---

Before you launch

Readiness is not a single switch. Before you put an AI feature in front of EU users, run a control inventory that tells you which obligations apply and which you can already evidence. This checklist is deliberately framed as "what to check," not "you pass." If any item is unowned, that is your remediation list.

The checklist

  • Classify the risk tier — Is the use listed in Annex III (recruitment, credit scoring, safety, biometrics, and more)? If yes, high-risk duties (Art. 9–17) attach. If not, check prohibited practices (Art. 5) and transparency duties (Art. 50).
  • Document the gaps to obligations — For each applicable article (Art. 9 risk management, 10 data governance, 11 technical documentation, 12 logging, 13 transparency, 14 oversight, 15 robustness), note whether you can evidence the control today.
  • Assign a human-oversight owner (Art. 14) — Name the natural person who understands, monitors, and can interrupt the system. "The team" is not an owner.
  • Log the assessment — Keep the classification, the gap list, and the evidence artifacts together so they can be produced for a conformity assessment.
  • Re-run after any material change — A new model, new data source, or new use case can change the tier and reopen closed gaps.

How to use the output

Each unchecked item is a remediation task with an owner and a due date. The finished checklist is an artifact for your conformity file — proof that you looked, classified, and assigned, even where controls are still in progress. Teams that score the system first (e.g., with ClauseGuard) get the gap list generated, then attach owners in this checklist.

What the checklist is not

It is a control inventory, not a pass/fail certification. Ticking every box does not make a regulator declare you compliant; leaving some open does not make you "non-compliant" by itself. Conformity depends on the full deployed system and is the deploying organization's responsibility. Use the checklist to drive evidence, not to claim a status you cannot support.

Authoritative references

  • EU AI Act (Reg. 2024/1689), Art. 5 / 9 / 10 / 11 / 12 / 13 / 14 / 15 / 50: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  • AI Act explorer: https://artificialintelligenceact.eu/
  • European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai