Skip to main content

Elevate

EU AI Act Compliance Checklist: Obligations by Risk Category

An EU AI Act compliance checklist only works if it is organized the way the law itself is organized: by risk tier. The Act does not impose one uniform set of rules on every AI system; it sorts systems into risk categories and assigns obligations to each, so the first question is never what must be done but rather which tier a system falls into. This guide lays out the obligations for the prohibited, high-risk, and limited-risk tiers, explains how classification drives everything, and points to where the current application dates are maintained, since those have been revised.

The reason the tier comes first is that it determines the entire obligation set. A system in the minimal-risk tier carries no mandatory obligations, while one in the high-risk tier carries an extensive program of them, and misclassifying a system is therefore the most consequential mistake an organization can make. Working through this checklist means classifying each AI system first, then applying only the obligations that its tier actually triggers.

How the EU AI Act Classifies Risk

The Act’s risk-based structure is the foundation of every obligation, and the table sets out the four tiers and what each demands. The classification comes directly from the Regulation.

Risk tierWhat it coversWhat the Act requires
ProhibitedAI practices deemed an unacceptable risk under Article 5, such as certain manipulative techniques and social scoringThe practice is banned outright
High-riskAI that is a product safety component or falls within the Act’s listed use cases under Article 6An extensive set of obligations before and throughout use
Limited riskAI that interacts directly with people or generates content, under Article 50Transparency obligations
Minimal riskAll other AI systemsNo mandatory obligations under the Act

The practical consequence of this structure is that classification is not a formality but the step that decides how much work an organization faces. Most business AI falls into either the high-risk or limited-risk tiers, and the gap between the two is large, so an honest classification, rather than an optimistic one, is where compliance genuinely begins. The tiers are mutually exclusive for a given use, which is why the checklist is built to be read one tier at a time.

Prohibited Practices: What You Must Not Do

The prohibited tier is the shortest part of any such checklist because it is a list of things to stop, not build. Article 5 bans a defined set of practices outright, including AI that uses subliminal or purposefully manipulative techniques to materially distort behavior, AI that exploits the vulnerabilities of specific groups, social scoring of individuals by public or private actors, and certain uses of biometric categorization and remote identification. An organization’s obligation here is simply to confirm that none of its systems, current or planned, fall into these categories.

The reason this tier sits first on the checklist is that a prohibited practice cannot be remediated into compliance; it must be abandoned. Unlike a high-risk system, which becomes compliant through controls and documentation, a system whose purpose is a prohibited practice has no compliant version. Screening the AI portfolio against Article 5 early therefore prevents an organization from investing in a system it can never lawfully deploy.

High-Risk Systems: The Core Obligations

The high-risk tier carries the heaviest obligations, and it is where most of the checklist lives. A system is high-risk under Article 6 either when it is a safety component of a regulated product or when it falls within the Act’s listed high-risk use cases, which cover sensitive domains such as employment, access to essential services, and critical infrastructure. Once a system is classified high-risk, a defined program of requirements applies to it before it reaches the market and throughout its operation.

The core requirements the Regulation sets for high-risk systems are a connected set, and a checklist should treat them as items to evidence rather than boxes to tick. They include a risk management system that runs across the lifecycle under Article 9, data and data governance practices under Article 10, technical documentation under Article 11, automatic record-keeping and logging under Article 12, transparency and information provided to deployers under Article 13, human oversight designed into the system under Article 14, and appropriate accuracy, robustness, and cybersecurity under Article 15. Surrounding these, providers must operate a quality management system, complete a conformity assessment before placing the system on the market, register it as required, and monitor it after deployment.

The through-line across these obligations is evidence: each requirement is satisfied not by intent but by documentation that a regulator or a deployer can inspect, which is why a high-risk program looks in practice like a managed system rather than a one-time project. This is also where a structured AI risk assessment does much of the work, because the risk management requirement sits at the center of the high-risk obligations and feeds several of the others.

