EU AI Act
Compliance checklists
A classification on its own does not make anyone compliant. The checklist is where the Act's requirements become assignable tasks with owners, statuses and attached evidence.
Transcript
A classification alone does not make you compliant. This is where the AI Act's requirements become tracked, assignable work.
Each item maps to an article of the AI Act. Article 9 requires a risk management system running continuously across the whole lifecycle. Article 10 requires training and testing data to be relevant, representative and examined for bias.
The AI Act's Article 11 and Annex 4 require technical documentation before the system reaches the market. Article 12 requires automatic logging across its lifetime so behaviour can be traced after the fact.
The AI Act's Article 13 requires deployers to receive real instructions. Article 14 requires a human who can genuinely understand, override and stop the system. Article 15 requires accuracy and resilience against data poisoning and adversarial attack.
Opening an item shows its full obligation text and the evidence already attached to it.
Evidence attaches directly to the item it proves: a test report, a policy excerpt, a signed-off document, not just a status changed from pending to done.
Marking an item complete moves the system's compliance score. The score measures evidence produced, not confidence expressed.
The stakes are set by the AI Act's Article 99. A prohibited practice can cost up to thirty-five million euro or seven per cent of worldwide annual turnover. Breaching these obligations can cost up to fifteen million euro or three per cent.
Why this is required
Articles 9 to 15 set out the conditions a high-risk AI system must meet before it can lawfully be placed on the market. They are cumulative: meeting six of seven is not partial compliance, it is non-compliance.
Article 9 requires a risk management system that runs continuously and iteratively across the entire lifecycle. The word 'continuous' is doing real work: a risk assessment performed once at launch and filed does not satisfy it.
Article 10 requires training, validation and testing datasets to be relevant, sufficiently representative, and to the best extent possible free of errors and complete, and requires examination for biases likely to affect health, safety or fundamental rights.
Article 11 requires technical documentation per Annex IV before market placement. Article 12 requires automatic logging over the system's lifetime to ensure traceability appropriate to its intended purpose.
Article 13 requires deployers to receive instructions covering capabilities, limitations, accuracy and risks. Article 14 requires the system to be designed so a human can genuinely understand, monitor, interpret, override and stop it: meaningful oversight, not a person nominally in the loop who cannot in practice intervene.
Article 15 requires appropriate accuracy, robustness and cybersecurity, including resilience against data poisoning and adversarial examples.
What EuroCompliant does
Registering and classifying a system generates its checklist automatically. High-risk systems receive the full set; limited-risk systems receive the AI Act's Article 50 transparency items.
Each item names the article it discharges, so the checklist is readable as a compliance argument rather than as an opaque task list.
Items carry a status (pending, in progress, complete) and an owner, and evidence artefacts attach directly to them.
The compliance score reflects evidence produced, not confidence expressed. It moves when work is actually done.
Walking through it
Review the generated obligation set
Confirm the items match the system's classification. If they look wrong, the classification is usually what is wrong.
Open /compliance-docs →Assign owners
The AI Act's Article 26 duties are only enforceable inside an organisation if someone in particular holds them. An item owned by everyone is owned by no one.
Attach evidence as you complete items
Policies, test results, approvals, contracts, screenshots. A ticked box with nothing behind it is an assertion, not a demonstration.
Open /evidence →Re-check after any material change
The AI Act's Article 9 is continuous. A model retrain, a purpose change or a new data source should send you back through the affected items.
The law
Risk management system
A continuous, iterative process across the whole lifecycle to identify, evaluate and mitigate risks to health, safety and fundamental rights.
Data and data governance
Datasets must be relevant and representative, and examined for biases likely to affect health, safety or fundamental rights.
Record-keeping
High-risk systems must technically allow automatic recording of events over their lifetime to ensure traceability.
Human oversight
Systems must be designed so natural persons can effectively understand, monitor, override and stop them.
Accuracy, robustness and cybersecurity
Appropriate levels of accuracy and resilience, including against data poisoning and adversarial examples.
Penalties for non-compliance
Non-compliance with the Article 9-15 obligations attracts fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, under Article 99.
Frequently asked
Is a person reviewing outputs enough for Article 14?
Only if that review is meaningful. Article 14(4) requires the overseer to be able to properly understand the system's capacity and limits, remain aware of automation bias, correctly interpret the output, and decide not to use it or to override it. A reviewer approving hundreds of outputs an hour with no practical ability to disagree does not meet that standard.
We bought the system. Do we still need all this?
Your obligation set is different, not absent. Most of Articles 9-15 fall on the provider, but as deployer you carry Article 26: use per instructions, assign competent oversight with authority to act, ensure input data is relevant, monitor operation, and keep logs for at least six months.
Related guides
Risk classification
The Article 6 assessment that decides which obligations a system carries, and why the reasoning matters as much as the result.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Post-market monitoring
The Article 72 duty to actively watch a high-risk system for its whole life, and why AI systems degrade without anyone changing the code.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial