What is an AI Act checklist, and how do you use it in practice?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

An AI Act checklist is a structured overview of the obligations your organization must meet under the EU AI Act (Regulation (EU) 2024/1689). To use this checklist, first take stock of your AI systems, classify them by risk level, and then work through the corresponding compliance steps for each category. The law applies to anyone who develops, uses, imports, or distributes AI in the EU. In this article, we answer the most frequently asked questions about AI compliance and how to address them.

Which organizations must comply with the AI Act?

The EU AI Act applies to any organization that develops, places on the market, imports, distributes, or uses AI systems within the European Union, regardless of where that organization is based. Even if you’re based outside the EU but your AI system produces output that’s used within the EU, you’re subject to the law. This makes its scope broad and extraterritorial.

The law distinguishes four roles, each with its own obligations:

  • Provider: the party that develops and markets an AI system. Has the most stringent obligations.
  • Deployer (responsible party): any organization that deploys an AI system under its own authority. Has less stringent but still serious obligations.
  • Importer: responsible for verifying compliance before a system enters the EU market.
  • Distributor: Must verify the presence of required documents and suspend distribution in the event of non-compliance.

An important point to note is that you can inadvertently go from being a deployer to a provider. This happens when you put your name on a system, make a substantial change to it, or modify its intended purpose in such a way that the system becomes high-risk. Organizations that purchase AI systems and customize them internally must be vigilant about this. Providers outside the EU are required to designate an authorized representative in the EU.

How does risk classification work under the AI Act?

The AI Act classifies AI systems into four risk levels: prohibited applications, high-risk AI, low-risk AI, and AI with minimal or no risk. The risk level determines which obligations apply to your system. Most AI applications fall into the lowest category and remain largely unregulated.

Prohibited AI Applications

Applications that pose an unacceptable risk are completely prohibited. These include, among other things, manipulative techniques that influence behavior without a person’s awareness and cause harm; social scoring by governments; predictive policing based on profiling; and the creation of facial recognition databases through indiscriminate scraping. Emotion recognition in the workplace or in educational institutions also falls under this prohibition, with the exception of medical or safety applications. These prohibitions have been in effect since February 2, 2025.

High-Risk AI Systems

A system is considered high-risk if it is a safety component of a regulated product that requires a conformity assessment by a third party, or if it falls within one of the eight domains listed in Annex III. These areas are biometrics, critical infrastructure, education and vocational training, employment and human resources management, access to essential services such as credit and insurance, law enforcement, migration and border control, and the administration of justice. Systems that profile individuals are always high-risk.

What is included on an AI Act checklist for high-risk systems?

An AI Act checklist for high-risk systems outlines the mandatory measures that providers and deployers must take to comply with the law. The requirements for providers are the most extensive; deployers have a shorter but still significant list.

For providers, a comprehensive checklist must include at least the following:

  • A continuous risk management system throughout the entire system lifecycle
  • Use of training, validation, and test data that are representative and as free of errors as possible
  • Systematic investigation and mitigation of potential bias
  • Technical documentation in accordance with Annex IV
  • Automatic logging of events throughout the product lifecycle
  • A Clear User Guide for Deployers
  • A design that effectively enables human oversight, including awareness of automation bias
  • Guarantees of accuracy, robustness, and cybersecurity
  • A quality management system
  • A conformity assessment and an EU declaration of conformity
  • CE marking and registration in the EU database

For deployers, the checklist includes:

  • Use the system in accordance with the provider’s user manual
  • Assign human supervision to qualified and trained individuals
  • Retain logs for at least six months
  • Informing Employees Before Commencement of Use (Article 26(7))
  • Conduct a data protection impact assessment (DPIA) where applicable

Under Article 86, individuals who are subject to a decision made by a high-risk system have the right to request an explanation of the factors that determined that decision. As a deployer, you must be able to facilitate this.

When must your organization be compliant with the AI Act?

