EU AI Act Checklist 2026: 8 Steps for Businesses

Which AI applications should be reviewed first?

EU AI Act Checklist – Eight Steps to Robust AI Governance

What steps must companies take now under the EU AI Act?

The EU AI Act is now in effect, the first obligations are being enforced, and new AI tools are constantly appearing in companies. For small and medium-sized enterprises, therefore, the question is not so much whether they should address the AI regulation, but rather where they should start.

This EU AI Act checklist translates the legal requirements into a practical workflow. It guides you from the AI inventory through role and risk assessment to documentation. The result should not be a file folder that spends its best years gathering dust in a cabinet. The goal is to create a robust process for the actual use of AI.

Date of this post: August 29, 2026.

The short answer is: Companies should first identify their AI applications, determine their role, rule out prohibited practices, and implement the existing requirements for AI competence and transparency. Next, they should assess potential high-risk systems, data protection issues, security requirements, and internal responsibilities.

The following checklist outlines the most effective procedure.


EU AI Act Checklist for Small and Medium-Sized Enterprises: Eight Steps to AI Governance

1. Track all AI systems in use

Without a comprehensive overview, it is impossible to make a reliable assessment. The first step, therefore, is to create a centralized AI inventory. This inventory should include not only officially procured applications, but also free tools, trial accounts, built-in AI features, and in-house solutions.

For each system, at least the following information should be recorded:

  • Name, provider, and version of the application,
  • specific intended use,
  • Responsible department,
  • internal and external user groups,
  • Data types used,
  • affected individuals,
  • Involvement in decisions or business processes,
  • technical interfaces,
  • Contract and privacy policy documents,
  • Date of introduction and last inspection.

AI features within existing software should also be included in the inventory. If an HR, CRM, or collaboration platform suddenly begins evaluating text, sorting job applications, or summarizing conversations, that is not merely a matter of product maintenance. It can affect the legal assessment.

2. Defining Your Role Under the AI Act

The obligations under the AI Act depend largely on the role a company plays. Most small and medium-sized enterprises will act as operators when using a third-party AI system in the ordinary course of business. The English text of the regulation uses the term “deployer” for this purpose.

However, a company can become a provider if it develops an AI system itself or has it developed, and then brings it to market or puts it into operation under its own name. A significant change to the system or its intended purpose may also result in new provider obligations.

Therefore, the following should be documented for each system:

  • Are we using a ready-made system in accordance with the manufacturer's specifications?
  • Should we offer the system under our own name?
  • Should we integrate a model into our own application?
  • Are we making significant changes to the functions or intended use?
  • Do we make the system available to customers or other companies?

The answer must be determined on a per-application basis. A company is not automatically a provider or an operator. It may be an operator for one system and a provider for another. The AI Regulation calls for clear roles, even if companies in their day-to-day operations prefer to wear several hats at once.

3. Eliminate Prohibited AI Practices

Certain AI practices are already prohibited. These include, among other things, particularly harmful manipulative or deceptive practices, certain forms of social scoring, the indiscriminate collection of facial images for the purpose of building recognition databases, and emotion recognition in the workplace, unless a strictly limited exception applies.

A review of potential restrictions should take place before procurement, development, or pilot operations. Some useful questions to consider are:

  • Does the system influence people using manipulative or deceptive methods?
  • Does it specifically exploit a person's particular vulnerability, such as due to age or disability?
  • Does it evaluate people across different areas of life?
  • Does it recognize or assess employees' emotions?
  • Does it process biometric data or create corresponding categories?
  • Does it automatically collect facial images from publicly available sources?

If there are indications of a prohibited practice, the project should not simply be continued under closer scrutiny. First, it must be determined whether the use can be structured in a way that is permissible at all.

4. Implement existing obligations

Not all provisions of the AI Act take effect at the same time. However, some requirements have been in effect for quite some time.

Organizing AI Expertise

Providers and operators must take measures to support the development of AI literacy among employees and other individuals who work with AI systems on their behalf. In doing so, they must take into account prior knowledge, experience, training, the context of use, and potential impacts on affected individuals.

The AI Act does not require all employees to have the same level of knowledge. Instead, a role-based training approach makes more sense:

  • Fundamentals for all users of shared AI applications,
  • in-depth knowledge of IT, procurement, data protection, and compliance,
  • application-specific training for particularly relevant departments,
  • Decision-Making Skills for Managers and Project Leaders.

Appropriate measures can be documented in terms of participation, content, and target audiences. K11 supports companies in this effort with practical AI training tailored to different roles and use cases.

Review Transparency Requirements

The transparency requirements set forth in Article 50 have been in effect since August 2, 2026. Among other things, they apply to AI systems that interact directly with people, machine-readable labels for synthetic content, and disclosure requirements for deepfakes and certain texts concerning matters of public interest.

Companies should therefore consider the following:

  • Are customers or other individuals informed that they are interacting with an AI system?
  • Is AI-generated content technically identifiable when the provider's obligation applies?
  • Are deepfakes clearly labeled?
  • Is there an editorial review process for AI-generated texts on topics of public interest?
  • Are the instructions provided in a timely manner, easy to understand, and visible to the people concerned?

Not every image processed with AI or every text correction automatically requires a visible disclosure. The key factors are the nature, purpose, and scope of AI use. Our article “EU AI Act: When AI Must Be Disclosed” explains the distinctions in detail.

5. Identify potential high-risk AI

Following the amendment to the timeline, the key requirements for high-risk AI set forth in Annex III will generally apply starting December 2, 2027. For AI systems integrated as safety components into regulated products listed in Annex I, the corresponding set of obligations will generally apply starting August 2, 2028.

