AI Act compliance checklist: 8 steps to bring your company into compliance

While the AI Act does not mandate a specific compliance checklist, it remains the most reliable way to demonstrate that you are meeting your obligations. The process consists of eight steps: inventory all AI systems used within the organization, classify them according to the four risk levels defined by the AI Act, identify applicable obligations based on your role in the value chain (provider, deployer, importer, or distributor), compile verifiable documentation, develop AI literacy among relevant teams, integrate the framework with the GDPR (which remains in effect), evaluate suppliers and models used—including GPAI—and schedule regular audits. Finally, ten checkpoints allow you to verify your organization's actual progress.

By
Rémy Bozonnet
1
Min
Share this article
IT Checklist

The AI Act marks a major milestone in the regulation of artificial intelligence in Europe. Following years of focus on data protection under the GDPR, organizations must now structure the governance of their AI systems to meet new requirements.

For DPOs, legal departments, CISOs, and innovation managers, one question comes up repeatedly: where do we start to become AI Act compliant?

The answer lies not in simply reading the regulation, but in following a structured approach. This AI Act compliance checklist guides you step-by-step to identify priority actions, mitigate risks, and build sustainable compliance.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Télécharger la plaquette AI Act

Why use an AI Act compliance checklist?

AI Act compliance is not a one-off project. Companies adopt new artificial intelligence tools every month, develop business use cases, and work with an ever-growing number of suppliers.

Without a methodology, it quickly becomes difficult to answer essential questions such as:

  • which AI systems are used within the company?
  • which ones are subject to specific obligations?
  • is the necessary documentation available?
  • are the teams sufficiently trained?
  • how can compliance be demonstrated during an inspection?

A checklist helps structure this process and ensures ongoing monitoring, rather than reacting only during an audit or a regulatory change.

Step 1: inventory all AI systems in use

The first step is to establish a register of AI systems. This inventory must cover both internally developed solutions and tools acquired from vendors or used directly by business departments.

Some examples:

  • conversational assistants: ChatGPT Enterprise, Copilot, Gemini
  • HR solutions incorporating recommendation algorithms
  • marketing tools that automatically generate content
  • document analysis software
  • fraud detection solutions
  • models embedded in business software

In many organizations, this mapping reveals uses unknown to the IT or legal departments.

Centralizing this inventory is the foundation of any compliance approach. It is also the first step toward sustainable governance, especially when managed within a dedicated AI compliance platform.

Step 2: classify each AI system according to its risk level

Not all AI systems are subject to the same obligations. The AI Act distinguishes between several risk categories.

Prohibited practices

Certain uses are banned due to the level of risk they pose to fundamental rights.

High-risk AI systems

These primarily concern sensitive sectors such as human resources, critical infrastructure, healthcare, and certain security devices. These systems are subject to the most stringent governance and documentation requirements.

Limited-risk systems

These remain permitted but impose transparency obligations toward users.

Minimal-risk systems

Most common use cases fall into this category and are subject to much more limited obligations.

Misclassifying the risk level can lead to applying inappropriate obligations or, conversely, overlooking certain regulatory requirements.

Step 3: Identify the AI Act obligations applicable to your organization

Once the classification is complete, you can precisely identify the applicable obligations. Key requirements include:

  • implementing a risk management system
  • data quality and governance
  • technical documentation
  • retaining specific information for traceability
  • human oversight
  • monitoring system performance
  • incident management

Not all of these obligations apply to every company. They depend on your role in the value chain—whether as a provider, deployer, importer, or distributor—as well as the AI system's risk category.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Step 4: Build robust documentation

Compliance is not just about the actions taken, but also about the ability to demonstrate them. Structured documentation is essential for maintaining:

  • AI system descriptive sheets
  • risk assessments
  • qualification decisions
  • internal procedures
  • proof of controls
  • governance policies

Take this example: A company uses AI to assist its recruiters without automating the final decision. In the event of an audit, it must be able to explain why this use case does not qualify as a high-risk system or, if it does, demonstrate that all applicable requirements are met.

The more centralized and up-to-date this documentation is, the easier it becomes to prepare for audits.

Step 5: Develop AI literacy within the company

The AI Act also introduces an often underestimated obligation: AI literacy. In practical terms, individuals using AI systems must have a level of understanding appropriate to their roles.

This particularly concerns:

  • HR teams
  • legal departments
  • DPOs
  • CISOs
  • business unit managers
  • employees using generative AI tools on a daily basis

Training users is not just about learning how to use a tool. It is also about understanding:

  • model limitations
  • bias risks
  • impacts on personal data
  • individual responsibilities

This upskilling directly contributes to reducing operational and legal risks.

Step 6: Aligning the AI Act with the GDPR

The AI Act does not replace the GDPR. The two regulations are complementary.

When an AI system processes personal data, it remains essential to verify, in particular:

  • the legal basis for processing
  • data minimization principles
  • information obligations
  • security measures
  • the potential need to conduct a Data Protection Impact Assessment (DPIA)

This alignment is particularly important for HR projects, internal assistants, or data analysis tools.

