AI Act compliance checklist: 8 steps to bring your company into compliance
While the AI Act does not mandate a specific compliance checklist, it remains the most reliable way to demonstrate that you are meeting your obligations. The process consists of eight steps: inventory all AI systems used within the organization, classify them according to the four risk levels defined by the AI Act, identify applicable obligations based on your role in the value chain (provider, deployer, importer, or distributor), compile verifiable documentation, develop AI literacy among relevant teams, integrate the framework with the GDPR (which remains in effect), evaluate suppliers and models used—including GPAI—and schedule regular audits. Finally, ten checkpoints allow you to verify your organization's actual progress.

The AI Act marks a major milestone in the regulation of artificial intelligence in Europe. Following years of focus on data protection under the GDPR, organizations must now structure the governance of their AI systems to meet new requirements.
For DPOs, legal departments, CISOs, and innovation managers, one question comes up repeatedly: where do we start to become AI Act compliant?
The answer lies not in simply reading the regulation, but in following a structured approach. This AI Act compliance checklist guides you step-by-step to identify priority actions, mitigate risks, and build sustainable compliance.
Why use an AI Act compliance checklist?
AI Act compliance is not a one-off project. Companies adopt new artificial intelligence tools every month, develop business use cases, and work with an ever-growing number of suppliers.
Without a methodology, it quickly becomes difficult to answer essential questions such as:
- which AI systems are used within the company?
- which ones are subject to specific obligations?
- is the necessary documentation available?
- are the teams sufficiently trained?
- how can compliance be demonstrated during an inspection?
A checklist helps structure this process and ensures ongoing monitoring, rather than reacting only during an audit or a regulatory change.
Step 1: inventory all AI systems in use
The first step is to establish a register of AI systems. This inventory must cover both internally developed solutions and tools acquired from vendors or used directly by business departments.
Some examples:
- conversational assistants: ChatGPT Enterprise, Copilot, Gemini
- HR solutions incorporating recommendation algorithms
- marketing tools that automatically generate content
- document analysis software
- fraud detection solutions
- models embedded in business software
In many organizations, this mapping reveals uses unknown to the IT or legal departments.
Centralizing this inventory is the foundation of any compliance approach. It is also the first step toward sustainable governance, especially when managed within a dedicated AI compliance platform.
Step 2: classify each AI system according to its risk level
Not all AI systems are subject to the same obligations. The AI Act distinguishes between several risk categories.
Prohibited practices
Certain uses are banned due to the level of risk they pose to fundamental rights.
High-risk AI systems
These primarily concern sensitive sectors such as human resources, critical infrastructure, healthcare, and certain security devices. These systems are subject to the most stringent governance and documentation requirements.
Limited-risk systems
These remain permitted but impose transparency obligations toward users.
Minimal-risk systems
Most common use cases fall into this category and are subject to much more limited obligations.
Misclassifying the risk level can lead to applying inappropriate obligations or, conversely, overlooking certain regulatory requirements.
Step 3: Identify the AI Act obligations applicable to your organization
Once the classification is complete, you can precisely identify the applicable obligations. Key requirements include:
- implementing a risk management system
- data quality and governance
- technical documentation
- retaining specific information for traceability
- human oversight
- monitoring system performance
- incident management
Not all of these obligations apply to every company. They depend on your role in the value chain—whether as a provider, deployer, importer, or distributor—as well as the AI system's risk category.
Step 4: Build robust documentation
Compliance is not just about the actions taken, but also about the ability to demonstrate them. Structured documentation is essential for maintaining:
- AI system descriptive sheets
- risk assessments
- qualification decisions
- internal procedures
- proof of controls
- governance policies
Take this example: A company uses AI to assist its recruiters without automating the final decision. In the event of an audit, it must be able to explain why this use case does not qualify as a high-risk system or, if it does, demonstrate that all applicable requirements are met.
The more centralized and up-to-date this documentation is, the easier it becomes to prepare for audits.
Step 5: Develop AI literacy within the company
The AI Act also introduces an often underestimated obligation: AI literacy. In practical terms, individuals using AI systems must have a level of understanding appropriate to their roles.
This particularly concerns:
- HR teams
- legal departments
- DPOs
- CISOs
- business unit managers
- employees using generative AI tools on a daily basis
Training users is not just about learning how to use a tool. It is also about understanding:
- model limitations
- bias risks
- impacts on personal data
- individual responsibilities
This upskilling directly contributes to reducing operational and legal risks.
Step 6: Aligning the AI Act with the GDPR
The AI Act does not replace the GDPR. The two regulations are complementary.
When an AI system processes personal data, it remains essential to verify, in particular:
- the legal basis for processing
- data minimization principles
- information obligations
- security measures
- the potential need to conduct a Data Protection Impact Assessment (DPIA)
This alignment is particularly important for HR projects, internal assistants, or data analysis tools.
Organizations already equipped with GDPR compliance software often have a solid foundation that should be extended to AI system governance to avoid documentation silos.
Step 7: Verify AI providers and models used
Many companies now use AI models developed by third-party providers. It is essential to identify:
- which models are being used
- what guarantees are provided by the vendor
- what documentation is available
- what responsibilities fall to each party
This review must also include General Purpose AI (GPAI) models, which are now regulated by the AI Act.
Effective vendor governance helps anticipate regulatory changes and ensures readiness for future audits.
Step 8: Schedule regular AI compliance audits
Compliance is an ongoing process. Every new AI project, change of vendor, or regulatory update requires a reassessment.
Periodic audits are essential to verify:
- that the AI system registry is up to date
- that new applications have been properly qualified
- that documentation is complete
- that training has been completed
- that procedures remain appropriate
The most mature organizations integrate these checks into their overall compliance governance, just as they do with GDPR or cybersecurity audits.
Your 10-point AI Act compliance checklist
Before considering your organization compliant, ensure you can answer "yes" to each of these questions:
- all AI systems have been identified
- a registry of AI systems is kept up to date
- each system has been classified according to its risk level
- applicable obligations have been identified
- technical documentation is centralized
- responsibilities are clearly defined
- relevant employees have been trained
- interactions with GDPR have been analyzed
- AI providers have been evaluated
- a periodic audit process is planned
If several boxes remain to be checked, it is recommended that you structure your approach using a dedicated tool to centralize your inventory, documentation, assessments, and compliance tracking in a single environment.
What are the penalties for non-compliance with the AI Act?
The AI Act provides for administrative fines that can be particularly high depending on the nature of the breach.
Beyond financial risk, organizations also face:
- reputational damage
- restrictions on certain AI systems
- increased oversight
- a loss of trust from partners and clients
Compliance should therefore not be viewed as a mere regulatory constraint, but as a genuine driver for risk management and governance.
Why rely on an AI compliance platform?
As artificial intelligence projects multiply, the limitations of tracking them in Excel quickly become apparent.
A specialized platform allows you to:
- map all AI systems
- maintain a centralized register
- document risk assessments
- keep records of compliance
- track regulatory obligations
- facilitate internal and external audits
By using a solution capable of bridging GDPR and AI Act requirements, organizations avoid redundant documentation and gain a consolidated view of their compliance.
Conclusion: From a checklist to true AI governance
The AI Act introduces a new way of governing artificial intelligence usage. Companies that succeed in their compliance efforts will be those that implement a structured, documented, and scalable approach.
Starting with a reliable inventory, assessing risks, documenting decisions, training teams, and organizing regular audits is currently the best approach for building sustainable compliance.
More than just a simple to-do list, this AI Act compliance checklist serves as the starting point for true AI governance, capable of supporting company innovation while meeting European requirements.
FAQ - AI Act compliance checklist
Is an AI Act compliance checklist mandatory?
No, the European AI Act does not mandate the use of a checklist per se. However, affected organizations must be able to demonstrate that they meet the obligations applicable to them. A checklist is an excellent management tool to ensure no steps are missed and to facilitate internal or external audits.
Are all companies affected by the AI Act?
Yes, but not with the same level of obligations. Requirements depend on the organization's role—whether provider, deployer, importer, or distributor—as well as the type of AI system used and its risk level. An SME using only generative AI tools will not have the same obligations as a company developing a high-risk AI system.
How do I know if an AI system is considered high-risk?
The AI Act precisely defines the categories of high-risk AI systems within its text and annexes. This classification depends primarily on the system's intended purpose and the sector of activity involved. A classification step is essential before beginning any compliance process.
Is an AI system registry mandatory?
The AI Act imposes documentation and traceability obligations on certain actors. In practice, maintaining an AI system registry is highly recommended to track usage, monitor completed assessments, and demonstrate organizational compliance.
Does the AI Act replace the GDPR?
No. The AI Act and the GDPR are complementary. When an artificial intelligence system processes personal data, GDPR obligations continue to apply, particularly regarding the lawfulness of processing, security, transparency, and, where necessary, Data Protection Impact Assessments (DPIAs).
What are the penalties for non-compliance?
The AI Act provides for a regime of administrative fines that can reach several million euros or a percentage of total worldwide annual turnover, depending on the nature and severity of the infringement. Beyond the financial aspect, non-compliance can also lead to restrictions on the use of certain AI systems, increased oversight, and significant reputational damage to the company.
How can AI Act compliance management be simplified?
Compliance quickly becomes complex when multiple departments use different AI systems. Centralizing the AI system registry, documentation, risk assessments, compliance evidence, and follow-up actions in a dedicated platform improves efficiency, reduces oversights, and simplifies audits. For organizations already committed to GDPR compliance, a solution that unifies both GDPR and AI Act requirements offers more consistent and sustainable governance.

