EU AI Act Compliance Checklist: 74 Days Until High-Risk Enforcement Hits
With 74 days until EU AI Act high-risk enforcement hits, over half of organizations still lack basic AI system inventories. Here's your sprint-by-sprint compliance checklist to avoid €15 million penalties.

The August 2, 2026 deadline for EU AI Act high-risk obligations is 74 days away, and over half of organizations still lack a systematic inventory of the AI systems they operate. That inventory is the minimum prerequisite for any compliance programme. The question is not whether the regulation applies; the question is whether the evidence exists to prove compliance when a market surveillance authority asks.
In Brief
The EU AI Act’s high-risk AI system obligations become enforceable on August 2, 2026, covering eight sectors under Annex III including employment, credit scoring, biometrics, and critical infrastructure. Penalties reach €15 million or 3% of global annual turnover for high-risk violations, and €35 million or 7% for prohibited practices.
For Bulgarian teams, the national market surveillance authority designation remains incomplete, but the regulation applies directly regardless of local enforcement readiness.
If this matters to your team, it will matter on stage at ISTA 2026 this September. The organisers want real practitioners in the room, not compliance theatre.
The Deadline Is Real, Even If the Delay Might Be
Every compliance team is tracking the European Commission’s proposed Digital Omnibus package, which includes a provision to postpone Annex III high-risk obligations from August 2026 to December 2027. The European Parliament voted in favour of the delay in April 2026. The Council of the EU has not yet reached political agreement.
Do not plan around it.
The Digital Omnibus requires agreement from both the European Parliament and the Council before it becomes law. Legislative processes at that level are unpredictable. The extension may be rejected, amended, or delayed in ways that leave the August 2026 deadline intact. Organizations that pause compliance preparations pending political certainty are making a high-risk bet on a legislative outcome they cannot control, according to McKenna Consultants’ technical readiness guide.
More practically: the compliance work described here is not wasted effort even if the extension materialises. Technical documentation, quality management systems, data governance frameworks, and human oversight mechanisms are engineering investments that improve AI systems independently of their regulatory function. Build for August. Welcome any extension as a margin of safety, not a reason to delay.
Step 1: Build Your AI System Inventory
The first failure mode is invisible systems. A Deloitte survey found that only 35.7% of managers feel adequately prepared for EU AI Act compliance, while just 26.2% have started concrete compliance activities. Over half of organisations have not established systematic inventories of the AI systems they operate.
Do this next sprint:
- Audit all software procurement contracts for embedded AI components (SaaS tools with AI features count)
- Query your engineering teams for any ML models in production, including experimental deployments
- Check HR, finance, and customer service for AI-powered decision support tools
- Document each system’s purpose, data inputs, outputs, and affected persons
- Assign an owner to each system who can answer compliance questions
The inventory must include third-party AI systems deployed under your authority. If your US client uses your AI recruitment tool to screen candidates for their European offices, that system is in scope. The EU AI Act’s extraterritorial reach applies to any AI system whose output is used within the EU, regardless of where the provider or deployer is located.
Step 2: Classify Each System by Risk Tier
The EU AI Act uses a four-tier risk classification: unacceptable (banned), high-risk (heavily regulated), limited risk (transparency obligations), and minimal risk (largely unregulated). The classification determines your obligations.
Unacceptable risk systems are already banned as of February 2, 2025. These include social scoring, subliminal manipulation, emotion recognition in workplaces and educational institutions, and real-time remote biometric identification for law enforcement in public spaces.
