AI Act • AI Governance • Risk Management

AI Compliance Checklist

Use this checklist to create a practical AI compliance baseline before launching, buying or scaling AI systems.

Last updated4 May 2026
Update workflowWeekly monitoring, monthly edits
MethodOfficial sources + practical governance controls
Quick next step

Not sure where your AI use stands?

Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.

Checklist overview

  • Create an AI inventory with owners, vendors and use cases.
  • Classify use cases by possible risk level and regulatory relevance.
  • Screen for prohibited practices and sensitive use cases.
  • Identify possible high-risk AI systems and escalate them for legal review.
  • Create or update an employee AI policy.
  • Implement AI literacy and training for relevant staff.
  • Review personal data, confidential data, source code and security restrictions.
  • Add transparency notices for chatbots, AI-generated content and automated interactions where needed.
  • Document human oversight, escalation and override paths.
  • Monitor incidents, complaints, drift, vendor changes and model updates.
Advertisement

What “done” looks like

A checklist item is only done when there is evidence. For example, “AI policy” is not done because someone discussed it in a meeting; it is done when the current policy is approved, published, assigned an owner, and included in training. “Risk assessment” is done when the reasoning, controls, owners and review date are recorded.

How to prioritise

Start with high-impact decisions and high-exposure tools. HR, credit, education, essential services, biometric systems, safety components, public-facing chatbots, AI-generated content, and tools using sensitive data should be reviewed before low-risk productivity tools.

Advertisement

FAQ

Is this checklist enough for compliance?

No. It is a readiness checklist, not a legal determination.

How many checklist items should a small company start with?

Start with inventory, policy, risk triage, data restrictions and review ownership.

How often should the checklist be reviewed?

Monthly, and before launching any new AI use case.

Sources and review method

This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.

Reviewed byAI Compliance Checkup Editorial Team
Review methodOfficial AI Act, European Commission, EUR-Lex and NIST sources
Last reviewed4 May 2026
Contactcontact@aicompliancecheckup.com