Access control & compliance

EU AI Act Compliance Checklist for Enterprise AI Teams

Share via:
Written by:
CloudEagle.ai Team
Reviewed by
Nidhi Jain
Last Updated:
September 17, 2026
blog-cms-banner-bg
Little-Known Negotiation Hacks to Get the Best Deal on Slack
cta-bg-blogDownload Your Copy

HIPAA Compliance Checklist for 2025

Download PDF

TL;DR

  • Most enterprises are already deployers under the EU AI Act the moment they use AI-powered SaaS, whether or not they built the underlying model
  • Full deployer obligations became enforceable on August 2, 2026. This checklist assumes you are already in scope
  • Risk classification comes first. Every downstream obligation depends on whether a system is prohibited, high-risk, limited-risk, or minimal-risk
  • Fines scale by violation type: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for other non-compliance
  • Human oversight has to be genuinely reviewable and correctable. A vendor compliance checkbox does not satisfy this requirement
  • CloudEagle's AI governance module produces the live AI inventory, risk classification evidence, and audit-ready logging this checklist calls for

This EU AI Act compliance checklist is for teams that already know they are a deployer and need to work through the obligations.

Not teams still deciding whether the regulation applies to them. Not teams waiting for clearer guidance. Full deployer obligations became enforceable on August 2, 2026. If you are using AI-powered SaaS tools in your operations, you are almost certainly in scope.

Six phases. Each with the concrete evidence a regulator or auditor will actually ask for.

1. Are You a Deployer Under the EU AI Act? A Quick Reality Check

Before working through six phases of EU AI Act deployer obligations, confirm you are actually in scope.

The EU AI Act defines a deployer as any natural or legal person that uses an AI system under its authority, except for personal non-professional use. Building the underlying model is not the trigger. Using an AI-powered system in your operations is.

Most enterprises are deployers the moment any of the following touch their workflows:

  • An AI-powered HR screening or hiring tool
  • An embedded AI feature inside an approved SaaS product, even if IT never separately reviewed the AI capability
  • A customer-facing chatbot or AI-assisted support tool
  • A credit, insurance, or lending decision system with AI components
  • Any AI system that processes employee or candidate data at scale

If any of those apply to your organization, you are in scope. The checklist below covers your obligations.

For a deeper explanation of how the regulation maps to enterprise AI deployments: 👉 EU AI Act and SaaS Governance: What Enterprises Must Know

Is Your AI Program EU AI Act Ready?

Use this checklist to identify compliance gaps and keep your AI systems ready for regulatory review.
Download Checklist

2. Phase 1 Checklist: Classify Every AI System by Risk Tier

Risk classification is the foundation of this entire EU AI Act compliance checklist. Every downstream obligation, documentation requirements, human oversight mandates, log retention periods, all of them depend on which risk tier a given AI system falls into.

Risk tier structure:

Tier Description Obligation Weight
Prohibited AI practices that are banned outright Immediate cessation required
High-risk AI used in consequential decisions about people Full compliance obligations
Limited-risk AI that interacts with people without full transparency Transparency requirements
Minimal-risk All other AI systems No specific obligations

Classification checklist:

  • Inventory every AI system in use, sanctioned and shadow, including embedded AI features inside approved SaaS products
  • Classify each system as prohibited, high-risk, limited-risk, or minimal-risk based on the EU AI Act's Annex III criteria
  • Document the classification rationale for each system, not just the conclusion
  • Flag systems processing employee or candidate data, biometric data, or credit and insurance decisions for high-risk review immediately
  • Confirm no prohibited practices are in use: social scoring, real-time biometric surveillance in public spaces, and manipulative AI techniques are banned outright
  • Re-classify on a defined cadence. Vendor updates, expanded use cases, and new data categories can shift a system's risk tier

Completion signal: Every AI system has a documented risk tier with written classification rationale. Prohibited systems are identified and cessation is planned or complete. High-risk systems are flagged for phases two through five.

📖 Worth a Read 👉 AI Governance Auditing: A 2026 Playbook for Internal Audit Teams

3. Phase 2 Checklist: Build the AI System Inventory Regulators Will Ask For

This phase is where most EU AI Act compliance programs discover they have more in scope than they thought.

An AI inventory built from SSO logs surfaces the tools IT provisioned. It does not surface the AI features embedded in approved SaaS products that activated through a vendor update, the personal accounts employees use alongside enterprise seats, or the AI tools business units adopted through expense cards below procurement thresholds.

A regulator asking for your AI system register will expect all of them, not just the ones IT knows about.

Inventory requirements:

  • Maintain a living register of every AI system: vendor, purpose, data processed, populations affected, and risk tier
  • Include shadow AI, personal-account usage, and embedded AI features. Not just procured tools with formal purchase orders
  • Assign a named owner per system, not just per department
  • Document the data categories each system processes, particularly personal data, biometric data, and data relating to protected characteristics
  • Keep the inventory continuously updated, not refreshed on a quarterly cycle. A new AI tool adopted this week is in scope this week

Completion signal: A living AI system register exists. Every system has a named owner. Personal-account and embedded AI usage is included. The register reflects the current state, not last quarter's snapshot.

CloudEagle's AI governance module builds this inventory automatically by correlating SSO, browser, Zscaler, CrowdStrike, and finance signals simultaneously, surfacing the shadow AI and embedded AI features that manual inventory processes consistently miss.

👉 Shadow AI and Shadow IT Discovery

4. Phase 3 Checklist: Implement Genuine Human Oversight

Human oversight is the EU AI Act requirement most enterprises get wrong, not because they ignore it, but because they satisfy the form of it without satisfying the substance.

A vendor telling you their system supports human oversight is not evidence of human oversight. A user clicking "approve" on an AI recommendation without the context to evaluate it is not meaningful oversight. 

The regulation requires that a human can actually understand what the system is doing, review its outputs, and correct or override decisions before they take effect.

Human oversight requirements for high-risk systems:

  • Confirm high-risk AI decisions are reviewable by a qualified human before they take effect, not after the outcome is already locked in
  • Confirm the human reviewer can actually correct or override the decision, not just acknowledge that it was made by AI
  • Document the oversight process per high-risk system: who reviews, what they see, what actions they can take, and what happens when they override
  • Confirm reviewers have access to sufficient information to make a meaningful judgment, not just a summary output
  • Train reviewers on what they are actually approving: the decision logic, the data inputs, the known limitations of the system
  • A vendor's compliance claim is not sufficient evidence. Document your own oversight process independently of what the vendor states

Completion signal: Every high-risk AI system has a documented oversight process. Reviewers can correct or override decisions. Training records exist. The oversight process is documented by your organization, not referenced from vendor documentation.

5. Phase 4 Checklist: Documentation and Transparency Obligations

The EU AI Act's documentation requirements apply differently by risk tier. High-risk systems carry full technical documentation obligations. Limited-risk systems carry transparency disclosure requirements. Minimal-risk systems have no specific documentation obligations.

High-risk system documentation:

  • Maintain technical documentation for each high-risk system: intended purpose, data inputs, performance metrics, and known limitations
  • Keep documentation current. Vendor updates, model version changes, and use case expansions all require documentation updates
  • Confirm documentation covers the system as deployed in your environment, not just the vendor's general product documentation
  • Prepare documentation in a form that can be produced to a regulator or auditor quickly, not reassembled from scattered sources under deadline pressure

Limited-risk transparency obligations:

  • Inform users when they are interacting with an AI system rather than a human, where required
  • Confirm AI-generated content is appropriately disclosed where the regulation requires it
  • Document how transparency disclosures are implemented and where they appear in user interactions

Vendor documentation management:

  • Keep vendor documentation current. Data handling practices, model versions, and compliance certifications change after initial procurement review
  • Confirm vendor contracts include notification requirements when AI features or data handling terms change materially
  • Flag any vendor that cannot provide documentation sufficient to support your own compliance obligations for escalation and potential replacement

Completion signal: Technical documentation exists for every high-risk system and is current. Transparency disclosures are implemented for limited-risk systems. Vendor documentation is actively maintained, not filed once and forgotten.

6. Phase 5 Checklist: Logging and Audit Evidence

Log retention is one of the EU AI Act's most specific requirements for high-risk AI systems, and it is also one of the most commonly underimplemented. Storing logs is not sufficient. The logs need to be tied to the specific control or obligation they evidence, and they need to be producible on demand.

Log retention requirements:

  • Retain logs for high-risk AI systems for a minimum of six months from the date they are generated
  • Confirm logs cover the decisions made by each high-risk system, the data inputs, the outputs, and any human review actions taken
  • Ensure logs are tied to the specific control or obligation they evidence, not just stored generically in a repository
  • Confirm log retention survives vendor or tool changes. If a system is replaced or decommissioned, logs from its operation must be retained for the minimum period

Audit evidence production:

  • Build a process to produce audit evidence on request, not just after an incident surfaces a gap
  • Confirm the time from regulator request to evidence production is measured in hours, not weeks
  • Test the evidence production process before the first regulator inquiry, not during it
  • Include access governance records in the audit evidence set: who had access to each high-risk AI system, when it was granted, and when it was revoked

Completion signal: High-risk AI system logs are retained for at least six months. Evidence is tied to specific obligations. A production process exists and has been tested. Access governance records are included in the evidence set.

CloudEagle.ai generates continuous audit-ready logs for AI access events, policy enforcement interventions, and access reviews automatically, without requiring manual assembly before each audit cycle.

👉 AI Usage Control and Policy Enforcement

7. Phase 6 Checklist: Ongoing Monitoring and Enforcement Readiness

The August 2, 2026 enforcement date is not the finish line. The EU AI Act's obligations are continuous, and enforcement guidance is still evolving. A compliance program that was complete on August 2 needs to stay complete as the environment changes.

Ongoing monitoring:

  • Monitor for new AI systems entering the environment after the initial inventory, including new vendor AI feature activations and employee-adopted tools
  • Reassess risk classification when a system's use case, data inputs, or vendor configuration changes
  • Track enforcement developments from EU national supervisory authorities. Guidance on specific obligations is still being published
  • Review the prohibited practices list when new AI capabilities are considered for deployment. The list may expand through delegated acts

Enforcement readiness:

  • Assign clear internal ownership for responding to a regulator inquiry, with a named lead and a defined escalation path
  • Confirm the AI system register, technical documentation, and audit evidence are accessible to the response team without dependency on individual knowledge holders
  • Conduct a tabletop exercise simulating a regulator inquiry before one arrives
  • Review insurance and indemnification coverage for AI-related regulatory exposure

Completion signal: A monitoring process exists for new AI system adoption. A named owner is assigned for regulator response. The evidence package is accessible to the response team. A tabletop exercise has been conducted.

Is Your AI Program EU AI Act Ready?

Use this checklist to identify compliance gaps and keep your AI systems ready for regulatory review.
Download Checklist

Get Started

This EU AI Act compliance checklist covers the six phases from risk classification through ongoing enforcement readiness. The phase that determines whether everything else is auditable is Phase 2: building an AI inventory that is actually complete, including the shadow AI and embedded SaaS AI features that most compliance inventories miss.

CloudEagle's AI governance module produces the live AI inventory, continuous risk classification evidence, policy enforcement logs, and access governance records that phases two through six of this checklist require, automatically rather than assembled before each regulatory deadline.

Book a demo with CloudEagle.ai to see how much of your EU AI Act compliance evidence already exists before the formal compliance project starts.

Frequently Asked Questions

1. Are we a deployer if we just use AI-powered SaaS tools?
Yes, in most cases. A deployer is an organization using an AI system under its authority in a professional context. Using an AI-powered SaaS tool can make your organization a deployer.

2. What is the actual fine structure under the EU AI Act?
Fines depend on the violation. Prohibited practices can reach €35 million or 7% of global annual turnover. Other violations can reach €15 million or 3%, while misleading authorities can reach €7.5 million or 1%.

3. How is the EU AI Act different from SOC 2 or GDPR compliance work?
There is overlap in areas like inventory, access controls, logging, and documentation. The EU AI Act adds AI-specific requirements, including risk classification and human oversight for high-risk systems.

4. Do companies need to inventory every AI tool they use?
Yes. Organizations need visibility into the AI systems they deploy, including their purpose, risk classification, provider, and use cases. Without an inventory, it is difficult to determine which obligations apply.

5. Who is responsible for EU AI Act compliance?
Responsibility typically spans security, legal, compliance, IT, and business teams. The key is assigning clear ownership for each AI system so someone is accountable for its risk, controls, documentation, and ongoing compliance.

Advertisement for a SaaS Subscription Tracking Template with a call-to-action button to download and a partial graphic of a tablet showing charts.Banner promoting a SaaS Agreement Checklist to streamline SaaS management and avoid budget waste with a call-to-action button labeled Download checklist.Blue banner with text 'The Ultimate Employee Offboarding Checklist!' and a black button labeled 'Download checklist' alongside partial views of checklist documents from cloudeagle.ai.Digital ad for download checklist titled 'The Ultimate Checklist for IT Leaders to Optimize SaaS Operations' by cloudeagle.ai, showing checklist pages.Slack Buyer's Guide offer with text 'Unlock insider insights to get the best deal on Slack!' and a button labeled 'Get Your Copy', accompanied by a preview of the guide featuring Slack's logo.Monday Pricing Guide by cloudeagle.ai offering exclusive pricing secrets to maximize investment with a call-to-action button labeled Get Your Copy and an image of the guide's cover.Blue banner for Canva Pricing Guide by cloudeagle.ai offering a guide to Canva costs, features, and alternatives with a call-to-action button saying Get Your Copy.Blue banner with white text reading 'Little-Known Negotiation Hacks to Get the Best Deal on Slack' and a white button labeled 'Get Your Copy'.Blue banner with text 'Little-Known Negotiation Hacks to Get the Best Deal on Monday.com' and a white button labeled 'Get Your Copy'.Blue banner with text 'Little-Known Negotiation Hacks to Get the Best Deal on Canva' and a white button labeled 'Get Your Copy'.Banner with text 'Slack Buyer's Guide' and a 'Download Now' button next to images of a guide titled 'Slack Buyer’s Guide: Features, Pricing & Best Practices'.Digital cover of Monday Pricing Guide with a button labeled Get Your Copy on a blue background.Canva Pricing Guide cover with a button labeled Get Your Copy on a blue gradient background.

