EU AI Act Compliance Checklist for CTOs and CIOs
Actionable compliance checklist for technology leaders — assess your AI systems, understand requirements, and build a roadmap to EU AI Act compliance ahead of the 2 December 2027 and 2 August 2028 high-risk deadlines.
The EU AI Act (Regulation 2024/1689) is in force and being enforced, and its remaining obligations are phasing in on a fixed timeline. As a CTO or CIO, you are the person most likely to own the technical side of compliance — and the one who will need to answer when the board asks, "Are we ready?"
This article provides a structured, actionable checklist to help you assess your organisation's position, identify gaps, and build a compliance roadmap. It is designed for technology leaders at companies that develop, deploy, or procure AI systems that touch the EU market.
What Changed in July 2026
Regulation (EU) 2026/1744 ("Digital Omnibus on AI") entered into force on 27 July 2026 — the first amendment to the AI Act. It defers the Chapter III, Sections 1–3 high-risk regime. Stand-alone high-risk systems under Article 6(2) and Annex III now apply from 2 December 2027 (previously 2 August 2026). High-risk systems under Article 6(1) and Annex I — AI as a product or safety component — apply from 2 August 2028 (previously 2 August 2027). National regulatory sandboxes under Article 57 must be operational by 2 August 2027.
The deferral is unconditional. The Commission's original proposal would have tied the new dates to a decision confirming that harmonised standards were available — a "stop-the-clock" trigger — but the co-legislators dropped it. There is no standards-readiness condition in the adopted text, and no mechanism for a further automatic delay.
What did not move matters just as much. 2 August 2026 remained the AI Act's general application date, and the AI Office and national authorities began enforcing from that day. Article 50 transparency obligations — chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content — are in force now, as is Article 49 registration, which sits in Chapter III Section 5 and is outside the deferral. Article 6(5) is expressly carved out of it too. Article 5 prohibitions have applied since 2 February 2025 and are unchanged, and the Article 99 penalty ceilings are untouched.
Two additions are worth putting straight into your plan. Regulation (EU) 2026/1744 adds two new Article 5 prohibitions — AI systems that generate or manipulate non-consensual intimate imagery of an identifiable person, and systems that generate or manipulate child sexual abuse material — both applying from 2 December 2026. On the same date, the new Article 111(4) grace period expires: generative AI systems placed on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking duty by then.
Phase 1: Discovery and Inventory
Before you can comply, you need to know what you have. Most organisations significantly underestimate the number of AI systems they operate.
Checklist: AI System Inventory
- Identify all AI systems across the organisation — not just the ones labelled "AI." The regulation's definition (Article 3(1)) is broad: any machine-based system designed to operate with varying levels of autonomy that generates outputs such as predictions, recommendations, decisions, or content.
- Include third-party AI — systems you procure, embed, or access via API. As a deployer, you have obligations even for systems you did not build.
- Map AI systems to business functions — HR, customer service, fraud detection, content moderation, supply chain, marketing, product features, internal tools.
- Document the purpose and scope of each system — what decisions it influences, what data it processes, who is affected by its outputs.
- Identify the provider for each system — is it built in-house, procured from a vendor, or open-source? Your obligations differ depending on your role in the value chain.
The definition of "AI system" under the regulation is intentionally broad. It encompasses machine learning models, rule-based expert systems, statistical approaches, and hybrid systems. When in doubt, include a system in your inventory — it is far better to over-classify and then exclude than to miss a system that turns out to be in scope.
Checklist: Role Identification
The AI Act assigns different obligations based on your role. You may hold multiple roles simultaneously:
- Provider (Article 3(3)) — you develop an AI system or have one developed on your behalf and place it on the market or put it into service under your own name or trademark
- Deployer (Article 3(4)) — you use an AI system under your authority (even if you did not build it)
- Importer — you place on the EU market an AI system from a provider established outside the EU
- Distributor — you make an AI system available on the EU market without being a provider or importer
- Authorised representative — you are mandated by a non-EU provider to act on their behalf
Phase 2: Risk Classification
The heart of the AI Act is its risk-based approach. Your obligations depend entirely on which risk category each AI system falls into.
Checklist: Prohibited Practices Screen (Article 5)
- Review each AI system against the prohibited practices in Article 5 — enforceable since 2 February 2025
- Flag any system that involves: subliminal or manipulative techniques, exploitation of vulnerable groups, social scoring, individual predictive policing, untargeted facial image scraping, emotion recognition in workplaces/education, biometric categorisation for sensitive attributes, or real-time remote biometric identification in public spaces
- Screen against the two new prohibitions added by Regulation (EU) 2026/1744 and applying from 2 December 2026 — generation or manipulation of realistic intimate imagery of an identifiable person without their consent (Article 5(1)(ba)), and generation or manipulation of child sexual abuse material (Article 5(1)(bb))
- For flagged systems: determine immediately whether the system must be discontinued, redesigned, or falls within a narrow exception
- Document your analysis for each system — including the rationale for why systems near the boundary are not prohibited
Checklist: High-Risk Classification (Articles 6 and Annex III)
- Check Annex I — does your AI system serve as a safety component of, or is it itself, a product covered by EU harmonisation legislation (medical devices, machinery, toys, vehicles, aviation, etc.)? These systems face the requirements from 2 August 2028. Note that Regulation (EU) 2026/1744 moved machinery from Annex I Section A to Section B.
- Check Annex III — does your AI system fall into one of the eight high-risk areas? These systems face the requirements from 2 December 2027. Annex III itself was not amended, and no Article 7 delegated act has been adopted, so the eight headings stand as enacted.
- Biometric identification and categorisation
- Management and operation of critical infrastructure
- Education and vocational training (admissions, assessments)
- Employment, worker management, and access to self-employment (recruitment, task allocation, monitoring, evaluation)
- Access to essential private and public services (credit scoring, insurance pricing, emergency services)
- Law enforcement (risk assessment, polygraphs, evidence analysis)
- Migration, asylum, and border control
- Administration of justice and democratic processes
- Apply the exception in Article 6(3) — even if listed in Annex III, a system is not high-risk if it does not pose a significant risk of harm. The provision was not substantively amended, and the rule that an Annex III system performing profiling of natural persons is always high-risk survives. Document this assessment carefully if you rely on it.
- Document the classification rationale for every AI system — this will be a key artefact in any regulatory inquiry
The Commission's guidelines on high-risk classification under Article 6(5), published on 19 May 2026 in three documents, are still in draft; the consultation closed on 23 July 2026. Treat any position you take from them as a draft interpretation and record it as such, rather than as settled guidance.
Checklist: Limited-Risk and Minimal-Risk Systems
- Identify systems with transparency obligations (Article 50) — chatbots, deepfakes, emotion recognition, biometric categorisation. These obligations are enforceable now; Article 50 sits in Chapter IV and was not touched by the deferral. Treat this as your most urgent workstream, not a future one.
- Check your legacy generative systems — anything placed on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking duty by 2 December 2026 under the new Article 111(4)
- Classify remaining systems as minimal risk — voluntary codes of conduct encouraged but no mandatory obligations
- Document all classifications in your AI register
Automate your compliance documentation
Ctrl AI generates audit-ready execution traces and trust-tagged outputs for every AI decision, giving CTOs the evidence base that regulators expect.
Learn About Ctrl AIPhase 3: Gap Analysis for High-Risk Systems
If you have identified high-risk AI systems, this is where the substantive work begins. Articles 8 through 15 define the requirements. They bind from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems — roughly sixteen months and two years out respectively. That is a reprieve on the calendar, not on the workload: data governance, documentation and logging are multi-release engineering programmes, and the extra time is best read as room to do them properly rather than as licence to defer the start.
