Use this when: you have an AI product with actual or planned EU exposure and you want to know, concretely, what to check and in what order — under the post-Omnibus deadlines (Article 50 on August 2, 2026; high-risk pushed to December 2, 2027). Every step below ends in an artefact: a decision, a UI change, or a document. If a step produces nothing written down, it didn’t happen.
Step 1 — Confirm you’re in scope
- ☐ List where your users are, where output is used, and how EU users can reach the product.
- ☐ Decision recorded: in scope / geo-blocked (with the block actually enforced).
No EU office ≠ out of scope: the Act applies to any provider whose system reaches the EU market or whose output is used in the EU — details for US companies here.
Step 2 — Audit against the prohibited list (already in force)
- ☐ Roadmap and product swept for Article 5 practices: social scoring, manipulative/exploitative techniques, emotion inference in workplaces or schools, untargeted facial-image scraping.
- ☐ Generative features checked against the two prohibitions added by the 2026 Omnibus — AI generation of CSAM or non-consensual intimate content (apply from December 2, 2026): safeguards in place and documented.
- ☐ Any hits: feature killed or redesigned, decision documented.
These are bans, in force since February 2025 (the two new ones from December 2, 2026) — a launch blocker, not a 2027 problem.
Step 3 — Fix your role per feature
- ☐ For each AI feature: are we provider (we build/brand it) or deployer (we use someone else’s)?
- ☐ Third-party models and APIs listed, with each vendor’s AI Act posture noted.
Your obligations differ by role — most startups are providers of some features and deployers of others.
Step 4 — Classify risk level
- ☐ Each feature mapped: prohibited / high-risk (Annex III or I) / transparency-only (Article 50) / minimal.
- ☐ Anything touching hiring, credit, education, insurance, critical infrastructure, biometrics → flagged for the high-risk track (deadline December 2, 2027).
Step 5 — Ship Article 50 transparency (deadline: August 2, 2026)
- ☐ Chatbots/agents/voice: explicit “you’re talking to AI” disclosure at first interaction.
- ☐ Generated content: machine-readable marking wired into the pipeline (watermarking grace to 02.12.2026 only for systems already on the EU market by 02.08.2026).
- ☐ Deepfake features: visible label.
- ☐ Emotion recognition / biometric categorisation: user notice.
Full UI patterns and exemptions: Article 50 guide.
Step 6 — GPAI check (in force since August 2025)
- ☐ Do we train or substantially modify a general-purpose model? If yes: technical documentation, copyright policy, and public training-data summary in place.
- ☐ If we only consume GPAI via API: vendor’s documentation collected for our records.
Step 7 — AI literacy (in force since February 2025)
- ☐ One documented training session for everyone who builds or operates AI features.
- ☐ Attendance recorded. (An afternoon of work; the cheapest obligation to close.)
Step 8 — Contracts and vendors
- ☐ AI Act clauses reviewed in enterprise customer contracts (warranties, allocation of provider/deployer duties).
- ☐ DPAs and AI vendor terms updated; GDPR side aligned (if you’re non-EU with EU users, you likely also need an Article 27 EU representative).
Step 9 — Documentation pack
- ☐ One-page compliance memo: scope decision, role map, risk classification, transparency measures, exemptions relied on.
- ☐ Screenshots of disclosure UI states, dated.
- ☐ Owner assigned for keeping it current.
This pack is what you’ll show enterprise procurement, investors in DD — and, if it ever comes to that, a regulator.
Step 10 — Calendar the future deadlines
- ☐ Dec 2, 2026 — watermarking grace ends (if applicable); the new Article 5 prohibitions on AI-generated CSAM/non-consensual intimate content apply.
- ☐ Early 2027 — start high-risk readiness project if Step 4 flagged anything (realistic lead time: 9–18 months to December 2, 2027).
- ☐ Aug 2, 2028 — Annex I embedded high-risk.
- ☐ Subscription to regulatory updates (or a firm that watches it for you).
Full dates and what changed in the Omnibus: EU AI Act timeline 2026–2028.
FAQ
How long does EU AI Act compliance take for a startup?
For a typical SaaS with transparency-only exposure: the checklist above is 2–3 weeks of part-time work. High-risk systems are a different animal: 9–18 months.
What’s the first deadline I should care about?
August 2, 2026 — Article 50 transparency. Everything high-risk moved to December 2027 / August 2028, but the bans and GPAI/literacy duties already apply.
Do I need a lawyer for this?
Steps 1–3 and 5–7 are founder-doable. Step 4 (risk classification) and Step 8 (contracts) are where misjudgement is expensive — that’s the part worth fixed-fee expert review.
Is there an official EU compliance checker?
The EU’s AI Act Service Desk offers a compliance checker for orientation. It won’t classify edge cases or produce your documentation — treat it as a first pass, not an answer.
What are the penalties if I skip this?
Up to €35M/7% of global turnover for prohibited practices, €15M/3% for most other violations, €7.5M/1% for incorrect information to authorities. For SMEs and startups, each cap applies at the lower of the fixed amount or the percentage.

