Blog
sprinto angle right
EU AI Act
sprinto angle right
EU AI Act Compliance Checklist: What Applies From August 2, 2026

EU AI Act Compliance Checklist: What Applies From August 2, 2026

TL;DR

The next live EU AI Act deadline is August 2, 2026, when Article 50 transparency obligations take effect.
Most standalone Annex III high-risk obligations now apply from December 2, 2027. Requirements for high-risk AI embedded in regulated products apply from August 2, 2028.
The Act can apply to organizations inside or outside the EU when they place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, or use an AI system’s output in the EU.
AI literacy remains an obligation for providers and deployers, but the amended Article 4 requires measures that support literacy rather than prescribing a course or a fixed competence level.
Your immediate priorities are to identify AI touchpoints, review Article 50 disclosures, maintain an AI inventory, assign owners, and document decisions and evidence.

If you build, sell, or use AI in the EU, the next live deadline is August 2, 2026. That is when the EU AI Act’s Article 50 transparency obligations begin to apply, including duties covering certain direct AI interactions and AI-generated or manipulated content.

The same date is no longer the deadline for most high-risk AI requirements. Following the AI Omnibus, standalone Annex III high-risk obligations apply from December 2, 2027, while requirements for high-risk AI embedded in regulated products apply from August 2, 2028. This checklist separates what your team should finish now from the work that belongs on its longer-term roadmap.

Does the EU AI Act apply to you?

Possibly. It depends on your role, where the system is placed or used, and where its output is used. The EU AI Act can apply to public and private organizations inside or outside the EU when they place an AI system or general-purpose AI model on the EU market, put an AI system into service or use it in the EU, or provide or deploy a system outside the EU whose output is used in the EU.

Applicability therefore depends on the AI system, your role, and its connection to the EU market, not simply on whether your organization stores EU residents’ personal data.

August 2 is the next live EU AI Act deadline

Use this one-page checklist to finish your immediate transparency, inventory, ownership, and evidence actions—and see what to prepare next for 2027 and 2028.

Download the August 2 action checklist

How to Check If You Are In Scope for the EU AI Act

EU AI Act vs ISO 42001: Do you need both?

In the last three months alone, our in-house experts have spoken to over 700 organizations, and this is one of the first questions that comes up in almost every conversation. 

The short answer: ISO 42001 gives you the governance management system. The EU AI Act is the law. They are complementary, not interchangeable.

ISO/IEC 42001 is a voluntary international standard for AI management systems. It gives your organization a certifiable framework for governing AI responsibly. Getting certified demonstrates to customers and regulators that your AI practices are structured and audited. It is sector-agnostic and applies globally.

The EU AI Act is binding legislation with heavy fines for non-compliance, depending on the violation. It imposes requirements that ISO 42001 does not cover: six-month log retention, specific Annex IV technical documentation, conformity assessments, CE marking, and EU database registration for high-risk systems.

The most practical way to think about it: ISO 42001 asks, “Do you govern AI responsibly?” The EU AI Act asks, “Is this specific system legally compliant?” There is roughly 40-50% overlap between them in areas such as risk management, data governance, transparency, and human oversight. Organizations with existing ISO 42001 certification can accelerate their EU AI Act compliance work by roughly 30-40%, but must still close specific gaps in conformity assessments, EU database registration, and post-market surveillance.

The EU AI Act compliance checklist

Before you dive in, build your AI inventory. List every AI system your organization builds, uses, or procures, including tools employees use informally. Everything in this checklist depends on knowing what you actually have.

Need a version your team can use in a working session?

Here’s a one-page EU AI Act Action Items Checklist that you can use to assign owners across transparency, AI inventory and intake, AI literacy, prohibited practices, and high-risk preparation.


Download the one-page checklist

1. Understand your risk level

Your obligations under the EU AI Act flow entirely from this classification. Get it wrong and everything else is built on a shaky foundation.

  • Prohibited practices: The original prohibited practices have applied since February 2, 2025. They include harmful manipulation, exploitation of vulnerabilities, certain forms of social scoring and predictive policing, untargeted facial-image scraping, certain emotion-recognition and biometric-categorization uses, and restricted use of real-time remote biometric identification by law enforcement. A further prohibition concerning AI systems that generate or manipulate non-consensual intimate material or child sexual-abuse material applies from December 2, 2026.
  • High-risk AI systems: Standalone AI systems covered by Annex III, including specified uses in employment, education, essential services, biometrics, law enforcement, migration, and justice, become subject to the high-risk requirements from December 2, 2027. AI systems classified as high risk because they are embedded in regulated products become subject to those requirements from August 2, 2028.
  • Systems subject to transparency obligations: Article 50 obligations apply from August 2, 2026 to specified interactive AI systems, AI-generated or manipulated content, deepfakes, emotion-recognition and biometric-categorization systems, and certain public-interest text.
  • Minimal or no-risk systems: These systems are generally not subject to the Act’s high-risk requirements. However, organization-wide obligations and other applicable laws may still matter.

These are not always mutually exclusive buckets. For example, a high-risk system may also be subject to Article 50 transparency obligations. Either way, once you have classified risk across your own systems, extend the same exercise to all your AI-enabled vendors and LLM providers.

2. Know your role and meet your obligations

Your role under the Act, whether you are a provider, deployer, importer, or distributor, determines what you are specifically required to do.

💡Not sure which role applies to you?
  • Provider: You build or develop the AI system.
  • Deployer: You use a third-party AI system in your operations.
  • Importer: You bring an AI system into the EU market from outside the EU.
  • Distributor: You resell or make an AI system available without modifying it.

For providers of high-risk AI systems:

  • Establish a risk management system covering the full AI lifecycle.
  • Prepare Annex IV technical documentation before placing the system on the market.
  • Build human oversight into the system so a human can monitor, intervene, and override.
  • Complete a conformity assessment, sign an EU Declaration of Conformity, and affix CE marking.
  • Register the system in the EU high-risk AI database. (EU AI Act Article 71, Regulation 2024/1689)

For deployers of high-risk AI systems:

  • Verify that the system is registered in the EU high-risk AI database before use.
  • Conduct a Fundamental Rights Impact Assessment where required.
  • Assign human oversight to staff with the competence and authority to intervene.
  • Inform affected individuals that an AI system is involved in decisions about them.

For all organizations:

  • Providers and deployers must take measures to support the development of AI literacy among staff and other people who operate or use AI systems on their behalf. The amended Article 4 does not mandate a particular course, certification, or fixed level of competence.
  • A proportionate program may include role-based training, safe-use guidance, onboarding for relevant roles, practical examples, escalation procedures, and records showing which measures the organization has taken.
sprinto-flares
Build your AI compliance roadmap →

3. Get your documentation and management systems in order

Documentation is what you hand a regulator or enterprise customer when they ask for proof. It is also the area where most businesses have the biggest gaps.

If you already have ISO 27001, you have a head start. Your Information Security Management System (ISMS) covers information security risk management, access controls, and data integrity, all of which the EU AI Act requires for high-risk systems. Extend your existing ISMS scope to explicitly cover AI systems and document how those controls map to Act requirements. Sprinto’s ISO 27001 guide can help you build or expand your ISMS.

If you already have ISO 42001, you are further ahead. Your AI management system already addresses risk governance, documentation practices, and oversight structures. You still need to close specific gaps: Annex IV technical documentation, conformity assessments, CE marking, and EU database registration. But the governance backbone is there. See how ISO 42001 maps to the EU AI Act.

If you are starting fresh:

  • Prepare Annex IV technical documentation for every high-risk system: design, training methodology, performance metrics, testing results, and known limitations.
  • Retain operational logs for at least six months.
  • Keep a signed EU Declaration of Conformity on file for every high-risk system.
  • Establish an AI management system (AIMS). ISO 42001 is the internationally recognized standard for this and the most efficient foundation for EU AI Act compliance.

4. Revisit your data governance practices

The Act cares about what data goes into your AI systems, how it is handled, and whether the people it affects have meaningful transparency.