High-risk systems under Annex III include:
- Biometric identification and categorisation (remote biometric ID, emotion recognition where permitted)
- Critical infrastructure (road traffic, water, gas, heating, electricity supply management)
- Education and vocational training (admission decisions, learning outcome evaluation, exam proctoring)
- Employment (recruitment, CV screening, promotion decisions, task allocation, termination decisions)
- Access to essential services (credit scoring, insurance pricing, emergency services dispatch)
- Law enforcement (individual risk assessment, polygraph alternatives, evidence reliability assessment)
- Migration and border control (asylum application assessment, entry screening)
- Administration of justice (legal research, case outcome prediction)
Do this next sprint:
- Map each inventoried system to the Annex III categories
- Flag any system that makes or influences decisions about natural persons in these domains
- Document the classification rationale for each system
- Use the official EU AI Act Compliance Checker to validate your classification
The trap: AI systems used for worker evaluation or task allocation can trigger full high-risk obligations without deploying a new tool. A team using GitHub Copilot for autocomplete has near-zero Annex III exposure. That same team piping GitHub telemetry into a manager-facing productivity dashboard has moved into Annex III Point 4 territory, according to Augment Code’s analysis.
Step 3: Determine Your Role in the AI Value Chain
Obligations differ based on whether you are a provider (developer), deployer (user), importer, or distributor. Most mid-market companies fall into the deployer category.
Providers (those who develop AI systems or have them developed and place them on the market under their own name) face the heaviest obligations:
- Implement a risk management system (Article 9)
- Ensure data governance and quality (Article 10)
- Maintain technical documentation per Annex IV (Article 11)
- Enable automatic logging (Article 12)
- Ensure transparency and provide information to deployers (Article 13)
- Design for human oversight (Article 14)
- Meet accuracy, robustness, and cybersecurity requirements (Article 15)
- Complete conformity assessment before market placement (Article 43)
- Register in the EU AI database
- Implement post-market monitoring
Deployers (those who use AI systems under their authority in a professional capacity) have lighter but still significant obligations under Article 26:
- Use the system according to provider instructions
- Implement human oversight with competent personnel
- Ensure input data is relevant to the intended purpose
- Monitor system operation and report malfunctions
- Retain automatically generated logs for at least six months
- Conduct Fundamental Rights Impact Assessments (FRIAs) where required
- Inform affected persons that they are subject to high-risk AI decisions
Do this next sprint:
- Classify your organisation’s role for each AI system
- If you modify a high-risk system substantially, you may become a provider
- If you use a provider’s system for a purpose not covered by their instructions, you may become a provider
- Document the role classification with supporting evidence
Step 4: Address AI Literacy Obligations (Already Enforceable)
Article 4 AI literacy requirements have been enforceable since February 2, 2025. This obligation applies to all AI systems, not just high-risk ones.
The European Commission’s Q&A clarifies that providers and deployers must ensure their staff and other persons dealing with AI systems on their behalf have a sufficient level of AI literacy. Other persons includes contractors, service providers, temporary agency workers, and partners.
Minimum content for AI literacy programmes:
- General AI understanding: what AI is, how it works, which systems are in use
- Organisational role clarity: whether the organisation develops or deploys AI
- Risk awareness: risks associated with specific AI systems and necessary mitigations
- Context-specific competence: understanding of human oversight requirements
- Critical thinking: ability to question outputs, recognise biases, decide when human intervention is required
Do this next sprint:

- Identify all personnel who interact with AI systems
- Assess current AI literacy levels against the requirements
- Develop or procure training appropriate to each role
- Document training completion and maintain records
- Review the European Commission’s repository of AI literacy programmes
The Commission makes clear that simply asking staff to read an AI system’s instructions for use may be ineffective and insufficient, according to Travers Smith’s analysis. Article 4 is a conduct obligation, not a directly finable offence, but non-compliance will likely impact the extent of enforcement measures taken for other AI Act infringements.
Step 5: Prepare Technical Documentation (Annex IV)
For high-risk systems, Annex IV specifies the technical documentation requirements. This documentation must be detailed enough for an external party to assess compliance.
Required documentation elements:
- General description of the AI system (intended purpose, provider identity, version)
- Detailed description of system elements and development process
- Information about monitoring, functioning, and control
- Description of the risk management system
- Data governance practices (training, validation, testing datasets)
- Human oversight measures
- Accuracy, robustness, and cybersecurity specifications
- Quality management system description
Do this next sprint:
- Create a documentation template aligned with Annex IV
- Assign documentation ownership to system owners
- Establish a documentation review cadence
- Ensure documentation is version-controlled and auditable
- Test documentation completeness by having someone unfamiliar with the system review it
Step 6: Implement Human Oversight Mechanisms
Article 14 requires high-risk AI systems to be designed and developed so they can be effectively overseen by natural persons during use.
