Skip to main content
    Pritect
    All resources
    AI GovernanceChecklist7 min readUpdated 29 Jun 2026

    EU AI Act readiness checklist

    A pragmatic checklist for getting ready for the EU AI Act, from building an AI system inventory to classifying risk, assigning obligations, and connecting them to your existing governance.

    By Federico Marengo·AI Governance Partner, White Label Consultancy

    The EU AI Act applies obligations by risk tier, and most of the early work is the same regardless of where your systems land: know what you have, classify it, assign the obligations to owners, and connect them to processes you already run. This checklist is the practical starting point.

    The readiness checklist

    1. Build an AI system inventory. You cannot govern what you have not catalogued. For each system, record what it does, who owns it, what data it touches, and whether it is built or bought.
    2. Classify each system. Determine whether it is prohibited, high-risk, limited-risk, or minimal-risk under the Act's criteria. Most of the obligation weight falls on high-risk systems (the Annex III uses, such as AI that filters job applications or determines access to essential services).
    3. Identify your role. Provider and deployer obligations differ, and many organisations may be both, but for different systems. A tool you build and sell makes you a provider but a tool you adopt makes you a deployer.
    4. Map obligations to owners. Risk management, data governance, technical documentation, record-keeping, human oversight, transparency, and post-market monitoring each need a named owner.
    5. Connect to data protection. A high-risk system processing personal data almost always needs a DPIA. Run the AI Act assessment and the DPIA together rather than in separate tools.
    6. Handle transparency. Limited-risk systems, like customer-facing chatbots, mainly carry transparency duties. Tell people they are interacting with AI, and label AI-generated content where required.
    7. Plan for serious-incident reporting. Know the timelines and the process before an incident occurs.

    Where teams underestimate the effort

    Shadow AI discovery is the first because the systems employees adopt on their own are both the hardest to find and often the riskiest, since nobody assessed them. The second is ongoing monitoring. A point-in-time classification ages quickly as systems are retrained, repurposed, or extended, so treat classification as a living attribute of each system, reviewed on material change.

    From checklist to operating model

    Once the inventory exists and systems are classified, the goal is to make registration and assessment routine: a new AI system goes through governance as a matter of course, gets its obligations and oversight owner assigned, and stays under periodic review. Our companion guide, AI governance in practice, walks through that full lifecycle.

    See AI system inventory, EU AI Act classification, and connected obligations in Pritect.

    Explore AI Governance