Checklist · AI Act
Seven steps for companies that do not build AI, only use it. Article 5 prohibitions, Article 50 transparency, Article 26 duties and the dates that apply.
The Artificial Intelligence Act, Regulation (EU) 2024/1689, allocates obligations by role. The overwhelming majority of its text — the risk management system, data governance, technical documentation, conformity assessment, the CE marking, registration in the EU database — is addressed to the provider, meaning whoever develops an AI system and places it on the market or puts it into service under their own name. A deployer is someone else: the party that uses a finished system in the course of its activity.
For companies that only use AI, that brings good news and one trap. The good news is that only a fraction of the Regulation applies to them. The trap is that a deployer can slide into the provider role without anyone deciding to — the circumstances are listed in Article 25(1) and there are three of them. That is precisely why the last step of this checklist is about watching that line.
The checklist therefore deliberately contains nothing from the provider obligations in Article 16 and the articles that follow. Where a provider obligation is mentioned, it is always expressly flagged, and only so that you can recognise it and avoid taking it on. A vendor document that arrives with sixty pages of AI Act obligations usually describes the vendor's world, not yours.
One more distinction is worth making at the outset, because without it the first step goes wrong. The Regulation does not sort tools by whether you pay for them, nor by whether IT procured them. It sorts them by purpose and by risk. A free tool an HR officer uses to screen applicants matters more, in the eyes of the Regulation, than an expensive platform used to rephrase text.
Before you start: most of what is circulating about the AI Act today was written before 27 July 2026. That is the day Regulation (EU) 2026/1744 entered into force, which among other things moved the dates of application for high-risk systems and rewrote Article 4. Any material stating that obligations for high-risk systems under Annex III begin on 2 August 2026 (and for Annex I on 2 August 2027) is based on the old text.
Without an inventory, the rest of the checklist is a paper exercise. Every later step is done for a specific tool and a specific purpose of use — none of it can be done for the company as a whole, because the Regulation assesses nothing at that level.
The inventory has one property companies underestimate: it is not a list of purchased licences. A large share of what gets used inside a company was never bought. Free accounts, browser add-ons, features a vendor switched on in an update to an existing application, and tools brought in by contractors. Those are where something that collides awkwardly with the Regulation most often turns up.
For each entry you need to record more than a name. The intended purpose of use is the critical field, because it drives both the risk category and whether a transparency obligation arises at all. Beyond that you need to know who uses the tool, on whom it is used, and whether its output influences decisions about people — that is the line past which the obligations change sharply.
A practical note on scope: do not try to decide up front what is and is not an AI system within the meaning of the Regulation. Anything that presents or sells itself as one belongs in the inventory. Filtering comes in the next step, with a recorded reason. Doing it the other way round, screening things out at the door, means nobody ever looks at them again.
The inventory usually yields a side benefit that would justify the effort even if the AI Act did not exist: a view of which company data is leaving for services nobody ever signed a contract with. That is a decision in its own right, and in practice it is often more pressing than the regulation.
The Article 5 prohibitions are checked first, for two reasons. They carry the highest penalty band — up to EUR 35 000 000 or up to 7 % of total worldwide annual turnover, whichever is higher (Article 99(3)). And, more importantly, there is nothing to weigh: a prohibited practice cannot be offset by a control, by documentation or by consent.
For a deployer, the most important item in the whole of Article 5 is point (f). It prohibits the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons. The word use is there deliberately — the prohibition catches the party that did not build the system.
One widespread misconception needs correcting here. Regulation (EU) 2026/1744 did not touch point (f) at all. The amending point through which the omnibus changes Article 5 only inserts new points (ba) and (bb) and new paragraphs 1a and 1b. The wording of the prohibition on inferring emotions at the workplace therefore stands as originally adopted and has applied since 2 February 2025, more than a year now. Anyone who expected the high-risk postponement to reach this too was waiting for nothing.
The omnibus did add two new prohibitions, and those apply only from 2 December 2026. New point (ba) prohibits the placing on the market, the putting into service or the use of AI systems that generate, or that manipulate, realistic image, video, audio or similar material depicting the intimate parts of an identifiable natural person, or that person engaged in sexually explicit activities, without that person's freely given, specific, informed, unambiguous and explicit consent. New point (bb) prohibits AI systems that generate or manipulate material or performances within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a ground excluding unlawfulness applies under national law.
The new Article 5(1a) narrows the reach of both new prohibitions, and that matters for deployers. Placing on the market or putting into service is prohibited only where generating such material is the intended purpose of the system, or where such generation is — given the design, training, architecture, capabilities or functions of the system — a reasonably foreseeable and reproducible outcome that requires no significant technical modification, and the system lacks adequate technical safeguards and guarantees. Use is prohibited only where the deployer uses the system precisely in order to generate such material or to manipulate it. The new paragraph 1b then carves out of the notion of manipulation the case where a system manipulates material in a way that neither increases the exposure of the intimate parts depicted nor alters the nature of the sexually explicit activities depicted.
The output of this step should be a written decision for every tool on the list, not a feeling. A short record is enough — tool, intended purpose, conclusion and date. Without it you will run the same reasoning again next year, and probably reach a different answer.
Once a tool has survived the prohibitions, classification is next. The question is whether it is a high-risk AI system under Article 6, because that is what governs when the deployer obligations in Article 26 reach you.
The Regulation offers two routes to high risk and, after the omnibus, the two also differ in date. The first route runs through Article 6(2) read with Annex III, which lists the areas of use — for ordinary companies the most common of them is employment and worker management. The second runs through Article 6(1) read with Annex I: the AI system is a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I.
The new Article 113, third subparagraph, point (c) postpones the application of Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), to 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and to 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. Article 26 belongs to Section 3, so deployer obligations for Annex III high-risk systems do not begin on 2 August 2026, as the original text implied. For Annex I the starting point was different: the original point (c) of Article 113 set 2 August 2027 for Article 6(1) and the related obligations, so the shift there is one year, not two. Recital 40 of the omnibus grounds this in the delayed availability of standards, common specifications and alternative guidance, and in the delayed establishment of the competent national authorities.
The postponement has limits, though, and they tend to get lost in summaries. It does not cover Chapter IV, meaning the transparency obligations in Article 50, and it does not cover Chapter III, Section 5, which holds harmonised standards, conformity assessment, certificates and registration under Articles 40 to 49 — those keep the general date of application of 2 August 2026 under the second subparagraph of Article 113. Nor does it cover the prohibitions from the previous step.
The omnibus also narrowed one concept that drives classification. Under the new Article 6(1a), AI systems used exclusively for user support, performance optimisation, service efficiency, automation, convenience or quality control unrelated to safety are not to be regarded as safety components. Under the new Article 6(1b), by contrast, systems whose failure or malfunctioning would endanger health and safety are to be regarded as safety components. The narrowed definition of safety component also appears in Article 3, point (14). The new Article 6(1c) then provides that a product for which third-party conformity assessment is required exclusively on account of risks other than risks to health and safety does not meet the condition in Article 6(1).
Do not confuse a postponed date of application with postponed preparation. Classifying a tool, recording its intended purpose and deciding who will exercise human oversight are things you will need anyway — and doing them for five tools as you go is incomparably easier than for thirty at once, six months before the deadline.
This is the most urgent step in the whole checklist, because it is the only one whose deadline has already arrived. Article 50 makes up the whole of Chapter IV, and Chapter IV appears in none of the points of the third subparagraph of Article 113. It therefore takes the general date of application under the second subparagraph, 2 August 2026. The transparency obligations were not postponed.
The omnibus touched Article 50 exactly once, in paragraph 7: it removed the Commission's power to approve codes of practice by implementing act. The Commission now merely assesses, taking utmost account of the opinion of the Board, whether adherence to the codes is sufficient to ensure compliance with the obligations in paragraphs 2 and 4, and only if it does not consider a code adequate may it adopt an implementing act laying down common rules. Recital 41 explains this by pointing out that codes of practice have limited legal effect and, in particular, do not confer a presumption of conformity. Paragraphs 1 to 6 remain as originally adopted.
Two paragraphs of Article 50 matter for deployers. Under paragraph 3, deployers of an emotion recognition system or a biometric categorisation system inform the natural persons exposed to it of the operation of the system, and process personal data in accordance with Regulation (EU) 2016/679, Regulation (EU) 2018/1725 and Directive (EU) 2016/680. An exception applies to systems permitted by law to detect, prevent or investigate criminal offences. Watch the overlap with the previous step: at the workplace and in education institutions, inferring emotions is prohibited under Article 5(1)(f), so the information duty does not apply there — you cannot satisfy a prohibition by telling someone about it.