Checklist: Data Governance (Article 10)
- Document training, validation, and testing datasets — including their provenance, relevance, representativeness, and any known gaps or biases
- Implement data quality criteria — examine data for errors, incompleteness, and biases before training and on an ongoing basis
- Ensure appropriate data governance — including data collection processes, labelling, cleaning, and enrichment operations
- Address bias in datasets — especially concerning protected characteristics (gender, ethnicity, age, disability)
- For personal data processing: confirm GDPR compliance, including legal basis, data minimisation, and purpose limitation
Checklist: Technical Documentation (Article 11)
- Prepare technical documentation before a system is placed on the market — this is not optional and must be kept up to date
- Include all elements specified in Annex IV: general description, development process, monitoring and control, risk management, changes, and standards applied
- Ensure documentation is comprehensive enough for authorities to assess compliance — vague or superficial documentation will not suffice
Checklist: Record-Keeping and Logging (Article 12)
- Implement automatic logging of events during the AI system's operation — the regulation requires traceability
- Ensure logs capture: the period of each use, the reference database against which input data was checked, the input data for which the search led to a match, and the identification of persons involved in human oversight
- Define retention periods for logs — at minimum for the period appropriate to the intended purpose of the system, and no less than six months unless otherwise specified
- Ensure logs are accessible to deployers and available to authorities upon request
Checklist: Transparency and Information (Article 13)
- Design systems to be transparent — deployers must be able to understand and use the system's output appropriately
- Provide clear instructions for use covering: intended purpose, level of accuracy and robustness, known limitations, foreseeable misuse risks, human oversight measures, and expected input data specifications
- Where applicable: inform individuals that they are subject to a decision made by a high-risk AI system
Checklist: Human Oversight (Article 14)
- Design systems for effective human oversight — this means real, meaningful oversight, not a rubber stamp
- Ensure the human overseer can: fully understand the system's capabilities and limitations, correctly interpret outputs, decide not to use the system or override its output, and intervene or halt the system
- Implement "human-on-the-loop" or "human-in-the-loop" mechanisms appropriate to the risk level and context
- Train the individuals responsible for human oversight — they must have the competence, training, and authority to exercise their role
Checklist: Accuracy, Robustness, and Cybersecurity (Article 15)
- Define and declare accuracy metrics — the system must achieve the level of accuracy appropriate to its intended purpose
- Test for robustness — the system should perform consistently under expected conditions and handle errors or inconsistencies gracefully
- Implement cybersecurity measures — protect against unauthorised third-party manipulation of training data, inputs, or the model itself (data poisoning, adversarial examples, model extraction)
- Document all testing results and include them in the technical documentation
Phase 4: Organisational Readiness
Technical compliance is necessary but not sufficient. You also need organisational structures and processes.
Checklist: Quality Management System (Article 16)
- Establish a quality management system proportionate to your organisation's size — documented policies and procedures for AI system development, deployment, and monitoring
- Include compliance strategy, resource allocation, and accountability in the QMS
- Implement a post-market monitoring system (Article 72) — systematic processes to collect and analyse data on the performance of your AI systems after deployment
- Define a serious incident reporting process (Article 73) — you must report to authorities within 15 days of becoming aware of a serious incident
Checklist: Conformity Assessment (Articles 43-44)
- Determine which conformity assessment procedure applies to each high-risk system — internal control (Annex VI) or third-party assessment (Annex VII)
- Identify whether a notified body is required — this is mandatory for certain biometric and critical infrastructure AI systems
- Prepare the EU declaration of conformity (Article 47) — a formal statement that the system meets all applicable requirements
- Affix the CE marking (Article 48) before placing the system on the market
- Register the system in the EU database (Article 49) — this obligation sits in Chapter III Section 5, outside the deferral, and applies from 2 August 2026
- Do not plan around a presumption of conformity yet — no harmonised standard has been cited in the Official Journal, so no CEN-CENELEC deliverable currently confers one under Article 40. Standardisation request M/613 runs to 28 February 2027.
- If you rely on a notified body, factor in the new Article 43(3) deadline: bodies already notified under Annex I Section A sectoral legislation must apply for designation under AI Act Chapter III Section 4 by 28 January 2028
Checklist: Deployer Obligations (Article 26)
If you deploy (use) high-risk AI systems built by others:
- Use the system in accordance with the provider's instructions for use
- Assign human oversight to individuals with the necessary competence, training, and authority
- Ensure input data is relevant and sufficiently representative for the system's intended purpose
- Monitor the system's operation and report any serious incidents to the provider and relevant authority
- Conduct a fundamental rights impact assessment (Article 27) if you are a body governed by public law or a private entity providing public services
- Inform individuals that they are subject to a high-risk AI system decision, where required
Deployer obligations apply even if you purchased an AI system from a vendor that claims to be "EU AI Act compliant." Compliance is a shared responsibility. You cannot outsource your deployer obligations to your provider.
