Key Takeaways
- Penalties for the most serious violations reach €35 million or 7% of global annual turnover, whichever is higher, above even GDPR’s ceiling.
- The EU AI Act applies extraterritorially. A U.S. company whose AI system’s output is used within the EU market can fall under it, regardless of where the company is headquartered.
- Most enterprises are still behind. Recent readiness research puts the share of organizations with no meaningful compliance program in place well above half.
- The delay is breathing room, not a reason to stop. Technical documentation written now, while design decisions are fresh, costs a fraction of reconstructing it in 2027 from systems already running in production.
The EU AI Act is changing how enterprises develop, deploy, and manage artificial intelligence across the European market. In 2026, compliance is no longer something businesses can leave until the final stages of AI deployment. Enterprises need to understand which AI systems they use, assess the risks involved, and put the right governance controls in place.
But compliance can feel complicated, especially for organizations managing multiple AI tools, vendors, models, and business processes. A clear checklist makes it easier to identify what needs attention and where potential gaps exist.
This EU AI Act compliance checklist for enterprises covers the key areas businesses should review in 2026, including AI risk classification, governance, documentation, transparency, human oversight, data practices, monitoring, and accountability. Use it to assess your current AI setup and create a practical compliance roadmap.

Do EU AI Act Requirements Apply to US Companies?
Yes, in most cases where an AI system’s output reaches the EU market. The EU AI Act follows the same extraterritorial logic GDPR established: physical presence in the EU isn’t the trigger, market impact is.
The Digital Omnibus delayed high-risk AI obligations to December 2027 (Annex III systems) and August 2028 (Annex I product-embedded systems), but Article 50 transparency duties remain in force since August 2026
If a U.S. company’s AI system is used by, or produces output that affects, people located in the EU, the obligations generally apply regardless of where the company is based. This catches a lot of companies off guard, particularly SaaS providers who assumed EU regulation was someone else’s problem.
What Counts as a High-Risk AI System Under the EU AI Act?
High-risk classification is the single most consequential decision in this whole process, because it determines which obligations actually apply to you. Two categories exist.
- Annex I systems: AI that’s a safety component of, or embedded in, a product already regulated elsewhere, such as medical devices, machinery, aviation, and vehicles. These follow existing sectoral conformity assessment processes, now with an AI Act layer on top, due August 2028.
- Annex III systems: standalone AI used in specific high-stakes contexts, listed explicitly in the regulation. This includes recruitment and employment decisions, credit scoring, biometric identification, critical infrastructure management, education access, law enforcement risk assessment, and migration/asylum processing. These are the systems now due by December 2027.
If you’re not sure which bucket, or neither, your systems fall into, the starting point is always a system inventory.
You cannot classify what you haven’t catalogued, and Vision Compliance’s 2026 EU AI Act Readiness Analysis found that a majority of assessed organizations still lack a complete inventory of the AI systems they’re running, which makes accurate risk classification effectively impossible until that gap closes.
EU AI Act Compliance Checklist: What to Do Now
Here’s a practical sequence for enterprises working through this, regardless of where your systems land on the risk tiers.
- Inventory every AI system in production or development. Include vendor tools and embedded AI features, not just custom-built models. Shadow AI usage is one of the most common gaps compliance teams find once they actually look.
- Classify each system against the four risk tiers: unacceptable, high-risk, limited-risk (transparency obligations), and minimal-risk. Document the reasoning, not just the conclusion.
- Assign a named internal owner or governance body for AI compliance. Readiness research consistently finds that a lack of clear ownership, not a lack of awareness, is one of the biggest reasons compliance programs stall.
- Start technical documentation for anything trending toward high-risk, even with the extended deadline. This includes data governance records, model performance metrics, and human oversight procedures. Documentation written alongside development is far cheaper than documentation reconstructed after the fact.
- Confirm Article 50 transparency compliance now, since this obligation is already enforceable. That means disclosing AI-generated content, labeling chatbots as AI, and flagging deepfakes and synthetic media appropriately.
- Map GDPR overlap. Data Protection Impact Assessments and Fundamental Rights Impact Assessments both apply to many high-risk use cases, and duplicating that work separately wastes budget your legal team doesn’t have to spare.
