The EU AI Act Compliance Checklist: Classify, Document, Govern

By CompliSense-AI3 min read

The EU AI Act regulates artificial intelligence by risk, not by industry. The obligations that apply to you depend entirely on what your AI system does and how it is used — so the first job is honest classification, and the second is building the evidence each tier demands.

This checklist walks the risk tiers, then lists the concrete obligations that follow. Use it to place each of your systems and to see what documentation you are missing.

Step 1 — Classify each system by risk

The Act sorts AI systems into four tiers. A single product can contain systems in different tiers, so classify per system, not per company.

  • Unacceptable risk — prohibited. Practices like social scoring by public authorities, manipulative techniques that cause harm, and certain biometric categorisation are banned outright. If a system falls here, the answer is to stop, not to document.
  • High risk — heavily regulated. Systems used in areas such as employment, credit, education, essential services, biometrics, and safety components of regulated products. This tier carries the bulk of the obligations.
  • Limited risk — transparency obligations. Systems that interact with people or generate content — chatbots, deepfakes, synthetic media — must disclose that fact so users know they are dealing with AI.
  • Minimal risk — largely unregulated. Most AI, such as spam filters or game AI, falls here and faces no specific obligations under the Act.

Step 2 — For high-risk systems, meet the core obligations

If any system lands in the high-risk tier, the following are not optional. Treat each as an evidence requirement you must be able to produce on request.

  • Risk management system. A continuous process to identify, evaluate, and mitigate risks across the system's lifecycle — not a one-time assessment.
  • Data governance. Training, validation, and testing data must be relevant, representative, and examined for bias. You need to show how the data was assessed.
  • Technical documentation. Detailed documentation of the system's design, capabilities, and limitations, kept current as the system changes.
  • Record-keeping and logging. The system must automatically log events to enable traceability throughout its operation.
  • Transparency to deployers. Clear instructions for use so those operating the system understand its capabilities, limits, and correct handling.
  • Human oversight. The system must be designed so a person can understand, monitor, and if needed override or stop it.
  • Accuracy, robustness, and cybersecurity. Appropriate levels of each, maintained across the lifecycle and documented.
  • Conformity assessment and registration. High-risk systems generally require a conformity assessment before going to market and registration in the EU database.

Step 3 — For limited-risk systems, meet transparency duties

If your system talks to users or generates content, disclosure is the obligation:

  • Tell users when they are interacting with an AI system rather than a human.
  • Label AI-generated or manipulated content — including synthetic audio, image, and video — as artificially produced.

Step 4 — Set up governance that keeps this current

The Act treats AI compliance as ongoing. Systems drift as models are retrained and use cases expand, and a system can move between tiers as its purpose changes. Sustainable compliance means:

  1. A maintained inventory of AI systems with their current risk classification.
  2. An owner for each high-risk system responsible for its documentation and oversight.
  3. A trigger to re-assess classification whenever a system's purpose or data materially changes.
  4. Living technical documentation and logs, not a snapshot captured for one audit.

A quick self-check

For every AI system you operate, can you answer:

  • Which risk tier is it in, and why?
  • If high-risk, where is its technical documentation, and is it current?
  • How is human oversight actually implemented?
  • If limited-risk, is the AI disclosure in place and visible?
  • Who owns keeping this true as the system evolves?

Gaps in those answers are your compliance backlog.

Where CompliSense-AI fits

The hard part of the AI Act is not reading it once — it is keeping classification, documentation, and oversight accurate as systems change. CompliSense-AI maintains the AI system inventory, ties each high-risk system to its evidence and owner, and flags when a change should trigger re-assessment, so your governance stays current instead of decaying between audits.

See how your programme scores against the AI Act core with our free readiness tool.