Limited-Risk Systems: Transparency Obligations

The limited-risk tier is defined by transparency rather than by the extensive controls of the high-risk tier. Under Article 50, systems that interact directly with people must make clear that a person is dealing with an AI system unless that is already obvious, and systems that generate or manipulate content must ensure that synthetic content, including deepfakes, is disclosed and detectable. Similar disclosure obligations apply to systems that perform emotion recognition or biometric categorization, which must inform the people exposed to them.

The obligation for this tier is narrower but still real, and organizations often overlook it precisely because it feels light. A chatbot, a synthetic-media tool, or a recommendation interface may carry no high-risk obligations yet still owe clear disclosure to the people who encounter it. The checklist item for this tier is therefore to identify every system that interacts with people or produces content and confirm that its disclosures meet the transparency standard.

Who the Obligations Fall On

A checklist organized by risk tier answers what the obligations are, but a second question decides who carries them: the Act assigns duties by role, and an organization needs to know which role it occupies for each system. The heaviest obligations fall on the provider, the party that develops an AI system or has it developed and places it on the market under its own name. Providers of high-risk systems own the full program of requirements, from the risk management system through conformity assessment and registration, so an organization that builds or commissions AI is usually where the weight lands.

The deployer, the party that uses an AI system under its own authority, carries a lighter but distinct set of obligations, including using the system in line with its instructions, maintaining human oversight, and monitoring its operation. Many organizations are deployers rather than providers, and they sometimes assume the provider’s compliance covers them, which it does not: the deployer’s obligations are its own. Importers and distributors that bring third-party AI systems into the market carry further checks of their own, confirming that the provider has met its obligations before the system moves down the chain.

The practical consequence is that the same organization can be a provider for one system, a deployer for another, and neither for a third, so role must be assessed per system alongside tier. Getting the role wrong is as costly as getting the tier wrong, because it misallocates the obligations and can leave a genuine duty unowned. Running the checklist therefore means answering two questions for each system: which tier it falls into, and which role the organization plays with respect to it.

The Deadlines That Apply Now

The Act applies in phases rather than all at once, and the order of those phases is the part of the timeline that has stayed stable: the prohibitions on unacceptable practices came into force first, obligations for general-purpose AI models followed, and the full weight of the high-risk obligations phases in afterward, with certain product-related high-risk systems on a later phase again. That sequence is why the prohibited tier is already something to act on while parts of the high-risk regime continue to phase in.

The specific calendar dates, however, have been revised, which is why this checklist points to a single maintained source for them rather than printing dates that may already be out of step. Elevate’s EU AI Act timeline with the current deadlines tracks the dates as they now stand, and the key dates and who needs to comply guide covers who each phase binds. Because these dates shape when each part of the checklist becomes enforceable, confirming the current phase against that timeline is the right first move before treating any obligation as immediately due.

How to Use This EU AI Act Compliance Checklist

The right way to use this checklist is to run it per system, not once for the organization, because each AI system may fall into a different tier and therefore carry a different obligation set. For each system, first screen it against the prohibited practices, then determine whether it is high-risk under the Article 6 rules, and only then work the relevant tier’s obligations. A system that clears the prohibited screen and is not high-risk usually lands in the limited-risk or minimal-risk tier, where the burden drops to transparency or nothing.

Turning that classification into an operating program is where documentation matters, and it is what an organized policy set is built to support. Elevate’s EU AI Act policy suite provides the governance documents that operationalize the high-risk and transparency obligations, so the checklist becomes a running system rather than a static list. What ties the effort together is honest classification at the start, because every obligation downstream depends on getting the tier right, and the discipline of the checklist is only as good as that first judgment.

Conclusion

An EU AI Act compliance checklist has to be read by risk tier, because the Act assigns obligations by classification: prohibited practices are banned outright under Article 5, high-risk systems carry an extensive program of requirements under Article 6 and Articles 9 through 15, limited-risk systems owe transparency under Article 50, and minimal-risk systems carry no mandatory obligations. Classification is the decisive step, because it determines which of these obligation sets applies at all.