Organizations already equipped with GDPR compliance software often have a solid foundation that should be extended to AI system governance to avoid documentation silos.

Step 7: Verify AI providers and models used

Many companies now use AI models developed by third-party providers. It is essential to identify:

  • which models are being used
  • what guarantees are provided by the vendor
  • what documentation is available
  • what responsibilities fall to each party

This review must also include General Purpose AI (GPAI) models, which are now regulated by the AI Act.

Effective vendor governance helps anticipate regulatory changes and ensures readiness for future audits.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Step 8: Schedule regular AI compliance audits

Compliance is an ongoing process. Every new AI project, change of vendor, or regulatory update requires a reassessment.

Periodic audits are essential to verify:

  • that the AI system registry is up to date
  • that new applications have been properly qualified
  • that documentation is complete
  • that training has been completed
  • that procedures remain appropriate

The most mature organizations integrate these checks into their overall compliance governance, just as they do with GDPR or cybersecurity audits.

Your 10-point AI Act compliance checklist

Before considering your organization compliant, ensure you can answer "yes" to each of these questions:

  • all AI systems have been identified
  • a registry of AI systems is kept up to date
  • each system has been classified according to its risk level
  • applicable obligations have been identified
  • technical documentation is centralized
  • responsibilities are clearly defined
  • relevant employees have been trained
  • interactions with GDPR have been analyzed
  • AI providers have been evaluated
  • a periodic audit process is planned

If several boxes remain to be checked, it is recommended that you structure your approach using a dedicated tool to centralize your inventory, documentation, assessments, and compliance tracking in a single environment.

What are the penalties for non-compliance with the AI Act?

The AI Act provides for administrative fines that can be particularly high depending on the nature of the breach.

Beyond financial risk, organizations also face:

  • reputational damage
  • restrictions on certain AI systems
  • increased oversight
  • a loss of trust from partners and clients

Compliance should therefore not be viewed as a mere regulatory constraint, but as a genuine driver for risk management and governance.

Why rely on an AI compliance platform?

As artificial intelligence projects multiply, the limitations of tracking them in Excel quickly become apparent.

A specialized platform allows you to:

  • map all AI systems
  • maintain a centralized register
  • document risk assessments
  • keep records of compliance
  • track regulatory obligations
  • facilitate internal and external audits

By using a solution capable of bridging GDPR and AI Act requirements, organizations avoid redundant documentation and gain a consolidated view of their compliance.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

Conclusion: From a checklist to true AI governance

The AI Act introduces a new way of governing artificial intelligence usage. Companies that succeed in their compliance efforts will be those that implement a structured, documented, and scalable approach.

Starting with a reliable inventory, assessing risks, documenting decisions, training teams, and organizing regular audits is currently the best approach for building sustainable compliance.

More than just a simple to-do list, this AI Act compliance checklist serves as the starting point for true AI governance, capable of supporting company innovation while meeting European requirements.

FAQ - AI Act compliance checklist

Is an AI Act compliance checklist mandatory?

No, the European AI Act does not mandate the use of a checklist per se. However, affected organizations must be able to demonstrate that they meet the obligations applicable to them. A checklist is an excellent management tool to ensure no steps are missed and to facilitate internal or external audits.

Are all companies affected by the AI Act?

Yes, but not with the same level of obligations. Requirements depend on the organization's role—whether provider, deployer, importer, or distributor—as well as the type of AI system used and its risk level. An SME using only generative AI tools will not have the same obligations as a company developing a high-risk AI system.

How do I know if an AI system is considered high-risk?

The AI Act precisely defines the categories of high-risk AI systems within its text and annexes. This classification depends primarily on the system's intended purpose and the sector of activity involved. A classification step is essential before beginning any compliance process.

Is an AI system registry mandatory?

The AI Act imposes documentation and traceability obligations on certain actors. In practice, maintaining an AI system registry is highly recommended to track usage, monitor completed assessments, and demonstrate organizational compliance.

Does the AI Act replace the GDPR?

No. The AI Act and the GDPR are complementary. When an artificial intelligence system processes personal data, GDPR obligations continue to apply, particularly regarding the lawfulness of processing, security, transparency, and, where necessary, Data Protection Impact Assessments (DPIAs).

What are the penalties for non-compliance?

The AI Act provides for a regime of administrative fines that can reach several million euros or a percentage of total worldwide annual turnover, depending on the nature and severity of the infringement. Beyond the financial aspect, non-compliance can also lead to restrictions on the use of certain AI systems, increased oversight, and significant reputational damage to the company.

How can AI Act compliance management be simplified?

Compliance quickly becomes complex when multiple departments use different AI systems. Centralizing the AI system registry, documentation, risk assessments, compliance evidence, and follow-up actions in a dedicated platform improves efficiency, reduces oversights, and simplifies audits. For organizations already committed to GDPR compliance, a solution that unifies both GDPR and AI Act requirements offers more consistent and sustainable governance.

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.

The latest news

They have trusted us for years

Discover Adequacy

One of our experts introduces Adequacy to you in a real situation.