Free template · Excel · English and Dutch
EU AI Act compliance checklist: every obligation per role and risk class (Excel template)
An EU AI Act compliance checklist is an overview of the obligations under the AI Act (Regulation (EU) 2024/1689) that apply to your organisation. For each obligation it records the article, the role that carries it (provider or deployer), since or from when it applies and the evidence you keep. Where AI processes personal data, the GDPR applies as well.
- Last checked against the law
- Editor
- Zahed Ashkara, jurist, privacy and AI
- Version and template ID
- 2.0 ·
praxikon:template:ai-act-checklist - Legal basis
- Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; Regulation (EU) 2016/679 (GDPR); Dutch Works Councils Act (WOR), Article 27
Who is this template for?
- Compliance officer or owner of AI governanceKeeps the checklist and determines the role and risk class for each system (Articles 3, 5, 6 and 25)
- Management of an SME that buys in and uses AIDeployer: AI literacy measures (Article 4), no prohibited practices (Article 5) and the deep fake disclosure (Article 50(4))
- Product team that develops AI or offers it under its own nameProvider: AI notice and marking of output (Article 50(1) and (2)) and, for high-risk AI, the obligations of Article 16, for Annex III from 2 December 2027
- Data protection officer or privacy officerController under the GDPR: legal basis, DPIA and automated decisions (Articles 6, 22 and 35 GDPR)
- HR and employers with employee representativesInforming workers about high-risk AI in the workplace (Article 26(7)) and, in the Netherlands, the works council's right of consent (WOR, Article 27(1)(k) and (l))
- Public authorities and public bodiesRegistering the use in the EU database and a fundamental rights impact assessment for Annex III high-risk AI (Articles 26(8), 49(3) and 27, from 2 December 2027; not for Annex III, point 2)
What is inside
- About this template: seven steps to complete the workbook, and fields for organisation, owner and review date
- Start questions: sixteen questions about your role and your applications (Yes, No or Not sure), plus three calculated derived answers, such as whether a FRIA may be required
- Checklist: 55 rows in twelve sections, from basics, prohibited practices, AI literacy and transparency to general-purpose AI models, high-risk, suppliers, GDPR, works council and governance
- For each row the article, the role that carries the obligation, legal obligation or good practice, the date of application and the evidence you keep
- Two calculated columns per row: does it apply to you, and does it apply now or is it coming
- SME starter set: 17 rows a small organisation that buys in and uses AI starts with
- Dashboard: 24 counts of open items per role and risk class, each with a next step, plus the maximum fines of Article 99 and how supervision is organised
- Timeline: ten dates, from the GDPR (25 May 2018) up to and including 2 August 2030
- Many rows link to the matching free Praxikon template
How to use the template
- On the Start questions sheet, replace the example answers of the fictional wholesaler with your own. Answer each question for the whole organisation: if the answer is Yes for one system, it is Yes.
- Find out what stays on Not sure. The related rows show Check until you know.
- Small organisation? Filter the Checklist on the column SME starter set and start there.
- Give every row that applies to you an owner, an internal deadline and the place where the evidence is kept. Start with the red counts on the Dashboard: those apply now and are not yet done.
- Outside the Netherlands? The AI Act rows apply across the EU. For the works council and national GDPR rows, apply the equivalent law of your Member State.
- Review the checklist at least every six months, for every new or changed application and after a change in the law or new guidelines.
Common mistakes
- Assuming that buying in AI brings no obligations. An organisation that uses AI under its own authority is a deployer (Article 3(4)) and already has obligations, such as AI literacy measures (Article 4), the prohibited practices (Article 5) and the deep fake disclosure (Article 50(4)).
- Treating Article 50 as future law. The transparency obligations have applied since 2 August 2026. Only the marking of output (Article 50(2)) has a transition period until 2 December 2026, and only for systems placed on the market before 2 August 2026.