The application dates phase in over time and have been revised, so the current deadlines are maintained in Elevate’s timeline rather than printed here, and the sequence, prohibitions first and full high-risk obligations later, is what tells an organization where to focus now. To turn this checklist into an operating governance program, start with Elevate’s EU AI Act policy suite or book a call with an Elevate advisor.

Key Takeaways

An EU AI Act compliance checklist must be organized by risk tier, because the Act assigns obligations by classification rather than uniformly.

  • Classification comes first: whether a system is prohibited, high-risk, limited-risk, or minimal-risk decides its entire obligation set, so an honest classification is where compliance begins.
  • Prohibited practices cannot be remediated: Article 5 bans a defined set of practices outright, so the only response is to confirm no system falls into them and abandon any that does.
  • High-risk carries the heaviest program: systems classified high-risk under Article 6 must satisfy the requirements in Articles 9 through 15, from a risk management system to human oversight and cybersecurity, plus quality management, conformity assessment, and registration, all evidenced with documentation.
  • Limited-risk means transparency: under Article 50, systems that interact with people or generate content owe clear disclosure, an obligation organizations often overlook because it feels light.
  • The dates have moved, so verify them: the Act applies in phases and the calendar dates were revised, so confirm the current deadlines against Elevate’s timeline before treating any obligation as immediately due.

FAQs

Q1. What is an EU AI Act compliance checklist? An EU AI Act compliance checklist is a structured list of the obligations the Regulation imposes, organized by the risk tier into which an AI system falls. Because the Act assigns duties by classification rather than uniformly, a useful checklist is read one tier at a time: prohibited practices that are banned outright, high-risk systems that carry an extensive program of requirements, limited-risk systems that owe transparency, and minimal-risk systems that carry no mandatory obligations. The checklist is applied per system, since different systems in the same organization can fall into different tiers.

Q2. What are the risk categories under the EU AI Act? The Act uses four risk categories. Prohibited practices, defined in Article 5, are banned outright, and include certain manipulative techniques and social scoring. High-risk systems, classified under Article 6, are those used as a product safety component or within the Act’s listed sensitive use cases, and they carry the heaviest obligations. Limited-risk systems, covered by Article 50, are those that interact with people or generate content and owe transparency. Everything else is minimal-risk and carries no mandatory obligations. Classification determines which obligation set applies.

Q3. What are the obligations for high-risk AI systems? High-risk systems must meet the requirements the Regulation sets in Articles 9 through 15: a risk management system across the lifecycle, data and data governance, technical documentation, automatic record-keeping, transparency and information for deployers, human oversight built into the system, and appropriate accuracy, robustness, and cybersecurity. Around these, providers must operate a quality management system, complete a conformity assessment before placing the system on the market, register it as required, and monitor it after deployment. Each obligation is satisfied through documented evidence a regulator or deployer can inspect, not through intent.

Q4. When do EU AI Act obligations take effect? The Act applies in phases rather than all at once, with the prohibitions on unacceptable practices taking effect first, obligations for general-purpose AI models following, and the full high-risk obligations phasing in afterward, with certain product-related high-risk systems on a later phase again. The specific calendar dates have been revised over time, so the current deadlines should be confirmed against a maintained source rather than assumed. The sequence itself, prohibitions first and high-risk obligations later, is stable and tells an organization which parts of the checklist are enforceable soonest.

Q5. How do you use an EU AI Act compliance checklist? Run it per AI system rather than once for the whole organization, because each system may fall into a different tier. For each, first screen it against the Article 5 prohibited practices, then determine whether it is high-risk under the Article 6 classification rules, and only then apply the obligations that its tier triggers. A system that is neither prohibited nor high-risk usually lands in the limited-risk or minimal-risk tier, where the burden drops to transparency or nothing. Honest classification at the start is essential, because every downstream obligation depends on getting the tier right.