← All resourcesEU AI Act

EU AI Act readiness assessment: a practical checklist

7 min read

EU AI Act readiness assessment

Use this EU AI Act readiness assessment as a practical checklist: role, inventory, risk class, high-risk obligations, transparency, and evidence. The EU AI Act (Regulation (EU) 2024/1689) applies based on your role and the risk category of each AI system, and it phases in over time. This is a readiness aid, not legal advice — consult counsel for your specific obligations.

1. Scope & role

  • [ ] Determine whether the Act reaches you (systems on the EU market or affecting people in the EU).
  • [ ] For each AI system, record your role: provider, deployer, importer, or distributor.
  • [ ] Assign an owner for EU AI Act readiness.

2. Inventory

  • [ ] Maintain a complete inventory of AI systems and use cases.
  • [ ] Capture purpose, data, affected people, and vendor for each.

3. Classify by risk

  • [ ] Classify each in-scope use case: prohibited, high-risk, limited-risk (transparency), or minimal.
  • [ ] Record the rationale for each classification.
  • [ ] Confirm you deploy no prohibited practices (Article 5).

4. High-risk obligations (where applicable)

  • [ ] Risk-management system across the lifecycle.
  • [ ] Data governance — appropriate, representative data; attention to bias.
  • [ ] Technical documentation and instructions for use.
  • [ ] Record-keeping / logging for traceability.
  • [ ] Human oversight measures.
  • [ ] Accuracy, robustness, and cybersecurity appropriate to purpose.
  • [ ] Post-market monitoring and serious-incident reporting.

5. Transparency

  • [ ] Inform people when they interact with an AI system (unless obvious).
  • [ ] Label AI-generated or manipulated content where required.

6. General-purpose AI (GPAI)

  • [ ] Where you provide or build on foundation models, track applicable provider obligations and vendor attestations.

7. Evidence & monitoring

  • [ ] Keep the documentation and logs above as evidence of readiness.
  • [ ] Track the Act's phased application dates and adjust as obligations take effect.
  • [ ] Re-review periodically and on material change.

Turn the checklist into a living system

A checklist in a doc goes stale. The efficient path is a system of record that inventories your AI, classifies each use case, tracks human oversight, and keeps the evidence — mapped to EU AI Act documentation categories (and NIST AI RMF and ISO/IEC 42001). See ISO 42001 vs the EU AI Act.

AI Assurance Hub does exactly this. Explore the live demo or start free.

_This checklist is educational and not legal advice. Consult qualified counsel for obligations specific to your role, systems, and jurisdiction._

Put this into practice.

Inventory, assess, approve, and evidence every AI use case in one place.

Stay ahead of AI governance.

Get new guides and product updates in your inbox. Occasional, no spam.