Phase 5: Timeline and Roadmap
Build a concrete roadmap with milestones aligned to the regulation's phased enforcement.
Phase 6: Ongoing Compliance
Compliance is not a one-time project. The AI Act requires continuous monitoring and adaptation.
Checklist: Continuous Obligations
- Monitor AI system performance post-deployment — track accuracy, bias, and reliability metrics over time
- Update technical documentation whenever the system is substantially modified (Article 43(4))
- Report serious incidents to the relevant market surveillance authority within the required timeframe
- Stay current with regulatory guidance — the AI Office, AI Board, and national authorities will continue to issue implementing acts, standards, and codes of practice in the run-up to the 2027 and 2028 high-risk dates, and the Article 6(5) classification guidelines are still in draft
- Conduct periodic internal audits of your AI systems against the regulation's requirements
- Retrain your teams as the regulatory landscape evolves
- Maintain your AI register — keep it current as systems are added, modified, or retired
Organisations that treat AI Act compliance as an ongoing programme — not a one-time checkbox exercise — will find themselves better positioned not just for regulatory compliance, but for building AI systems that are genuinely trustworthy. The requirements for data governance, transparency, human oversight, and robustness are simply good engineering practices codified into law.
Common Pitfalls for Technology Leaders
Based on the regulation's requirements and the obligations now in force, here are the mistakes CTOs and CIOs should actively avoid:
Underestimating scope. The AI Act's definition of "AI system" is broader than many expect. If you only look at systems explicitly labelled as "AI" or "ML," you will miss rule-based systems, statistical models, and embedded AI in third-party tools.
Treating compliance as legal-only. AI Act compliance requires deep technical work — data governance, logging, testing, documentation. Legal teams cannot do this alone. Engineering leadership must be directly involved.
Ignoring deployer obligations. Many CTOs assume that if they buy an AI system from a compliant vendor, they are covered. They are not. Deployers have independent obligations for human oversight, monitoring, and input data quality.
Reading the deferral as a reprieve. The high-risk dates moved, but enforcement of the AI Act began on 2 August 2026 and Article 50 transparency is binding today. Organisations that hear "delay" and stand their programme down are exposed on the obligations that are already live, and will start the high-risk work too late to finish it.
Overlooking GPAI model obligations. If your organisation provides or fine-tunes a general-purpose AI model, additional requirements under Articles 51-55 have applied since 2 August 2025. Chapter V was not substantively amended by Regulation (EU) 2026/1744, the systemic-risk threshold remains 10^25 cumulative training FLOP, and models placed on the market before 2 August 2025 still have until 2 August 2027 to comply under Article 111(3).
Conclusion
EU AI Act compliance is a technical and organisational challenge that sits squarely in the CTO's and CIO's domain. The checklist above provides a structured path from discovery through ongoing compliance, aligned with the regulation's phased enforcement timeline.
The organisations that will navigate this transition most smoothly are those that invest in systematic inventory and classification now, keep the already-binding obligations under control, and treat compliance not as a burden but as an opportunity to build AI systems that are transparent, robust, and worthy of trust.
The dates are settled: Article 50 transparency and the enforcement machinery are live, Annex III high-risk obligations arrive on 2 December 2027, and Annex I on 2 August 2028. The deferral is unconditional, so there is no further slippage to plan around. The requirements are defined. The question is whether your organisation will be ready.
Make Your AI Auditable and Compliant
Ctrl AI provides expert-verified reasoning units with full execution traces — the infrastructure you need for EU AI Act compliance.
Explore Ctrl AIRelated Articles
EU AI Act Compliance for Startups and SMEs
How small and medium-sized enterprises and startups can navigate EU AI Act compliance — proportional penalties, sandbox access, simplified documentation, and a pragmatic compliance roadmap on a startup budget.
Technical Documentation Requirements for AI Systems
What technical documentation is required under the EU AI Act — Annex IV requirements, risk management records, data governance documentation, and how to maintain compliance.
AI-Generated Content Labelling Under the EU AI Act
Article 50 of the EU AI Act requires machine-readable marking and user-facing disclosure of AI-generated content. Practical guidance on what to label, who is responsible, and the technical implementation.