The AI Act will take effect in phases. The deadline that is most relevant to your organization depends on the role you play and the type of AI system you use or develop. The key dates are:

  • February 2, 2025: The prohibitions set forth in Article 5 and the AI literacy requirement (Article 4) take effect.
  • August 2, 2025: Requirements for GPAI models, governance structures, and penalty provisions take effect. National supervisory authorities must be designated.
  • August 2, 2026: Most requirements for high-risk Annex III systems will become enforceable. This is the most relevant deadline for most organizations.
  • August 2, 2027: Requirements for high-risk AI used as a safety component in regulated products (Annex I) take effect. GPAI models that were on the market before August 2025 must therefore also be compliant.

Since 2026 is the critical deadline for most high-risk applications, now is the time to get your AI registry in order and begin the compliance process.

How do you use the AI Act checklist step by step?

You use an AI Act checklist by systematically following four steps: identifying, classifying, determining obligations, and implementing. Each step builds on the previous one and gives you a clear picture of what still needs to be done.

Step 1: Take inventory of all AI systems. Create a registry of all AI systems that your organization develops, purchases, or uses. For each system, also note the role you play: Are you a provider, deployer, importer, or distributor? Be aware of situations in which you could inadvertently become a provider by making modifications to an existing system.

Step 2: Classify each system by risk level. For each system, determine whether it is prohibited, high-risk, medium-risk, or low-risk. To do so, review the eight domains listed in Annex III and determine whether the system performs profiling of individuals. Document your reasoning, especially if you conclude that an Annex III system does not fall into the high-risk category.

Step 3: Determine the responsibilities for each system and role. Use the checklist from the previous section as a starting point. Also include the AI literacy requirement: your employees must have sufficient knowledge of AI to use it responsibly.

Step 4: Implement and document. Establish the necessary processes, prepare documentation, designate individuals responsible for human oversight, and ensure that logging and retention requirements are in place. Schedule periodic reviews, as AI systems may change risk categories over the course of their lifecycle.

What are the consequences of noncompliance with the AI Act?

Failure to comply with the AI Act may result in substantial fines, depending on the nature of the violation. The fine structure has three tiers and will take effect on August 2, 2025. For small and medium-sized enterprises, the lower of the percentage or the fixed amount applies in each case.

  • Violation of the prohibitions (Article 5): up to 35 million euros or 7% of global annual revenue, whichever is higher.
  • Non-compliance with other obligations: up to 15 million euros or 3% of global annual revenue.
  • Inaccurate or misleading information provided to authorities: up to 7.5 million euros or 1% of global annual revenue.

In addition to fines, there are also reputational risks. Oversight of high-risk AI rests with national market surveillance authorities, which may lead to differences in enforcement priorities among Member States. In January 2026, Finland became the first Member State to grant enforcement powers under Article 99 to its authority. It is therefore realistic to expect that enforcement will become more concrete and proactive in the coming years.

How Pegamento Helps with AI Compliance

AI compliance is not a one-time project, but an ongoing process that combines technical, organizational, and legal aspects. We help Dutch organizations use AI responsibly, positioning Agentic AI for customer service as an evolution from task-oriented bots to self-thinking assistants that take the initiative and act independently. This requires a clear governance structure and thorough documentation—exactly what compliance processes are built upon.

What we specifically offer:

  • Inventory and Classification of Your Existing and Planned AI Systems
  • Assistance with the preparation of technical documentation and risk management systems
  • Implementation of human oversight and logging in accordance with the AI Act requirements
  • Customized solutions using standard building blocks—not costly custom work, but a smart combination of proven modules
  • Everything under one roof: from consulting and implementation to management and support, without complex supplier structures

We are ISO 27001 (information security), ISO 9001, and ISO 26000 certified, which means that information security and quality assurance are structurally embedded in our operations. Would you like to know where your organization stands in terms of AI compliance? Contact us, and we’d be happy to help you figure it out.

Frequently Asked Questions

Hoe weet ik of mijn AI-systeem onder Annex III valt als het meerdere functies heeft?

Als een AI-systeem meerdere functies heeft, beoordeel je elk gebruik afzonderlijk op basis van het beoogde doel. Zodra één van de functies binnen een van de acht Annex III-domeinen valt én een significante invloed heeft op beslissingen over personen, is het systeem als geheel hoog-risico. Documenteer je redenering altijd zorgvuldig, want de toezichthouder kan vragen om een onderbouwing van je classificatiebeslissing.

