New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

EU AI Act

Compliance checklists

A classification on its own does not make anyone compliant. The checklist is where the Act's requirements become assignable tasks with owners, statuses and attached evidence.

Transcript

A classification alone does not make you compliant. This is where the AI Act's requirements become tracked, assignable work.

Each item maps to an article of the AI Act. Article 9 requires a risk management system running continuously across the whole lifecycle. Article 10 requires training and testing data to be relevant, representative and examined for bias.

The AI Act's Article 11 and Annex 4 require technical documentation before the system reaches the market. Article 12 requires automatic logging across its lifetime so behaviour can be traced after the fact.

The AI Act's Article 13 requires deployers to receive real instructions. Article 14 requires a human who can genuinely understand, override and stop the system. Article 15 requires accuracy and resilience against data poisoning and adversarial attack.

Opening an item shows its full obligation text and the evidence already attached to it.

Evidence attaches directly to the item it proves: a test report, a policy excerpt, a signed-off document, not just a status changed from pending to done.

Marking an item complete moves the system's compliance score. The score measures evidence produced, not confidence expressed.

The stakes are set by the AI Act's Article 99. A prohibited practice can cost up to thirty-five million euro or seven per cent of worldwide annual turnover. Breaching these obligations can cost up to fifteen million euro or three per cent.

Why this is required

Articles 9 to 15 set out the conditions a high-risk AI system must meet before it can lawfully be placed on the market. They are cumulative: meeting six of seven is not partial compliance, it is non-compliance.

Article 9 requires a risk management system that runs continuously and iteratively across the entire lifecycle. The word 'continuous' is doing real work: a risk assessment performed once at launch and filed does not satisfy it.

Article 10 requires training, validation and testing datasets to be relevant, sufficiently representative, and to the best extent possible free of errors and complete, and requires examination for biases likely to affect health, safety or fundamental rights.

Article 11 requires technical documentation per Annex IV before market placement. Article 12 requires automatic logging over the system's lifetime to ensure traceability appropriate to its intended purpose.

Article 13 requires deployers to receive instructions covering capabilities, limitations, accuracy and risks. Article 14 requires the system to be designed so a human can genuinely understand, monitor, interpret, override and stop it: meaningful oversight, not a person nominally in the loop who cannot in practice intervene.

Article 15 requires appropriate accuracy, robustness and cybersecurity, including resilience against data poisoning and adversarial examples.

What EuroCompliant does

Registering and classifying a system generates its checklist automatically. High-risk systems receive the full set; limited-risk systems receive the AI Act's Article 50 transparency items.

Each item names the article it discharges, so the checklist is readable as a compliance argument rather than as an opaque task list.

Items carry a status (pending, in progress, complete) and an owner, and evidence artefacts attach directly to them.

The compliance score reflects evidence produced, not confidence expressed. It moves when work is actually done.

Walking through it

1

Review the generated obligation set

Confirm the items match the system's classification. If they look wrong, the classification is usually what is wrong.

Open /compliance-docs →
2

Assign owners

The AI Act's Article 26 duties are only enforceable inside an organisation if someone in particular holds them. An item owned by everyone is owned by no one.

3

Attach evidence as you complete items

Policies, test results, approvals, contracts, screenshots. A ticked box with nothing behind it is an assertion, not a demonstration.

Open /evidence →
4

Re-check after any material change

The AI Act's Article 9 is continuous. A model retrain, a purpose change or a new data source should send you back through the affected items.

The law

Penalties for non-compliance

Non-compliance with the Article 9-15 obligations attracts fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, under Article 99.

Frequently asked

Is a person reviewing outputs enough for Article 14?

Only if that review is meaningful. Article 14(4) requires the overseer to be able to properly understand the system's capacity and limits, remain aware of automation bias, correctly interpret the output, and decide not to use it or to override it. A reviewer approving hundreds of outputs an hour with no practical ability to disagree does not meet that standard.

We bought the system. Do we still need all this?

Your obligation set is different, not absent. Most of Articles 9-15 fall on the provider, but as deployer you carry Article 26: use per instructions, assign competent oversight with authority to act, ensure input data is relevant, monitor operation, and keep logs for at least six months.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial