HIPAA Compliance Checklist for 2025
TL;DR
- Most enterprises are already deployers under the EU AI Act the moment they use AI-powered SaaS, whether or not they built the underlying model
- Full deployer obligations became enforceable on August 2, 2026. This checklist assumes you are already in scope
- Risk classification comes first. Every downstream obligation depends on whether a system is prohibited, high-risk, limited-risk, or minimal-risk
- Fines scale by violation type: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for other non-compliance
- Human oversight has to be genuinely reviewable and correctable. A vendor compliance checkbox does not satisfy this requirement
- CloudEagle's AI governance module produces the live AI inventory, risk classification evidence, and audit-ready logging this checklist calls for
This EU AI Act compliance checklist is for teams that already know they are a deployer and need to work through the obligations.
Not teams still deciding whether the regulation applies to them. Not teams waiting for clearer guidance. Full deployer obligations became enforceable on August 2, 2026. If you are using AI-powered SaaS tools in your operations, you are almost certainly in scope.
Six phases. Each with the concrete evidence a regulator or auditor will actually ask for.
1. Are You a Deployer Under the EU AI Act? A Quick Reality Check
Before working through six phases of EU AI Act deployer obligations, confirm you are actually in scope.
The EU AI Act defines a deployer as any natural or legal person that uses an AI system under its authority, except for personal non-professional use. Building the underlying model is not the trigger. Using an AI-powered system in your operations is.
Most enterprises are deployers the moment any of the following touch their workflows:
- An AI-powered HR screening or hiring tool
- An embedded AI feature inside an approved SaaS product, even if IT never separately reviewed the AI capability
- A customer-facing chatbot or AI-assisted support tool
- A credit, insurance, or lending decision system with AI components
- Any AI system that processes employee or candidate data at scale
If any of those apply to your organization, you are in scope. The checklist below covers your obligations.
For a deeper explanation of how the regulation maps to enterprise AI deployments: 👉 EU AI Act and SaaS Governance: What Enterprises Must Know
2. Phase 1 Checklist: Classify Every AI System by Risk Tier
Risk classification is the foundation of this entire EU AI Act compliance checklist. Every downstream obligation, documentation requirements, human oversight mandates, log retention periods, all of them depend on which risk tier a given AI system falls into.
Risk tier structure:
Classification checklist:
- Inventory every AI system in use, sanctioned and shadow, including embedded AI features inside approved SaaS products
- Classify each system as prohibited, high-risk, limited-risk, or minimal-risk based on the EU AI Act's Annex III criteria
- Document the classification rationale for each system, not just the conclusion
- Flag systems processing employee or candidate data, biometric data, or credit and insurance decisions for high-risk review immediately
- Confirm no prohibited practices are in use: social scoring, real-time biometric surveillance in public spaces, and manipulative AI techniques are banned outright
- Re-classify on a defined cadence. Vendor updates, expanded use cases, and new data categories can shift a system's risk tier

Completion signal: Every AI system has a documented risk tier with written classification rationale. Prohibited systems are identified and cessation is planned or complete. High-risk systems are flagged for phases two through five.
📖 Worth a Read 👉 AI Governance Auditing: A 2026 Playbook for Internal Audit Teams
3. Phase 2 Checklist: Build the AI System Inventory Regulators Will Ask For
This phase is where most EU AI Act compliance programs discover they have more in scope than they thought.
An AI inventory built from SSO logs surfaces the tools IT provisioned. It does not surface the AI features embedded in approved SaaS products that activated through a vendor update, the personal accounts employees use alongside enterprise seats, or the AI tools business units adopted through expense cards below procurement thresholds.
A regulator asking for your AI system register will expect all of them, not just the ones IT knows about.
Inventory requirements:
- Maintain a living register of every AI system: vendor, purpose, data processed, populations affected, and risk tier
- Include shadow AI, personal-account usage, and embedded AI features. Not just procured tools with formal purchase orders
- Assign a named owner per system, not just per department
- Document the data categories each system processes, particularly personal data, biometric data, and data relating to protected characteristics
- Keep the inventory continuously updated, not refreshed on a quarterly cycle. A new AI tool adopted this week is in scope this week
Completion signal: A living AI system register exists. Every system has a named owner. Personal-account and embedded AI usage is included. The register reflects the current state, not last quarter's snapshot.