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
License Count
Benchmark
Per User/Per Year

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
License Count
Benchmark
Per User/Per Year

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
Notion Plus
License Count
Benchmark
Per User/Per Year
100-500
$67.20 - $78.72
500-1000
$59.52 - $72.00
1000+
$51.84 - $57.60
Canva Pro
License Count
Benchmark
Per User/Per Year
100-500
$74.33-$88.71
500-1000
$64.74-$80.32
1000+
$55.14-$62.34

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.
Zoom Business
License Count
Benchmark
Per User/Per Year
100-500
$216.00 - $264.00
500-1000
$180.00 - $216.00
1000+
$156.00 - $180.00

Enter your email to
unlock the report

Oops! Something went wrong while submitting the form.

Get the Right Security Platform To Secure Your Cloud Infrastructure

Please enter a business email
Thank you!
The 2023 SaaS report has been sent to your email. Check your promotional or spam folder.
Oops! Something went wrong while submitting the form.

Access full report

Please enter a business email
Thank you!
The 2023 SaaS report has been sent to your email. Check your promotional or spam folder.
Oops! Something went wrong while submitting the form.

TL;DR

  • Most enterprises are already deployers under the EU AI Act the moment they use AI-powered SaaS, whether or not they built the underlying model
  • Full deployer obligations became enforceable on August 2, 2026. This checklist assumes you are already in scope
  • Risk classification comes first. Every downstream obligation depends on whether a system is prohibited, high-risk, limited-risk, or minimal-risk
  • Fines scale by violation type: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for other non-compliance
  • Human oversight has to be genuinely reviewable and correctable. A vendor compliance checkbox does not satisfy this requirement
  • CloudEagle's AI governance module produces the live AI inventory, risk classification evidence, and audit-ready logging this checklist calls for

This EU AI Act compliance checklist is for teams that already know they are a deployer and need to work through the obligations.

Not teams still deciding whether the regulation applies to them. Not teams waiting for clearer guidance. Full deployer obligations became enforceable on August 2, 2026. If you are using AI-powered SaaS tools in your operations, you are almost certainly in scope.

Six phases. Each with the concrete evidence a regulator or auditor will actually ask for.

1. Are You a Deployer Under the EU AI Act? A Quick Reality Check

Before working through six phases of EU AI Act deployer obligations, confirm you are actually in scope.

The EU AI Act defines a deployer as any natural or legal person that uses an AI system under its authority, except for personal non-professional use. Building the underlying model is not the trigger. Using an AI-powered system in your operations is.

Most enterprises are deployers the moment any of the following touch their workflows:

  • An AI-powered HR screening or hiring tool
  • An embedded AI feature inside an approved SaaS product, even if IT never separately reviewed the AI capability
  • A customer-facing chatbot or AI-assisted support tool
  • A credit, insurance, or lending decision system with AI components
  • Any AI system that processes employee or candidate data at scale

If any of those apply to your organization, you are in scope. The checklist below covers your obligations.

For a deeper explanation of how the regulation maps to enterprise AI deployments: 👉 EU AI Act and SaaS Governance: What Enterprises Must Know

Is Your AI Program EU AI Act Ready?

Use this checklist to identify compliance gaps and keep your AI systems ready for regulatory review.
Download Checklist

2. Phase 1 Checklist: Classify Every AI System by Risk Tier

Risk classification is the foundation of this entire EU AI Act compliance checklist. Every downstream obligation, documentation requirements, human oversight mandates, log retention periods, all of them depend on which risk tier a given AI system falls into.

