Home · AI Regulation · EU AI Act Checklist

The EU AI Act readiness checklist

Updated 2026-08-11 · Maintained by the Tokto team

EU AI Act readiness comes down to evidence: knowing what AI you use, classifying it against the Act's risk tiers, enforcing your policies at the point of use, and keeping records a regulator can read. These eleven steps are the practical sequence enterprises are following.

  1. Build a living AI inventory. Register every AI system, tool, and AI-powered feature in use — including AI embedded in approved SaaS. Record owner, purpose, data classes, and provider. An inventory generated from observed traffic stays current; one built from surveys rots in a quarter.
  2. Classify each use against the Act's risk tiers. Screen every use case against Article 5 prohibited practices first, then identify anything that may qualify as high-risk under Annex III, and note where you rely on general-purpose AI models. Document the reasoning, not just the conclusion.
  3. Stand up AI literacy (Article 4 — already in force). Since February 2025, providers and deployers must ensure staff operating AI have sufficient AI literacy. Track who has been trained, on what, and when — training you cannot evidence is training that did not happen.
  4. Assign ownership and governance cadence. Name the accountable owner for AI compliance, and give legal, security, finance, and engineering a shared operating view. A committee without traffic-level visibility governs a slideshow, not the AI.
  5. Map what data reaches which models. Know which data classes (PII, financial, health, trade secrets) can reach which providers, in which jurisdictions. This mapping drives both GDPR alignment and AI Act documentation.
  6. Turn your AI policy into runtime enforcement. Write the acceptable-use policy, then enforce it where usage happens: allow, transform, or block at the moment of the prompt, per team, per model. Regulators increasingly ask how policy is applied, not just what it says.
  7. Log AI interactions with retention and immutability. Keep interaction-level records — user, tool, model, prompt context, policy decision, timestamp — in tamper-evident form with retention aligned to your obligations. This is the single most-requested artifact in early enforcement actions.
  8. Collect provider and GPAI documentation. Gather model providers' technical documentation, transparency reports, and terms. For general-purpose models you deploy, know what the provider discloses and what remains your responsibility as deployer.
  9. Define human oversight for consequential uses. For any use that touches employment, credit, customers, or safety: define where human review sits, who can override, and how the review is recorded per interaction.
  10. Rehearse the regulator's request for information. The February 2026 coordinated enforcement action asked for prohibition classification, consent state per interaction, and per-decision policy application. Run the drill: could you export that packet for your top three AI use cases this week?
  11. Track the enforcement timeline. Prohibitions and AI literacy have applied since February 2025; general-purpose AI obligations since August 2025; most high-risk obligations phase in through August 2026-2027, and national authorities are now coordinating. Assign someone to watch it monthly.
Tokto does not provide legal advice, and this checklist does not replace counsel's reading of the Act for your specific systems. It is the operational layer underneath the legal work: what to have running so counsel has something to point at. See also: What is the EU AI Act?

Want the evidence layer under your AI Act program?

Book a working session →
AI Regulation ReadinessEU AI Act first enforcement actionAI Model InventoryImmutable Audit Log