🇩🇪
EU AI Act Compliance checklist

EU AI Act Compliance Checklist for mid-sized businesses

EU AI Act • 4 May 2026

As of: 24 June 2026 · Reading time: 7 min

Teilen:

Key takeaways

  • A structured checklist that enables medium-sized companies to systematically build up their EU AI Act compliance – from stocktaking to risk classification to ongoing governance.

A structured checklist that enables medium-sized companies to systematically build up their EU AI Act compliance – from stocktaking to risk classification to ongoing governance.

Digitalization is not an IT project—it is a business strategy.

Björn Groenewold, Managing Director, Groenewold IT Solutions

EU AI Act Compliance checklist for mid-level

Short: This EU AI Act compliance checklist is aimed at medium-sized companies that use AI systems (operators) or commissioned (factual providers).

This EU AI Act compliance checklist is aimed at medium-sized companies that use AI systems (operators) or commissioned (factual providers).

It does not replace legal advice for individual cases, but gives a structured working base for entering the AI act compliance.

The complete background to the EU AI Act can be found in our article EU AI Act: What Companies 2026 need to know and High Risk Classification.

Phase 1: stocktaking

Short: Short response: A structured checklist with which medium-sized enterprises systematically build up their EU AI Act compliance – from stocktaking to risk classification to ongoing governance.

Short response: A structured checklist with which medium-sized enterprises systematically build up their EU AI Act compliance – from stocktaking to risk classification to ongoing governance.

Decision-makers around EU AI Act use compliance checklist for mid-sized businesses cost calculator: AI development, digitalization in mid-sized businesses and IT-security as structured next steps.

** Creating AI inventory** Capture all AI systems in the company – including embedded AI functions in existing software (HR tools, CRM, ERP, marketing platforms, recruiting software).

Enter for each system:

  • Name, provider, version
  • Purpose and areas used
  • Processed data types
  • decisions that support or make the system
  • Number of persons affected (employees, customers, third parties)

** Clear your own role** Are you providers, operators, importers or traders? For internally developed AI: provider. For purchased systems: operator. When ordering an agency for customer software: provider.

** Examination of prohibitions ** Do you use social scoring, biometric real-time monitoring or unconscious manipulation? If yes: immediate shutdown or legal advice.

phase 2: classification

** Annex I check ** Are AI systems integrated into regulated product categories as safety components? (machines, medical devices, vehicles, elevators etc.)

** Annex III check ** Falling systems into one of the eight high-risk areas?

  • Biometric identification
  • Critical infrastructure
  • Education/training
  • Employment / HR ☐
  • Key services (credit, insurance) ☐
  • Law enforcement
  • Migration / asylum ☐
  • Legal care

** Exemptions check** Does the auxiliary function take? Document the reasons in writing.

** Creating classification documentation **Keep the result and justification for each AI system in writing – even when classed as non-high risk.

Phase 3: Obligations for high-risk systems as operators

Short: ** Procure conformity documentation** CE marking, EU declaration of conformity, request technical documentation from the AI provider.

** Procure conformity documentation** CE marking, EU declaration of conformity, request technical documentation from the AI provider. No high-risk system without using these documents.


Will the system be used only in the intended use provided by the provider? Deviations can trigger own vendor tiles.

** Ensure human supervision ** Are processes defined in which a person can monitor, understand and oversteer the AI system? Documentation of supervisory processes.

** Check input data ** Are the input data relevant and representative of the intended use? Identify and document systemic distortions.

** Set up protocols** Will the operation and decisions of the system be sufficiently recorded? Set log retention periods.

** Employee training ** All employees who use or monitor the high-risk system must be trained accordingly. Training documentation.

** Define incident reporting process** In case of serious incidents or risks: to whom is reported in which period?

Phase 4: Obligations for AI as client/provider

Short: If you order AI software for third parties and become a factual provider:

If you order AI software for third parties and become a factual provider:

** Plan conformity assessment procedures** For high-risk systems: what method (self-assessment or notified body)?

** Create technical documentation according to Annex IV ** Mandatory content: description of the system, development process, training and test data, risk management, monitoring measures.

** Building quality management system ** High-risk providers need a formal QM system for the entire life cycle.

** clarifying contractual responsibilities** When ordering an AI agency: Who carries what compliance responsibility contractually? This question about software development with AI components will be resolved from the outset.