CloudEagle's AI governance module builds this inventory automatically by correlating SSO, browser, Zscaler, CrowdStrike, and finance signals simultaneously, surfacing the shadow AI and embedded AI features that manual inventory processes consistently miss.
👉 Shadow AI and Shadow IT Discovery
4. Phase 3 Checklist: Implement Genuine Human Oversight
Human oversight is the EU AI Act requirement most enterprises get wrong, not because they ignore it, but because they satisfy the form of it without satisfying the substance.
A vendor telling you their system supports human oversight is not evidence of human oversight. A user clicking "approve" on an AI recommendation without the context to evaluate it is not meaningful oversight.
The regulation requires that a human can actually understand what the system is doing, review its outputs, and correct or override decisions before they take effect.
Human oversight requirements for high-risk systems:
- Confirm high-risk AI decisions are reviewable by a qualified human before they take effect, not after the outcome is already locked in
- Confirm the human reviewer can actually correct or override the decision, not just acknowledge that it was made by AI
- Document the oversight process per high-risk system: who reviews, what they see, what actions they can take, and what happens when they override
- Confirm reviewers have access to sufficient information to make a meaningful judgment, not just a summary output
- Train reviewers on what they are actually approving: the decision logic, the data inputs, the known limitations of the system
- A vendor's compliance claim is not sufficient evidence. Document your own oversight process independently of what the vendor states
Completion signal: Every high-risk AI system has a documented oversight process. Reviewers can correct or override decisions. Training records exist. The oversight process is documented by your organization, not referenced from vendor documentation.
5. Phase 4 Checklist: Documentation and Transparency Obligations
The EU AI Act's documentation requirements apply differently by risk tier. High-risk systems carry full technical documentation obligations. Limited-risk systems carry transparency disclosure requirements. Minimal-risk systems have no specific documentation obligations.
High-risk system documentation:
- Maintain technical documentation for each high-risk system: intended purpose, data inputs, performance metrics, and known limitations
- Keep documentation current. Vendor updates, model version changes, and use case expansions all require documentation updates
- Confirm documentation covers the system as deployed in your environment, not just the vendor's general product documentation
- Prepare documentation in a form that can be produced to a regulator or auditor quickly, not reassembled from scattered sources under deadline pressure
Limited-risk transparency obligations:
- Inform users when they are interacting with an AI system rather than a human, where required
- Confirm AI-generated content is appropriately disclosed where the regulation requires it
- Document how transparency disclosures are implemented and where they appear in user interactions
Vendor documentation management:
- Keep vendor documentation current. Data handling practices, model versions, and compliance certifications change after initial procurement review
- Confirm vendor contracts include notification requirements when AI features or data handling terms change materially
- Flag any vendor that cannot provide documentation sufficient to support your own compliance obligations for escalation and potential replacement
Completion signal: Technical documentation exists for every high-risk system and is current. Transparency disclosures are implemented for limited-risk systems. Vendor documentation is actively maintained, not filed once and forgotten.
6. Phase 5 Checklist: Logging and Audit Evidence
Log retention is one of the EU AI Act's most specific requirements for high-risk AI systems, and it is also one of the most commonly underimplemented. Storing logs is not sufficient. The logs need to be tied to the specific control or obligation they evidence, and they need to be producible on demand.
Log retention requirements:
- Retain logs for high-risk AI systems for a minimum of six months from the date they are generated
- Confirm logs cover the decisions made by each high-risk system, the data inputs, the outputs, and any human review actions taken
- Ensure logs are tied to the specific control or obligation they evidence, not just stored generically in a repository
- Confirm log retention survives vendor or tool changes. If a system is replaced or decommissioned, logs from its operation must be retained for the minimum period
Audit evidence production:
- Build a process to produce audit evidence on request, not just after an incident surfaces a gap
- Confirm the time from regulator request to evidence production is measured in hours, not weeks
- Test the evidence production process before the first regulator inquiry, not during it
- Include access governance records in the audit evidence set: who had access to each high-risk AI system, when it was granted, and when it was revoked
Completion signal: High-risk AI system logs are retained for at least six months. Evidence is tied to specific obligations. A production process exists and has been tested. Access governance records are included in the evidence set.