- Build a monitoring process for regulatory guidance and harmonized standards, which are still being finalized. The first relevant harmonized standard covering quality management systems entered public review only in late 2025, meaning the technical specifics enterprises need to build against are still solidifying.
AI Act Article 50 Transparency Obligations: What’s Already Enforceable
Article 50 deserves its own attention because it’s the one obligation companies keep assuming was delayed along with everything else. It wasn’t. As of August 2, 2026, providers and deployers must:
- Clearly disclose when a person is interacting with an AI system rather than a human, unless it’s obvious from context.
- Label AI-generated or manipulated image, audio, or video content (deepfakes) in a machine-readable format.
- Disclose when text is AI-generated and published to inform the public on matters of public interest, with narrow exceptions.
- Inform employees and affected individuals when AI is used for emotion recognition or biometric categorization.
None of this hinges on your high-risk classification. If you’re running a customer-facing chatbot or generating any synthetic content today, this applies to you right now, delay or no delay.
EU AI Act Penalties: What Non-Compliance Actually Costs
The penalty structure is tiered by severity, and it’s steep enough that “we’ll deal with it later” is a genuinely expensive bet.
- Up to €35 million or 7% of global annual turnover, whichever is higher, for violations of prohibited practices.
- Up to €15 million or 3% of global annual turnover for non-compliance with high-risk system obligations and most other provisions.
- Lower-tiered fines for supplying incorrect, incomplete, or misleading information to authorities or notified bodies.
For context, GDPR’s maximum penalty tops out at €20 million or 4% of global turnover. The AI Act’s ceiling is meaningfully higher, which tells you how seriously EU regulators are treating this compared to the last major digital regulation cycle enterprises had to absorb.
There’s also a cost most companies underweight: the compliance spend itself. Industry estimates for large enterprises operating high-risk systems put initial compliance investment between $8 million and $15 million, with ongoing annual costs of $500,000 to $2 million.
Gartner projects spending on dedicated AI governance platforms to reach $492 million globally in 2026, driven largely by this exact compliance pressure. That’s not a number to be alarmed by so much as a number to plan around, since the alternative, building governance reactively under a regulator’s timeline instead of your own, tends to cost more.
How to Implement EU AI Act Compliance: A Phased Roadmap

Working through twenty checklist items at once isn’t realistic for most enterprises, so sequence the work in phases instead. Here’s a roadmap that holds up whether you’re starting from zero or picking up a stalled program.
Phase 1: Discovery
- Run a company-wide AI system inventory, pulling from procurement records, IT asset management, and direct outreach to department heads, since vendor tools rarely show up in a single central list.
- Interview business units to surface shadow AI usage that wouldn’t appear in formal records.
- Assign the internal compliance owner or governance body, even on an interim basis, so the rest of the phases have a clear accountable party.
- Benchmark current state against the checklist above to establish a baseline, not to assign blame.
Phase 2: Classification and Risk Mapping
- Classify every inventoried system against the Act’s four risk tiers, documenting the reasoning for each call.
- Prioritize systems that fall into Annex III categories (employment, credit, biometric, critical infrastructure, education, law enforcement) for deeper review first, since these carry the most extensive obligations.
- Cross-reference classifications against GDPR data processing records to identify where impact assessments can be combined rather than duplicated.
- Flag any systems that may fall under prohibited practices for immediate legal review and, if confirmed, immediate remediation. This isn’t a 2027 problem; prohibited-practice obligations have applied since February 2025.
Phase 3: Documentation and Controls
- Begin technical documentation for high-risk candidates: data lineage, training methodology, performance benchmarks, and known failure modes.
- Define and implement human oversight mechanisms for systems where a person needs the ability to review or override an AI decision.
- Confirm Article 50 transparency measures are live across every applicable system, since this is enforceable now, not a future-phase item.
- Stand up a change-management process so documentation gets updated automatically whenever a covered system is retrained or materially modified.
Phase 4: Monitoring and Ongoing Governance
- Put continuous monitoring in place for model drift, data changes, and performance degradation on classified systems.
- Schedule recurring reviews, at minimum quarterly, of the system inventory to catch new tools before they become undocumented gaps.
- Track incoming harmonized standards and regulatory guidance, and update internal documentation templates as formal technical standards are published.
