is to start at step 10 - buying a documentation template or a compliance platform - before finishing step 1. It feels like progress because artefacts appear. But a technical file assembled for a system whose classification you have not verified, owned by nobody, listing systems you have not finished discovering, is expensive shelfware.
Steps 1 through 4 are unglamorous and take longer than anyone budgets. They are also the only steps that make the rest of the work meaningful. Start there.
This post is general information about the EU AI Act as at 30 July 2026, not legal advice. Primary sources: the AI Act, Regulation (EU) 2026/1744, the Commission's AI Act policy page and its Article 50 transparency FAQ.
Related reading

EU AI Act Implementation Status 2026: The Digital Omnibus Is Now Law - Re-Baseline Your Plans
Regulation (EU) 2026/1744 entered into force 27 July 2026. The high-risk clock moved; Art 50 transparency did not. Here is the complete re-baselined EU AI Act timeline for compliance leads.

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.