** Create post-market monitoring plan ** How are risks observed after go-live, incidents detected, updates controlled?

Phase 5: Transparency obligations (all AI systems)

Short: ** characterize chatbots and AI avatars** Users need to know that they interact with AI.

** characterize chatbots and AI avatars** Users need to know that they interact with AI. Insert notice at the beginning of each conversation.

** Identify AI-generated content** Texts, images, videos that have generated AI and are used publicly must be identified accordingly (deepfake control).

** Staff information **Inform employees transparently about AI systems that affect their work or evaluation. Include works council if available.

Phase 6: Current governance

Short: ** Al Act Manager ** Who is responsible for AI compliance in the company?

** Al Act Manager ** Who is responsible for AI compliance in the company? Define clear responsibility.

** Plan regular review ** AI Act and EU-Guidance continue to develop. Plan at least annual review of the AI inventory and classifications.

** Check new AI projects AI-Act-first ** Before each new AI project: clarify classification and compliance requirements before development begins.

** Contract protection for suppliers ** In contracts with AI service providers, make sure that they meet their AI-act lines and provide appropriate documentation.

Helpful: When external support makes sense

  • Yes. In the first inventory and classification: External view reduces blind spots
  • Yes. For high-risk systems you develop or commission: legal advice for conformity assessment
  • Yes. In case of unclear risk classification: expert opinion creates legal certainty
  • In case of reporting obligations to authorities: legal assistance recommended

Our team supports you in AI-Act-compliant AI implementation and consulting. The checklist above is a good starting point – the specific system architecture and mode of use are always decisive for the specific individual case.

Frequently Asked Questions (FAQ)

Is there an official EU compliance tool?

The EU-AI authorities (AIDA) are working on guidelines and tools. At booth 2026 there are first orientation documents, but not yet a complete self-assessment tool with legal binding.

When do we have to count on controls by authorities?

National market surveillance authorities are building capacity. Preliminary examinations (after complaints or incidents) are expected earlier than complete checks.

Does our GDPR documentation provide the basis for AI-act compliance?

Partial as a starting point. GDPR impact assessments (DSFA) for AI systems overlap with AI act requirements, but are not identical. Both are to be performed separately.

What is the difference between AI Act and AI Liability Directive?

The AI Act regulates ex-ante requirements (which must/ must meet a system). The AI Liability Directive (still in coordination) regulates ex-post liability (who is liable if something goes wrong).

Both together form the EU legal framework for AI.


Additional notes

Learn more:

EU AI Act Consulting – technical and organizational compliance support for your company: risk classification, documentation obligations and AI governance. Artificial Intelligence

Next consultation appointment →

Integration into your IT landscape

Typical integration points are ERP, CRM, identity providers, payment services and industry software. stable contracts, version policy for APIs and transparent error semantics – so that partners and internal teams do not have to guess.

If you need support in technical implementation, we will gladly arrange EU AI Act compliance checklist for mid-sized businesses into your existing architecture – including prioritization and resilient releases. Matching entry points: Software development, IT consulting.

EU AI Act Compliance checklist for mid-level

can be successfully implemented when technology, organization and measurability fit together – instead of insulated tool rollouts without process reference.

Use the overview in this article as a basis for discussion on priorities, risks and the first loadable pilot.

Intensify matching topics in category overview Blog category and check operational support via Software development, IT consulting. Groenewold IT accompanies analysis, implementation and operation – from the first classification to scalable releases.

The following independent references complement the classification on the topics of this Article:

"DevOps means less tool sense than common responsibility for quality and rollout – without that, automation remains superficial."

— *Björn Groenewold, Managing Director, Groenewold IT Solutions *

Conclusion and next steps

About the author

Björn Groenewold
Björn Groenewold(Dipl.-Inf.)

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH

Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.

Software ArchitectureAI IntegrationLegacy ModernisationProject Management

Blog recommendations

Related articles

These posts might also interest you.

Free download

Checklist: 10 questions before software development

Key points before you start: budget, timeline, and requirements.

Get the checklist in a consultation

Relevant next steps

Related services & solutions

Based on this article's topic, these pages are often the most useful next steps.

More on this topic

More on EU AI Act and next steps

This article is in the EU AI Act topic. In our blog overview you will find all articles; under category EU AI Act more posts on this subject.

For topics like EU AI Act we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.

If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.

Next Step

Questions about this topic? We're happy to help.

Our experts are available for in-depth conversations – practical and without obligation.

30 min strategy call – 100% free & non-binding