Wat is precies de AI-geletterdheidsplicht en hoe voldoe ik daaraan?

De AI-geletterdheidsplicht (Artikel 4) verplicht organisaties om ervoor te zorgen dat medewerkers die met AI-systemen werken voldoende kennis en vaardigheden hebben om die systemen verantwoord te gebruiken. In de praktijk betekent dit dat je trainingen aanbiedt, afgestemd op de rol van de medewerker: iemand die een hoog-risico systeem beheert, heeft diepgaandere kennis nodig dan een eindgebruiker. Leg vast welke trainingen zijn gevolgd en wanneer, zodat je dit kunt aantonen bij een eventuele audit.

Geldt de AI Act ook voor AI-systemen die we intern gebruiken en nooit aan klanten aanbieden?

Ja, ook intern gebruikte AI-systemen vallen onder de AI Act als ze hoog-risico zijn, bijvoorbeeld bij gebruik in HR-processen zoals werving, prestatiebeoordeling of ontslag. In dat geval ben je deployer en gelden de bijbehorende verplichtingen, zoals menselijk toezicht, logbewaring en het informeren van werknemers vóór ingebruikname. Alleen AI-systemen die uitsluitend voor persoonlijk, niet-professioneel gebruik worden ingezet, zijn vrijgesteld.

Wat moet ik doen als een leverancier geen technische documentatie of gebruiksaanwijzing kan aanleveren?

Als een aanbieder de verplichte documentatie niet kan leveren, loop je als deployer een serieus compliancerisico. Vraag de leverancier expliciet om de Annex IV-documentatie en een gebruiksaanwijzing conform de AI Act; stel dit eventueel contractueel vast. Kan of wil de leverancier dit niet aanleveren, dan is het verstandig het gebruik van dat systeem te heroverwegen of juridisch advies in te winnen over de verdeling van aansprakelijkheid.

Hoe vaak moet ik mijn AI-register en risicobeoordelingen bijwerken?

Er is geen wettelijk vastgelegde minimumfrequentie, maar de AI Act vereist een continu risicomanagementsysteem gedurende de gehele levenscyclus van een hoog-risico systeem. In de praktijk betekent dit dat je het register en de risicobeoordelingen herziet bij elke substantiële wijziging van een systeem, bij nieuwe use cases, bij veranderingen in de wetgeving of bij incidenten. Een jaarlijkse geplande review is een goede basisregel, aangevuld met ad-hoc updates wanneer de situatie daarom vraagt.

Wat is het verschil tussen een DPIA en een grondrechtenimpactbeoordeling onder de AI Act?

Een DPIA (gegevensbeschermingseffectbeoordeling) is een verplichting onder de AVG en richt zich specifiek op privacyrisico’s bij de verwerking van persoonsgegevens. De grondrechtenimpactbeoordeling (Artikel 27 van de AI Act) is breder en verplicht voor deployers van bepaalde hoog-risico AI-systemen in de publieke sector of bij diensten van publiek belang; deze beoordeelt de impact op een bredere set grondrechten. Beide beoordelingen kunnen overlappen maar zijn niet uitwisselbaar: controleer voor elk hoog-risico systeem of één of beide van toepassing zijn.

Kunnen kleine organisaties en start-ups een vereenvoudigde aanpak volgen voor AI Act compliance?

De AI Act kent geen formele vrijstelling voor kleine organisaties, maar de boetestructuur houdt wel rekening met bedrijfsomvang: voor kmo’s geldt het laagste van het percentage of het vaste bedrag. Praktisch gezien kunnen kleinere organisaties prioriteit geven aan de meest risicovolle systemen en beginnen met een beknopt AI-register en een gedocumenteerde risicoafweging. Schaalbare compliance-bouwblokken, zoals die van gespecialiseerde partners, zijn een kostenefficiënte manier om aan de verplichtingen te voldoen zonder een volledig intern juridisch en technisch team op te bouwen.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.