EU AI Act Compliance Checklist 2026: The 10-Step Version for Startups

Use this when: you have an AI product with actual or planned EU exposure and you want to know, concretely, what to check and in what order — under the post-Omnibus deadlines (Article 50 on August 2, 2026; high-risk pushed to December 2, 2027). Every step below ends in an artefact: a decision, a UI change, or a document. If a step produces nothing written down, it didn’t happen.

Step 1 — Confirm you’re in scope

  • ☐ List where your users are, where output is used, and how EU users can reach the product.
  • ☐ Decision recorded: in scope / geo-blocked (with the block actually enforced).

No EU office ≠ out of scope: the Act applies to any provider whose system reaches the EU market or whose output is used in the EU — details for US companies here.

Step 2 — Audit against the prohibited list (already in force)

  • ☐ Roadmap and product swept for Article 5 practices: social scoring, manipulative/exploitative techniques, emotion inference in workplaces or schools, untargeted facial-image scraping.
  • ☐ Generative features checked against the two prohibitions added by the 2026 Omnibus — AI generation of CSAM or non-consensual intimate content (apply from December 2, 2026): safeguards in place and documented.
  • ☐ Any hits: feature killed or redesigned, decision documented.

These are bans, in force since February 2025 (the two new ones from December 2, 2026) — a launch blocker, not a 2027 problem.

Step 3 — Fix your role per feature

  • ☐ For each AI feature: are we provider (we build/brand it) or deployer (we use someone else’s)?
  • ☐ Third-party models and APIs listed, with each vendor’s AI Act posture noted.

Your obligations differ by role — most startups are providers of some features and deployers of others.

Step 4 — Classify risk level

  • ☐ Each feature mapped: prohibited / high-risk (Annex III or I) / transparency-only (Article 50) / minimal.
  • ☐ Anything touching hiring, credit, education, insurance, critical infrastructure, biometrics → flagged for the high-risk track (deadline December 2, 2027).

Step 5 — Ship Article 50 transparency (deadline: August 2, 2026)

  • ☐ Chatbots/agents/voice: explicit “you’re talking to AI” disclosure at first interaction.
  • ☐ Generated content: machine-readable marking wired into the pipeline (watermarking grace to 02.12.2026 only for systems already on the EU market by 02.08.2026).
  • ☐ Deepfake features: visible label.
  • ☐ Emotion recognition / biometric categorisation: user notice.

Full UI patterns and exemptions: Article 50 guide.

Step 6 — GPAI check (in force since August 2025)

  • ☐ Do we train or substantially modify a general-purpose model? If yes: technical documentation, copyright policy, and public training-data summary in place.
  • ☐ If we only consume GPAI via API: vendor’s documentation collected for our records.

Step 7 — AI literacy (in force since February 2025)

  • ☐ One documented training session for everyone who builds or operates AI features.
  • ☐ Attendance recorded. (An afternoon of work; the cheapest obligation to close.)

Step 8 — Contracts and vendors

  • ☐ AI Act clauses reviewed in enterprise customer contracts (warranties, allocation of provider/deployer duties).
  • ☐ DPAs and AI vendor terms updated; GDPR side aligned (if you’re non-EU with EU users, you likely also need an Article 27 EU representative).

Step 9 — Documentation pack

  • ☐ One-page compliance memo: scope decision, role map, risk classification, transparency measures, exemptions relied on.
  • ☐ Screenshots of disclosure UI states, dated.
  • ☐ Owner assigned for keeping it current.

This pack is what you’ll show enterprise procurement, investors in DD — and, if it ever comes to that, a regulator.

Step 10 — Calendar the future deadlines

  • Dec 2, 2026 — watermarking grace ends (if applicable); the new Article 5 prohibitions on AI-generated CSAM/non-consensual intimate content apply.
  • Early 2027 — start high-risk readiness project if Step 4 flagged anything (realistic lead time: 9–18 months to December 2, 2027).
  • Aug 2, 2028 — Annex I embedded high-risk.
  • ☐ Subscription to regulatory updates (or a firm that watches it for you).

Full dates and what changed in the Omnibus: EU AI Act timeline 2026–2028.

FAQ

How long does EU AI Act compliance take for a startup?

For a typical SaaS with transparency-only exposure: the checklist above is 2–3 weeks of part-time work. High-risk systems are a different animal: 9–18 months.

What’s the first deadline I should care about?

August 2, 2026 — Article 50 transparency. Everything high-risk moved to December 2027 / August 2028, but the bans and GPAI/literacy duties already apply.

Do I need a lawyer for this?

Steps 1–3 and 5–7 are founder-doable. Step 4 (risk classification) and Step 8 (contracts) are where misjudgement is expensive — that’s the part worth fixed-fee expert review.

Is there an official EU compliance checker?

The EU’s AI Act Service Desk offers a compliance checker for orientation. It won’t classify edge cases or produce your documentation — treat it as a first pass, not an answer.

What are the penalties if I skip this?

Up to €35M/7% of global turnover for prohibited practices, €15M/3% for most other violations, €7.5M/1% for incorrect information to authorities. For SMEs and startups, each cap applies at the lower of the fixed amount or the percentage.

Want this done for you in a week?

Montaire & Co.’s fixed-fee EU AI Act compliance scan walks your product through all ten steps and hands you the documentation pack at the end. One week, no hourly billing.

30 minutes · senior advisor · no charge, no obligation

General information, not legal advice. Status as of July 16, 2026.