EU AI ActReg. 2024/1689⚠ August 2 2026Printable Checklist

EU AI Act Compliance Checklist

The five risk-tier obligation sets every SMB facing EU AI Act reach must map — print this, walk it with your team before enforcement begins.

GovernIQ · Full guide at governiq-6huk.polsia.app/eu-ai-act-guide · Verify against Regulation (EU) 2024/1689 — EUR-Lex

1.Prohibited Practices (Art. 5)

Article 5 prohibitions have been enforceable since February 2 2025. AI systems engaging in any of the following practices must not be deployed. Verify absence, not presence — if any deployer system matches, sunset it.

2.High-Risk Annex III + Annex I

High-risk obligations become enforceable August 2 2026. For every Annex III or Annex I high-risk AI system in your stack, the full provider + deployer framework applies. This is the largest operational lift on the calendar.

3.Limited Risk / Art. 50 Transparency

Article 50 transparency duties apply when the AI interacts with natural persons, generates synthetic content, performs emotion recognition or biometric categorisation, or generates deepfakes. Independent of the risk tier — these obligations apply in addition to whatever else applies.

4.Minimal Risk

AI systems outside the prohibited, high-risk, transparency, and GPAI categories. No mandatory obligations beyond Article 4 AI literacy — but voluntary best-practice codes are encouraged.

5.GPAI Model Obligations (Art. 51–55)

Articles 51–55 apply to GPAI model providers. SMBs rarely train GPAI from scratch above the 10²⁵ FLOPs systemic-risk threshold — but fine-tuning or materially modifying a GPAI model can shift your role to provider. The functional trigger is whether the modification materially changes the model's capability profile.