CloudEagle.ai generates continuous audit-ready logs for AI access events, policy enforcement interventions, and access reviews automatically, without requiring manual assembly before each audit cycle.
👉 AI Usage Control and Policy Enforcement
7. Phase 6 Checklist: Ongoing Monitoring and Enforcement Readiness
The August 2, 2026 enforcement date is not the finish line. The EU AI Act's obligations are continuous, and enforcement guidance is still evolving. A compliance program that was complete on August 2 needs to stay complete as the environment changes.
Ongoing monitoring:
- Monitor for new AI systems entering the environment after the initial inventory, including new vendor AI feature activations and employee-adopted tools
- Reassess risk classification when a system's use case, data inputs, or vendor configuration changes
- Track enforcement developments from EU national supervisory authorities. Guidance on specific obligations is still being published
- Review the prohibited practices list when new AI capabilities are considered for deployment. The list may expand through delegated acts
Enforcement readiness:
- Assign clear internal ownership for responding to a regulator inquiry, with a named lead and a defined escalation path
- Confirm the AI system register, technical documentation, and audit evidence are accessible to the response team without dependency on individual knowledge holders
- Conduct a tabletop exercise simulating a regulator inquiry before one arrives
- Review insurance and indemnification coverage for AI-related regulatory exposure
Completion signal: A monitoring process exists for new AI system adoption. A named owner is assigned for regulator response. The evidence package is accessible to the response team. A tabletop exercise has been conducted.
Get Started
This EU AI Act compliance checklist covers the six phases from risk classification through ongoing enforcement readiness. The phase that determines whether everything else is auditable is Phase 2: building an AI inventory that is actually complete, including the shadow AI and embedded SaaS AI features that most compliance inventories miss.
CloudEagle's AI governance module produces the live AI inventory, continuous risk classification evidence, policy enforcement logs, and access governance records that phases two through six of this checklist require, automatically rather than assembled before each regulatory deadline.
Book a demo with CloudEagle.ai to see how much of your EU AI Act compliance evidence already exists before the formal compliance project starts.
Frequently Asked Questions
1. Are we a deployer if we just use AI-powered SaaS tools?
Yes, in most cases. A deployer is an organization using an AI system under its authority in a professional context. Using an AI-powered SaaS tool can make your organization a deployer.
2. What is the actual fine structure under the EU AI Act?
Fines depend on the violation. Prohibited practices can reach €35 million or 7% of global annual turnover. Other violations can reach €15 million or 3%, while misleading authorities can reach €7.5 million or 1%.
3. How is the EU AI Act different from SOC 2 or GDPR compliance work?
There is overlap in areas like inventory, access controls, logging, and documentation. The EU AI Act adds AI-specific requirements, including risk classification and human oversight for high-risk systems.
4. Do companies need to inventory every AI tool they use?
Yes. Organizations need visibility into the AI systems they deploy, including their purpose, risk classification, provider, and use cases. Without an inventory, it is difficult to determine which obligations apply.
5. Who is responsible for EU AI Act compliance?
Responsibility typically spans security, legal, compliance, IT, and business teams. The key is assigning clear ownership for each AI system so someone is accountable for its risk, controls, documentation, and ongoing compliance.




.avif)




.avif)
.avif)




.png)


.png)

.avif)
.avif)
.avif)