- Reading Article 4 as a certification duty. Providers and deployers take measures that support AI literacy; the Regulation does not prescribe a fixed level per person or a certificate.
- Forgetting the role shift. If you put your name or trademark on a high-risk system, modify it substantially or use it for an Annex III purpose, you take on the obligations of the provider from 2 December 2027 for Annex III (Article 25(1)).
- Skipping the GDPR because a system is not high-risk. As soon as AI processes personal data, you as controller need a legal basis (Article 6 GDPR), often a DPIA (Article 35 GDPR), and the limits of Article 22 GDPR apply.
When do you need legal advice?
- Your role or risk class is not settled. A start question stays on Not sure, you modify a system or use it for an Annex III purpose, or as provider you want to rely on the derogation of Article 6(3). That choice decides whether you carry the obligations of the provider (Article 16) or those of the deployer (Article 26).
- You use high-risk AI for decisions about people. For example in recruitment, creditworthiness or access to services. As deployer you have the obligations of Article 26 from 2 December 2027 and possibly a FRIA (Article 27). As controller the GDPR already applies, often with a DPIA (Article 35 GDPR) and the limits of Article 22 GDPR.
- An application touches a prohibition or the transparency obligation. A function comes close to Article 5, such as emotion recognition of staff, or you use AI to create or spread a deep fake (image, audio or video that would falsely appear authentic, Article 3(60)), or publish AI-generated text to inform the public on matters of public interest. The prohibitions apply to provider and deployer; as deployer, you have carried the obligation of Article 50(4) since 2 August 2026.
Frequently asked questions
Which AI Act obligations already apply?
As of 6 October 2026: the prohibited practices (Article 5) and the obligation to take AI literacy measures (Article 4) have applied since 2 February 2025, the obligations for providers of general-purpose AI models since 2 August 2025 and the transparency obligations of Article 50 since 2 August 2026. The new prohibitions of Article 5(1)(ba) and (bb) apply from 2 December 2026.
When do the high-risk obligations apply?
For Annex III systems from 2 December 2027, for systems that are high-risk under Annex I from 2 August 2028. These dates follow from Regulation (EU) 2026/1744, in force since 27 July 2026. Systems already placed on the market or put into service before that date are only covered if their design changes significantly afterwards; systems intended to be used by public authorities must comply by 2 August 2030 (Article 111(2)).
We only buy in AI. What is our role?
Usually you are then a deployer (Article 3(4)). If you put your name or trademark on a high-risk system, modify it substantially or use it for an Annex III purpose, you may take on the obligations of the provider (Article 25(1)). The start questions help you check this.
What are the fines, and who supervises?
The Regulation sets maximums that Member States must lay down in their national rules on penalties: up to EUR 35 million or 7% of total worldwide annual turnover for a prohibited practice, up to EUR 15 million or 3% for other obligations and up to EUR 7.5 million or 1% for incorrect information (Article 99). For an SME the lower of the two applies; for a small mid-cap enterprise only under paragraphs 4 and 5. Which authority supervises depends on your Member State. As of 6 October 2026 the Netherlands had not yet designated a market surveillance authority for the AI Act and had no implementing act yet.
Once I have filled in this checklist, am I done with the AI Act?
No. The checklist shows which obligations you have taken up and where your evidence is. A status of Done means you have taken the measure, not that a supervisory authority has assessed it. Review the checklist at least every six months.
Can I use this checklist outside the Netherlands?
Yes. The AI Act and GDPR rows apply in every EU Member State. The rows on the works council (the Dutch Works Councils Act, WOR) and on national GDPR rules (the Dutch implementing act, UAVG) are written for the Netherlands; replace them with the equivalent rules of your Member State.
May I adapt the workbook and share it within my organisation?
Yes. You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.
Use and credit
You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.
How to cite this template: Source: Praxikon, EU AI Act compliance checklist: every obligation per role and risk class (Excel template), version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/eu-ai-act-compliance-checklist
This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.
Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597