That doesn't mean companies should put off the audit until then. Processes, contracts, technical documentation, and human oversight are rarely put in place in the week leading up to the deadline.

For small and medium-sized businesses, AI systems that:

  • Analyze applications or preselect candidates,
  • Evaluate employees' performance or conduct,
  • Assigning tasks based on personal characteristics or behavioral data,
  • Support decisions regarding promotions, contract terms, or termination,
  • assess the creditworthiness of individuals, or
  • be used as a safety component of a regulated product.

Whether a system should actually be classified as high-risk AI depends on its specific intended use and the legal requirements. A mere product description provided by the manufacturer is not always sufficient for this purpose. The K11 article “EU AI Act: What Obligations Apply to Your AI System?” provides a more in-depth analysis .

6. Integrating Procurement, Data Protection, and Information Security

The AI Act does not replace the General Data Protection Regulation or requirements regarding information security, copyright, or employee participation in management. An AI system may be permissible under the AI Act but still raise data protection concerns. After all, a nice transparency notice does not remedy unlawful processing; it merely describes it in a more polite manner.

Before making a purchase or granting approval, companies should clarify the following, among other things:

  • What data is processed?
  • Are inputs or outputs used to train the system?
  • Where and for how long is data stored?
  • Which subcontractors are involved?
  • What access and authorization policies are in place?
  • Can data and user accounts be completely deleted?
  • How does the provider report security incidents and significant changes?
  • What documentation does he provide for the AI Act assessment?
  • Are there reliable guidelines for updates and new AI features?
  • Can the company meet the required audit and documentation obligations?

These questions should be incorporated into the procurement and approval process. A separate AI review that begins only after the contract has been signed often leaves remarkably little room for negotiation.

7. Define Responsibilities and Approvals

The AI Act does not generally require the appointment of an AI officer. Nevertheless, companies need clear lines of responsibility.

At a minimum, the following should be addressed:

  • Who maintains the AI inventory?
  • Who evaluates new use cases?
  • Who is responsible for auditing data protection and information security?
  • Who decides on approvals?
  • Who organizes training sessions?
  • Who monitors existing systems?
  • To whom should errors, complaints, and incidents be reported?
  • Who informs management?

If there are multiple systems or departments, an internal or external AI Officer can coordinate these tasks. The AI Officer does not replace senior management, the data protection officer, or the information security officer. The AI Officer’s role is to bring together the various perspectives to create a functional governance process.

8. Document Decisions and Monitor Systems

A one-time approval is not enough. AI systems, provider terms, and operational uses are constantly changing. Therefore, every relevant system should be reviewed on a regular basis.

A streamlined yet robust documentation system should include:

  • AI Inventory,
  • Role and Risk Classification,
  • Investigation of prohibited practices,
  • Approval decision,
  • Vendor and contract documents,
  • Privacy and Security Review,
  • transparency measures implemented,
  • Training certificates,
  • responsible persons,
  • Known limitations,
  • Change and Incident History.

A defined audit cycle is just as useful as ad hoc audits. New features, different data sources, changes in user groups, or an expansion of the system’s intended use should trigger a reassessment.

EU AI Act Checklist: What Can Be Done in the First 30 Days

Companies do not have to set up a complete management system right away. A sensible first step within a month might look like this:

  1. Identify the person in charge and the departments involved.
  2. Compile an initial inventory of existing AI applications.
  3. Prioritize reviewing prohibited or obviously critical operations.
  4. Document provider and operator roles.
  5. Monitor transparency requirements for chatbots and generated content.
  6. Publish a preliminary internal AI policy.
  7. Identify training needs by user group.
  8. Implement a standardized testing and approval process for new AI systems.
  9. Mark any potential high-risk applications for further evaluation.
  10. Set dates for regular inspections and reports.

This does not mean that implementation is complete. However, the company now has a structure in place that allows further requirements to be addressed in an organized manner. That is worth considerably more than a very comprehensive checklist whose only “user” is the download folder.

Frequently Asked Questions About the EU AI Act Checklist

Does the EU AI Act also apply to small and medium-sized enterprises?
Yes. The AI Act does not contain a general exemption for small and medium-sized enterprises. However, the specific obligations that apply depend on the company’s role and the type of AI system used. There are various measures in place to ease the burden on SMEs and provide them with support.

Do companies have to report every AI system?
No. There is no general reporting requirement for every AI application used in a business. However, certain high-risk systems may be subject to registration and documentation requirements.

Is a list of the AI tools in use sufficient?
No. The inventory is only the starting point. In addition, the intended use, role within the company, risk classification, data processing, responsibilities, and required measures must be documented.

Does every company have to appoint an AI Officer?
No. An AI Officer is not generally required by law. However, this role can be useful for consolidating responsibilities and coordinating implementation in a transparent manner.

Is there an official AI Act compliance tool?
The European Commission provides an official AI Act Compliance Checker. It is currently in beta and is intended to serve as a preliminary guide. Its results do not replace a review of the specific use case.

Conclusion

The most important foundation for implementing the EU AI Act is not a complicated legal opinion, but a reliable overview: What AI is used for what purposes, who is responsible, and what impacts might its use have?

Role assessment, risk assessment, training, transparency measures, and documentation are built on this foundation. Companies that integrate these steps early on into procurement, IT, and business processes won’t have to reinvent the AI Act from scratch for every new application.

After all, transparency requires more than just a sticker. It requires a system.