- Build compliance checkpoints into the AI development lifecycle itself, so new systems are classified and documented before launch rather than audited afterward.
The Enterprise Readiness Gap: What the Data Actually Shows
This is the section worth sitting with, because the gap between awareness and actual preparation is wide.
- Deloitte’s 2026 State of AI in the Enterprise research, surveying more than 3,200 business and IT leaders across 24 countries, found that only about a third of organizations have moved past surface-level AI use into genuinely redesigning processes or products around it.
- Most are still in earlier stages of adoption, which matters here because governance maturity tends to trail adoption maturity by a wide margin, and regulatory readiness trails governance maturity further still.
- More directly on point, Vision Compliance’s 2026 EU AI Act Readiness Analysis, based on assessments across financial services, healthcare, technology, manufacturing, and other sectors, found that a large majority of assessed organizations had not taken meaningful steps toward compliance, most lacked a designated internal owner for AI governance, and most had no process in place for generating the technical documentation high-risk systems will eventually require.
- Separate research on AI governance readiness puts the share of managers who feel adequately prepared for EU AI Act compliance at roughly a third, with most others somewhere between uncertain and openly unprepared.
- None of this means panic. It means the extended deadline is genuinely useful time, provided it gets used for building governance infrastructure rather than assuming the delay solved the underlying problem.
How Generative AI and AI Governance Tools Can Support Compliance

There’s a reasonable question buried in all of this: can the same AI systems creating the compliance burden also help carry it? In practice, yes, particularly for the documentation-heavy parts of the process.
- Automated system inventories. AI-assisted discovery tools can scan an enterprise’s tech stack for AI and ML components that manual audits regularly miss, including embedded vendor features nobody remembers approving.
- Technical documentation drafting. Generative models can produce first drafts of model cards, data governance records, and risk assessment documentation from existing engineering artifacts, cutting the manual burden without replacing the human sign-off the Act requires.
- Continuous monitoring. Once a system is classified and documented, AI-driven monitoring can flag model drift, performance degradation, or data changes that would otherwise require ongoing human oversight to catch.
This is a good example of generative AI for compliance work more broadly, applying the technology to the operational grind of regulatory programs rather than only to customer-facing products. If you’re evaluating where AI-assisted compliance tooling could reduce your own team’s workload, the deeper breakdown on generative AI for compliance covers the approach in more detail.
Enterprises in regulated industries have already been down a version of this road. SoluLab’s own work on a clinical decision support system, detailed in the GenAI in MedTech case study involved building generative AI functionality inside a healthcare environment where documentation, human oversight, and regulatory defensibility weren’t optional extras. That’s close to the operating model the AI Act now expects from every high-risk deployer.
Getting Started: An AI Readiness Assessment Before You Build Anything New
Before adding a single new AI capability, most enterprises are better served running a structured AI readiness assessment against their current systems.
- It answers the questions this checklist keeps circling back to: what’s actually in production, where does each system sit on the risk tiers, and what documentation gap exists between where you are and where December 2027 or August 2026’s transparency rules require you to be.
- For enterprises building new AI capability from here forward, the smarter sequence is to bake compliance into the architecture from day one rather than retrofit it later, since retrofitting governance into a system already in production is consistently the most expensive way to get there.
- That’s where working with an enterprise AI development partner who understands the regulatory context earns its cost back quickly.

Conclusion
The Digital Omnibus bought enterprises real time, but it didn’t remove the underlying obligation, and Article 50’s transparency rules are proof of that: they’re enforceable today, delay or no delay. The organizations that come out ahead of December 2027 won’t be the ones that treated the extension as a reason to relax.
They’ll be the ones that used the extra runway to build a real system inventory, assign real ownership, and start writing documentation before a regulator asks for it.
SoluLab, an AI development company, can help your business build AI systems with compliance considered from the architecture stage rather than bolted on afterward, and can help assess where your existing AI footprint stands against the Act’s risk tiers.
FAQs
Neha is a curious content writer with a knack for breaking down complex technologies into meaningful, reader-friendly insights. With experience in blockchain, digital assets, and enterprise tech, she focuses on creating content that informs, connects, and supports strategic decision-making.