Under paragraph 4, deployers of an AI system that generates or manipulates content constituting a deep fake must disclose that the content has been artificially generated or manipulated. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the obligation is limited to disclosing the existence of such content in an appropriate manner that does not hamper the display or enjoyment of the work. The second subparagraph imposes a comparable duty for text published with the purpose of informing the public on matters of public interest, except for content that has undergone human review or editorial control and for which someone holds editorial responsibility.
The rule common to both sits in paragraph 5: the information under paragraphs 1 to 4 is to be provided in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must conform to the applicable accessibility requirements. A footnote at the bottom of a page, or a sentence in the general terms and conditions, does not meet that.
For penalties, Article 50 falls under Article 99(4), meaning the band of up to EUR 15 000 000 or up to 3 % of total worldwide annual turnover, whichever is higher. That is lower than the Article 5 band, but it is an obligation whose breach is visible from the outside without any inspection at all — a customer or a competitor need only notice the content.
Article 4 sits in Chapter I, which has applied since 2 February 2025. The omnibus changed nothing about that date, but it did change the whole wording of the obligation, with effect from 27 July 2026.
The difference is substantive. Previously, providers and deployers took measures to ensure, to their best extent, a sufficient level of AI literacy. The new Article 4(1) speaks of measures to promote the improvement of AI literacy, and expressly adds that the obligation does not require providers or deployers to guarantee a specific level of AI literacy for individual persons. What is assessed, therefore, is the measures, not the level attained.
The personal scope is unchanged, and it is broader than people expect. The obligation covers the relationship with staff and with all other persons dealing with the operation and use of AI systems on the company's behalf. Account is to be taken of the technical knowledge, experience, education and training of those persons, the context in which the systems are to be used, and the persons or groups of persons on whom the systems are to be used. A single universal course for everyone fits that distinction less well than two shorter ones split by role.
For penalties, Article 4 is a special case. It does not appear in the list of provisions in Article 99(4), where the band is up to EUR 15 000 000 or up to 3 % of turnover — the omnibus added only the new point (da), for Article 25(2) and (4), to that list. The AI Act therefore lays down no specific administrative fine for a breach of Article 4; what applies is the general duty of Member States under Article 99(1) to lay down effective, proportionate and dissuasive penalties. The omnibus rewrote paragraph 1 itself — alongside fines, it now expressly contemplates warnings and non-monetary measures.
What an internal rule on the use of AI should contain, and what wording actually survives contact with daily practice, is covered by a separate page in this category — What an AI usage rule should contain. Here it is enough to know that the rule is the cheapest way both to organise the Article 4 measures and to evidence them.
If step 3 told you that one of your tools is a high-risk AI system, this list is for you. The date of application is 2 December 2027 for systems under Article 6(2) and Annex III, and 2 August 2028 for systems under Article 6(1) and Annex I.
One thing gets distorted in summaries often enough that it is worth saying plainly: the substance of Article 26 has not changed. Regulation (EU) 2026/1744 never opened Article 26 — the list of amending points runs from Article 25 straight to Article 27. What changed is solely the date from which the article applies, and that was done through Article 113. Any material discussing the new wording of Article 26 is discussing something that does not exist.
The list below deliberately carries no commentary on what each obligation means in practice — that is work done on a specific system and cannot be done in the abstract. Its purpose is to let you walk through each high-risk tool and see what you already have and what still needs building. It is not a full transcript of Article 26: we give the obligations relevant to ordinary company operations and leave out paragraph 3 (the relationship to other obligations and the freedom to organise your own resources), paragraph 10 (the post-remote biometric identification regime for law enforcement purposes) and paragraph 12 (cooperation with the competent authorities).
Paragraph 7 deserves particular attention. Before putting into service or using a high-risk AI system at the workplace, deployers who are employers inform workers' representatives and the affected workers that they will be subject to the use of the system. The information is to be provided in accordance with the rules and procedures laid down in Union and national law and practice on the information of workers and their representatives. It is an obligation that has to be planned in advance — once the system is live, it can no longer be discharged.
