Updated for the June 2026 Omnibus

EU AI Act compliance checklist

Six steps, in the order that saves you the most work. Step 2 alone removes obligations for a lot of companies that assumed they had them.

Last updated 7 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

Check the date on any checklist you read, including this one. The June 2026 Omnibus moved several deadlines. A great deal of published guidance still carries the pre-Omnibus dates, which means it tells high-risk providers they are late when they are not, and tells chatbot builders they have time when they don't. Every date below is post-Omnibus.

Most AI Act checklists are a flat list of obligations. That's the wrong shape, because roughly half of what's on those lists won't apply to you — and which half depends on two answers you can work out in about twenty minutes.

So this is ordered. Each step either removes work or narrows it. Do them in sequence and you'll spend your effort on the obligations you actually have.

Step 1 — Are you in scope at all?

Two questions.

Is it an AI system? Article 3(1) defines this as a machine-based system that infers, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions. In practice: if there's a model doing inference in your product, you're in. Deterministic rule-based logic — an if/then engine, a scoring formula someone wrote by hand — generally is not, however "smart" the marketing calls it.

Does the EU have jurisdiction? Article 2 reaches providers placing systems on the EU market regardless of where they're established, and — the part people miss — providers and deployers outside the EU where the output is used in the EU. Being incorporated in Delaware does not remove you if your users are in Berlin.

If you're out of scope, stop here. Write down why, date it, and keep it. "We considered it and concluded it doesn't apply" is a defensible position. "We never looked" is not, and it's the one an enterprise procurement team will find.

Step 2 — What is your role?

This is the highest-leverage question in the entire regulation, and it's the one most often answered wrong.

RoleYou are this if…Core duties
ProviderYou develop an AI system and place it on the EU market or put it into service under your own name or trademarkThe full set — risk management, documentation, conformity assessment, CE marking, registration, where high-risk
DeployerYou use an AI system supplied by someone else, under your own authority, in your operationsArticle 26 only. No conformity assessment. No CE marking. No EU database registration.
Distributor / importerYou make someone else's system available on the EU market without putting your name on itArticles 23–24 — verification duties, materially lighter

Founders overwhelmingly assume "provider" because they built something. But if the AI system itself is someone else's and you're using it in your operations — a hiring tool you licensed, a support model you call through an API — you are a deployer of that system, and the difference is enormous. Teams budget for conformity assessments they were never going to owe.

It runs the other way too, and this is the expensive direction. Substantial modification can make you a provider of a system you didn't build. If you take a third-party system and materially change its intended purpose, you can inherit provider duties without ever deciding to.

The full provider vs deployer breakdown, including the mixed case where you're both at once, is worth twenty minutes if there's any doubt.

Step 3 — Did you modify a general-purpose model?

Separate question, separate obligation set, and it catches people out.

Article 53 obligations applied from August 2025 and became enforceable on 2 August 2026. The teams most exposed here are the ones who did a serious fine-tune eighteen months ago for performance reasons, when there was no regulatory reason to think about it. More on the Article 53 threshold.

Step 4 — What is your risk tier?

Work down. Stop at the first that fits.

Unacceptable — Article 5

Banned outright. Real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions), social scoring by or for public authorities, emotion recognition in the workplace or in education, untargeted facial-image scraping, and exploitative manipulation of vulnerable groups. Prohibited since February 2025; enforceable from 2 August 2026. If you land here, this is not a compliance project — it's a product decision.

High risk — Article 6 and Annex III

Annex III lists the areas: employment and worker management, education, credit and essential services, law enforcement, migration and border control, administration of justice, biometrics, and critical infrastructure. Annex I covers AI as a safety component of products already regulated under EU harmonisation law.

Being in an Annex III area does not automatically make you high-risk. Article 6(3) sits directly underneath the list and almost nobody quotes it. A system is not high-risk if it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing human assessment, or does preparatory work — and does not profile natural persons. That last condition is absolute; profile individuals and the exemption is gone regardless of how narrow the task is.

The exemption is not free. A provider relying on it must document that assessment and register the system. "We assumed we were exempt" written up afterwards is not an assessment. How to run the 6(3) check properly.

Limited risk — Article 50

Transparency duties. Systems that interact with people must disclose they're AI. Synthetic content must be labelled. Deepfakes must be disclosed. This is where most chatbots and generative products land — and, critically, Article 50 was not deferred by the Omnibus.

Minimal risk

No mandatory obligations beyond Article 4 AI literacy. Most business software is here.

Step 5 — What is enforceable right now?

ObligationApplies fromStatus
Article 5 — prohibited practicesFeb 2025, enforced 2 Aug 2026Live
Article 4 — AI literacyFeb 2025, enforced 2 Aug 2026Live
Article 50 — transparency2 Aug 2026Live
Article 53 — GPAI providersAug 2025, enforced 2 Aug 2026Live
Annex III high-risk obligations2 Dec 2027Deferred
Annex I high-risk (regulated products)Aug 2028Deferred

Read that table against what you were told in June. "The EU delayed the AI Act" describes rows five and six. Rows one to four are enforceable today, and they're the rows that catch chatbots and generative products — the group most likely to have relaxed.

Deferred is not the same as distant. Conformity assessment, technical documentation and a functioning risk-management system realistically take twelve to eighteen months for a small team. December 2027 means starting work in 2026. Full deadline table.

Step 6 — Do these this week

  1. If you have a chatbot: make it disclose. At or before first interaction, visible to the user — not in your privacy policy. Enforceable now, and it takes an afternoon.
  2. If you generate content: label it. Article 50(2) and (4). Also an afternoon.
  3. Run an AI literacy session and minute it. Article 4 is the cheapest obligation in the regulation. Half a day, attendance recorded, covering what your systems do and how they fail. The record is the compliance.
  4. Write down your role and tier, with reasons, and date it. One page. This is what an enterprise procurement questionnaire is actually asking for.
  5. If you're high-risk: get a fixed quote for conformity assessment. Not to buy yet — to know the number and the lead time.

A note on the fines, because most coverage gets it backwards

You'll see €35M / 7% and €15M / 3% quoted everywhere. Those are ceilings for large companies. Article 99(6) provides that for SMEs and start-ups the fine is the lower of the fixed amount and the percentage of turnover — the inverse of the rule applied to large firms.

For a small company the headline numbers were never aimed at you. Which doesn't make the risk zero — it relocates it. The realistic cost of an unanswerable AI Act position is the enterprise procurement questionnaire you can't complete and the deal that dies quietly in someone else's legal team. That happens long before a regulator has heard your name, and it happens far more often.

Work out your tier in two minutes

Six questions, instant result on screen. Or run the full 32-question assessment for a personalised gap report with your obligations, correct deadlines and a prioritised fix list.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.