  • Document training, validation, and testing datasets as relevant, representative, and error-free.
  • Examine datasets for biases that could affect fundamental rights.
  • Put formal Data Processing Agreements in place with AI vendors, explicitly prohibiting the use of your data for model training.
  • Identify where customer data is used in AI training, and give customers a meaningful opt-out option.

For financial institutions, data governance under the EU AI Act overlaps significantly with DORA obligations around ICT risk management and third-party oversight. If you are already DORA compliant, map your existing vendor risk controls and operational resilience documentation to your EU AI Act data governance requirements rather than building them separately. Read more about DORA compliance.

5. Build in transparency

Transparency is both a specific legal obligation for several AI use cases and an increasingly strong signal to enterprise buyers.

  • Where a system influences decisions about individuals, inform those individuals that AI is involved.
  • Providers must ensure that people are informed when they directly interact with specified AI systems, unless the interaction is obvious from the context. Providers of generative AI systems must also support detection by applying machine-readable marking to generated or manipulated content.
  • Deployers have separate disclosure duties for deepfakes, emotion-recognition and biometric-categorization systems, and AI-generated or manipulated text published to inform the public on matters of public interest when the relevant human-review or editorial-control exception does not apply.
  • Make product documentation clear on capabilities, limitations, and potential risks.
  • Set up a way to communicate your compliance posture to customers. Sprinto’s Trust Center lets you share compliance credentials publicly or in gated reviews, cutting down repetitive security questionnaires from enterprise buyers.

6. Make compliance continuous

The EU AI Act does not have a finish line. Guidelines are still being finalized. Delegated acts are in progress. Each significant update to an AI system can trigger a new conformity obligation. Point-in-time compliance will be out of date faster than most teams realize.

  • Do you have automated monitoring in place to detect when controls drift or evidence goes stale?
  • Is there a named person responsible for tracking EU AI Act updates and translating them into program changes?
  • Are risk assessments scheduled for review when AI systems are significantly updated or when regulations change?

Have you mapped your existing compliance frameworks to EU AI Act requirements to avoid duplicating effort? Sprinto’s Infinite Frameworks engine does this mapping automatically, so adding a new framework does not mean starting over.

sprinto-flares
Automate framework mapping with Sprinto →

Common gaps organizations miss when using an EU AI Act checklist

Even organizations with a mature compliance program tend to miss the same things. Here are the four most common gaps worth checking before you consider your program solid.

  • Shadow AI is not in the inventory: Your checklist is only as complete as your AI inventory. If employees are using AI tools that were never formally approved or cataloged, those systems are outside your risk classification, uncovered by your policies, and invisible to your compliance function. When a regulator asks for a complete list of AI systems in use, that gap is immediately visible. The fix is active discovery, not blanket bans.
  • Technical documentation is incomplete: Annex IV documentation is the most commonly cited gap in EU AI Act readiness assessments. Many organizations have AI systems in production with no architecture descriptions, no documentation of training data, and no performance benchmarks. Systems that were built before the Act was on anyone’s radar were not designed with this in mind. Retrofitting documentation is significantly harder than building it into your development process from the start. If you have high-risk systems in production today with incomplete documentation, this is your most urgent gap.
  • Readiness is treated as a one-time project: The EU AI Act lacks a finish line. The Commission is actively issuing guidelines and delegated acts. The AI Office is publishing and revising GPAI codes of practice. National enforcement authorities are operationalizing their penalty frameworks. Each significant modification to an AI system can trigger a new conformity obligation. Compliance programs built as static documents become outdated faster than most teams realize.
  • There is no process for monitoring regulatory updates: The Commission’s consultation on draft guidelines for classifying high-risk AI systems closed on July 23, 2026. The Commission says the final guidelines will be adopted by the end of 2026. Assign a named owner to monitor the final guidance and update classifications, policies, and implementation plans when it is published.

How Sprinto helps you get EU AI Act audit-ready faster

This checklist is a starting point, not a system. Working through it tells you where you stand; it doesn’t keep you there.

That’s the gap Sprinto is built for.