A breach of the Article 26 obligations falls into the band of up to EUR 15 000 000 or up to 3 % of total worldwide annual turnover, whichever is higher; the rate is set by Article 99(4)(e). The omnibus did not change it. A related topic is the fundamental rights impact assessment under Article 27, where the omnibus now allows, in paragraphs 4 and 5, cross-references to the relevant sections of a data protection impact assessment, or the incorporation of parts of it; the AI Office is to develop a template questionnaire for this.
The last step is also the only one that never gets ticked off. The deployer role is not a permanent state — you can leave it without any formal decision at all, simply by doing something to the tool.
There are three circumstances, and the omnibus left Article 25(1) unchanged. First, where you put your own name or trademark on a high-risk AI system already placed on the market or put into service. Second, where you make a substantial modification to a high-risk AI system already placed on the market or put into service in such a way that it remains high-risk. Third, where you modify the intended purpose of an AI system, including a general-purpose AI system, that had not been classified as high-risk, in such a way that the system concerned becomes high-risk under Article 6. The consequence is the same in each case: the provider obligations in Article 16 apply to you.
In practice the third circumstance is the treacherous one, because it requires no technical intervention at all. It is enough for a general-purpose tool to be connected to HR data and to start assisting with decisions about candidates. Nobody reprogrammed anything, yet the intended purpose changed, and the role with it.
The omnibus amended paragraphs 2 and 4, in both cases in favour of the party that has landed in the provider role. The amended paragraph 2 continues to provide that the initial provider is no longer considered the provider of that system for the purposes of the Regulation, and it now spells out that provider's duty of cooperation as a concrete list: to make available technical documentation sufficient to assess compliance with Article 16, to inform the new providers of known limitations and failure modes, and to provide targeted technical access, including access for testing and validation. For you as the new provider, that is a substantial improvement in negotiating position.
The exception to it, however, was widened, and not in your favour. Where the initial provider has clearly specified that its AI system is not to be changed into a high-risk AI system, it is bound neither by the duty to cooperate with new providers nor by the duty to hand over documentation — in the original wording, the exception covered documentation alone. That sentence in your vendor's terms is therefore considerably more important than it used to be.
The practical measure for this step is one sentence long and costs almost nothing: add to the approval path for new tools the question of whether the proposed use changes the intended purpose. The answer is yes or no, and when it is yes, the matter goes to someone who can assess the consequences.
A finished checklist invites the impression that the topic is closed. It is not, and it is only fair to say where it ends. The AI Act is one layer of requirements, and in practice it is usually the smaller of those that bear on deploying an AI tool.
The first thing sitting alongside it is data protection. The AI Act does not replace it and refers to it expressly in several places — Article 26(9) for the impact assessment under Article 35 GDPR, Article 50(3) for processing in emotion recognition and biometric categorisation systems. Processing personal data in an AI tool is assessed under the GDPR regardless of how the tool came out in step 3.
The second is security. Where company data goes, who you have a contract with, what happens to the outputs and how the tool hooks into internal systems — none of that is answered by a risk category from the Regulation. For most companies these questions are more pressing than the regulation, because they bite sooner.
The third is the contractual side. Vendor terms decide whether you will get the documentation and the support you are going to need, and after the change to Article 25(2) that goes double. It is settled at purchase, not at inspection.
And last: this page is not a legal service. It cites articles and annexes so that the wording can be looked up, but what binds is what appears in the Official Journal, and interpretation in a specific situation belongs to whoever carries responsibility for it.
Anyone wanting to walk through exactly what the omnibus changed in the AI Act, and from when, will find it article by article on a separate page in this category — What Regulation 2026/1744 changed. Anyone dealing with an internal rule on the use of AI has a page of its own for that in the category.
The timeline reflects the changes made by Regulation (EU) 2026/1744. Most publicly available summaries were written before 27 July 2026 and give 2 August 2026 for high-risk systems — that no longer holds. The transparency obligations and the prohibitions, by contrast, were not postponed.
The statements about obligations and deadlines on this page are based on the following sources, as at 9 August 2026. This material does not replace the text of the legislation — what binds is what appears in the Official Journal.
You use AI and do not know where you stand
An initial consultation on which AI tools are running in your company, which of them touch the prohibitions in Article 5 or transparency under Article 50, and which of those carry a deadline that has already arrived. The output is a list of steps in order. Tell us what you use.