EU AI Act Obligations Checklist (2026 Update)

The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved the high-risk deadlines: stand-alone Annex III systems now from 2 December 2027, AI in regulated products from 2 August 2028.
It did not move the rest. Prohibited practices and AI literacy have applied since February 2025, the rules for general-purpose models since August 2025, and the transparency duties since 2 August 2026.
Start with scope and your role for each system, then rule out the prohibited practices, then decide whether the system is high-risk. Each step either closes a question or tells you which of the later steps apply.
Every item carries the article number, so you can check the text of the Regulation yourself rather than take a summary on trust.
The checklist ends with the documents to keep: the system inventory with reasoning for each risk class, the Article 5 screening, AI literacy records, technical documentation and incident logs.
That pack is what an authority, an enterprise customer or an investor in due diligence will ask for first.
What's inside
The full outline of the guide. Every chapter below opens in full on this page once you sign in with your email — nothing is held back for an upsell.
How to use this checklist
- The dates that matter
Step 1. Are you in scope?
Step 2. Rule out prohibited practices
Step 3. AI literacy — already in force
Step 4. Is the system high-risk?
- Route 1: regulated products (Annex I)
- Route 2: use cases (Annex III)
- The exception for Annex III (Art. 6(3))
Step 5. Provider obligations for high-risk systems
Step 6. Deployer obligations for high-risk systems
Step 7. Transparency obligations — from 2 August 2026
Step 8. General-purpose AI models
Step 9. Penalties
Step 10. The evidence pack to keep
Where to start this week
Get the complete Checklist and start applying it this week.