Sprinto is the world’s first Autonomous Trust Platform for compliance that runs continuously in your background. The platform detects changes in your environment, determines what’s at risk, and acts across compliance, vendor risk, AI governance, and more. Here’s how Sprinto helps: 

  • Shadow AI detection and live AI registry: Sprinto detects AI tool adoption across your organization, maintains a continuously updated registry, and maps your full AI footprint to the EU AI Act, ISO 42001, and the NIST AI RMF. 
  • Framework alignment without manual mapping: Sprinto’s Infinite Frameworks engine continuously monitors regulatory updates, identifies which apply to your organization, and automatically maps changes to your existing controls. Gap assessments that used to take months now take days. 
  • Continuous evidence collection: Evidence for your audit checklist is collected and validated in the background. When a regulator or enterprise customer asks for your compliance documentation, it is already assembled.
  • Vendor risk management for AI-embedded tools: Your governance perimeter does not stop at your own systems. Sprinto continuously monitors third-party vendors, including SaaS tools with embedded AI, flagging changes in their security posture, data handling practices, and compliance status. If a vendor quietly adds an AI feature that touches your customer data, Sprinto catches it before your risk team does.
  • ISO 42001 and EU AI Act, together: If you are pursuing ISO 42001 alongside EU AI Act compliance, Sprinto supports both from the same platform, so you capture the 40 to 50% framework overlap without building duplicate programs.

Don’t let the deadline sneak up on you. Book a Sprinto demo and find out how quickly you can get audit-ready.

Frequently asked questions

Does the EU AI Act apply to companies outside the EU?

Yes. Applicability is determined by where your AI system operates or whose lives it affects, not where your company is headquartered. A US SaaS company selling an AI hiring tool to a German enterprise, or a Singapore fintech whose credit model processes French customer data, is fully in scope.

What is the enforcement deadline for the EU AI Act?

The EU AI Act does not have one enforcement deadline. Its obligations apply in phases:
1. Existing prohibited practices and AI literacy measures have applied since February 2, 2025.
2. General-purpose AI model obligations have applied since August 2, 2025.
3. Article 50 transparency obligations apply from August 2, 2026.
4. A new prohibition concerning non-consensual intimate material and child sexual-abuse material applies from December 2, 2026.
5. Standalone Annex III high-risk requirements apply from December 2, 2027.
6. Requirements for high-risk AI embedded in regulated products apply from August 2, 2028.

What are the four risk categories under the Act?

The Act classifies AI systems as prohibited (banned outright), high-risk (subject to full compliance obligations), limited-risk (transparency disclosures required), or minimal-risk (no mandatory obligations). Your entire compliance roadmap flows from this classification, so getting it right is the first and most consequential step.

What AI systems are prohibited under the Act?

Systems banned since February 2025 include social scoring by public authorities, subliminal manipulation techniques, predictive policing based solely on profiling, and real-time biometric identification in public spaces. If any of your systems fall into these categories, they need to be taken down immediately.

What is Annex IV documentation, and why does it matter?

Annex IV is a legally required set of technical documentation for every high-risk AI system, covering its design, training methodology, performance metrics, testing results, and known limitations. It is what you hand a regulator as proof of compliance, and it is the most commonly cited gap in EU AI Act readiness assessments. Systems built before the Act was on anyone’s radar often have no documentation at all, and retrofitting them is significantly harder than building them into your development process from the start.

Is AI literacy training already required?

Yes, Article 4 already applies, but the amended requirement is more flexible than a mandatory company-wide training course. Providers and deployers must take measures to support AI literacy among staff and others operating or using AI systems on their behalf. The appropriate measures depend on people’s roles, experience, the context in which AI is used, and the risks involved. No fixed level of competence or specific training format is prescribed.

Radhika Sarraf
Author

Radhika Sarraf

Radhika Sarraf is a content marketer at Sprinto, where she explores the world of cybersecurity and compliance through storytelling and strategy. With a background in B2B SaaS, she thrives on turning intricate concepts into content that educates, engages, and inspires. When she’s not decoding the nuances of GRC, you’ll likely find her experimenting in the kitchen, planning her next travel adventure, or discovering hidden gems in a new city.
Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
research & insights curated to help you earn a seat at the table.
single-blog-footer-img