Human oversight must enable the overseer to:
- Fully understand the system’s capacities and limitations
- Properly monitor operation and detect anomalies
- Interpret outputs correctly, accounting for the characteristics of the system
- Decide not to use the system or disregard, override, or reverse its output
- Intervene or interrupt the system through a stop button or similar procedure
Do this next sprint:
- Identify who will perform human oversight for each high-risk system
- Verify these individuals have the necessary training and support
- Implement technical controls that enable intervention and override
- Document the oversight procedures and escalation paths
- Test the override mechanisms under realistic conditions
Step 7: Establish Log Retention and Monitoring
Article 12 requires high-risk AI systems to have automatic logging capabilities. Deployers must retain these logs for at least six months.
Do this next sprint:
- Verify that each high-risk system generates automatic logs
- Confirm logs capture the information specified by the provider
- Implement log retention for minimum six months (longer if required by sector-specific law)
- Establish monitoring procedures to detect anomalies, malfunctions, and unexpected performance
- Create incident reporting procedures for serious incidents or malfunctions
Step 8: Conduct Fundamental Rights Impact Assessments
Article 27 requires deployers of certain high-risk AI systems to conduct Fundamental Rights Impact Assessments (FRIAs) before putting the system into use.
FRIAs are required for deployers that are:
- Bodies governed by public law
- Private entities providing public services
- Deployers of high-risk AI systems for credit scoring or insurance pricing
FRIA content requirements:
- Description of the deployer’s processes where the AI system will be used
- Period and frequency of intended use
- Categories of natural persons and groups likely to be affected
- Specific risks of harm likely to impact identified categories
- Human oversight measures
- Measures to be taken if risks materialise
Do this next sprint:
- Determine whether FRIA obligations apply to your organisation
- Develop a FRIA template aligned with Article 27 requirements
- Conduct FRIAs for applicable systems before deployment
- Notify the market surveillance authority of FRIA results where required
- Establish a FRIA review cadence for ongoing deployments
What This Means for Bulgaria
Bulgaria has not yet designated its national market surveillance authority for the EU AI Act, placing it in the red category alongside Austria, Belgium, Croatia, Estonia, Greece, Netherlands, Poland, Romania, Slovakia, Slovenia, and Sweden, according to research compiled in November 2025.
This does not mean Bulgarian organisations can delay compliance. The EU AI Act is a regulation, not a directive. It applies directly in all 27 member states from the moment each phase kicks in, regardless of national implementation status.
Practical actions for Bulgarian teams:
- Treat August 2, 2026 as the operative deadline for high-risk obligations
- Contact the AI Act Service Desk for compliance questions until Bulgaria designates its authority
- Monitor the Bulgarian Ministry of Transport and Communications for authority designation announcements
- If your organisation operates across multiple EU member states, identify which national authority has jurisdiction (typically where the AI system is first placed on the market)
- For Bulgarian engineers interviewing at EU companies, ask about AI Act compliance readiness during the interview process; it reveals organisational maturity
- If your Bulgarian company provides AI services to EU clients, expect contractual requirements for AI Act compliance evidence
The enforcement gap is temporary. The penalties are not. Organisations that build compliance infrastructure now will be positioned to demonstrate readiness when Bulgarian authorities become operational.
Dig Deeper
- Official EU AI Act Compliance Checker (European Commission)
- AI Act Explorer (Future of Life Institute)
- EU AI Act High-Risk Compliance: A Technical Readiness Guide (McKenna Consultants)
- Cloud Security Alliance Research Note on Enterprise Readiness Gap
- AI Literacy Q&A (European Commission)
- National Implementation Plans Overview (Future of Life Institute)