Risk tier structure:

Tier Description Obligation Weight
Prohibited AI practices that are banned outright Immediate cessation required
High-risk AI used in consequential decisions about people Full compliance obligations
Limited-risk AI that interacts with people without full transparency Transparency requirements
Minimal-risk All other AI systems No specific obligations

Classification checklist:

  • Inventory every AI system in use, sanctioned and shadow, including embedded AI features inside approved SaaS products
  • Classify each system as prohibited, high-risk, limited-risk, or minimal-risk based on the EU AI Act's Annex III criteria
  • Document the classification rationale for each system, not just the conclusion
  • Flag systems processing employee or candidate data, biometric data, or credit and insurance decisions for high-risk review immediately
  • Confirm no prohibited practices are in use: social scoring, real-time biometric surveillance in public spaces, and manipulative AI techniques are banned outright
  • Re-classify on a defined cadence. Vendor updates, expanded use cases, and new data categories can shift a system's risk tier

Completion signal: Every AI system has a documented risk tier with written classification rationale. Prohibited systems are identified and cessation is planned or complete. High-risk systems are flagged for phases two through five.

📖 Worth a Read 👉 AI Governance Auditing: A 2026 Playbook for Internal Audit Teams

3. Phase 2 Checklist: Build the AI System Inventory Regulators Will Ask For

This phase is where most EU AI Act compliance programs discover they have more in scope than they thought.

An AI inventory built from SSO logs surfaces the tools IT provisioned. It does not surface the AI features embedded in approved SaaS products that activated through a vendor update, the personal accounts employees use alongside enterprise seats, or the AI tools business units adopted through expense cards below procurement thresholds.

A regulator asking for your AI system register will expect all of them, not just the ones IT knows about.

Inventory requirements:

  • Maintain a living register of every AI system: vendor, purpose, data processed, populations affected, and risk tier
  • Include shadow AI, personal-account usage, and embedded AI features. Not just procured tools with formal purchase orders
  • Assign a named owner per system, not just per department
  • Document the data categories each system processes, particularly personal data, biometric data, and data relating to protected characteristics
  • Keep the inventory continuously updated, not refreshed on a quarterly cycle. A new AI tool adopted this week is in scope this week

Completion signal: A living AI system register exists. Every system has a named owner. Personal-account and embedded AI usage is included. The register reflects the current state, not last quarter's snapshot.

CloudEagle's AI governance module builds this inventory automatically by correlating SSO, browser, Zscaler, CrowdStrike, and finance signals simultaneously, surfacing the shadow AI and embedded AI features that manual inventory processes consistently miss.

👉 Shadow AI and Shadow IT Discovery

4. Phase 3 Checklist: Implement Genuine Human Oversight

Human oversight is the EU AI Act requirement most enterprises get wrong, not because they ignore it, but because they satisfy the form of it without satisfying the substance.

A vendor telling you their system supports human oversight is not evidence of human oversight. A user clicking "approve" on an AI recommendation without the context to evaluate it is not meaningful oversight. 

The regulation requires that a human can actually understand what the system is doing, review its outputs, and correct or override decisions before they take effect.

Human oversight requirements for high-risk systems:

  • Confirm high-risk AI decisions are reviewable by a qualified human before they take effect, not after the outcome is already locked in
  • Confirm the human reviewer can actually correct or override the decision, not just acknowledge that it was made by AI
  • Document the oversight process per high-risk system: who reviews, what they see, what actions they can take, and what happens when they override
  • Confirm reviewers have access to sufficient information to make a meaningful judgment, not just a summary output
  • Train reviewers on what they are actually approving: the decision logic, the data inputs, the known limitations of the system
  • A vendor's compliance claim is not sufficient evidence. Document your own oversight process independently of what the vendor states

Completion signal: Every high-risk AI system has a documented oversight process. Reviewers can correct or override decisions. Training records exist. The oversight process is documented by your organization, not referenced from vendor documentation.

5. Phase 4 Checklist: Documentation and Transparency Obligations

The EU AI Act's documentation requirements apply differently by risk tier. High-risk systems carry full technical documentation obligations. Limited-risk systems carry transparency disclosure requirements. Minimal-risk systems have no specific documentation obligations.

High-risk system documentation:

  • Maintain technical documentation for each high-risk system: intended purpose, data inputs, performance metrics, and known limitations
  • Keep documentation current. Vendor updates, model version changes, and use case expansions all require documentation updates
  • Confirm documentation covers the system as deployed in your environment, not just the vendor's general product documentation
  • Prepare documentation in a form that can be produced to a regulator or auditor quickly, not reassembled from scattered sources under deadline pressure

Limited-risk transparency obligations:

  • Inform users when they are interacting with an AI system rather than a human, where required
  • Confirm AI-generated content is appropriately disclosed where the regulation requires it
  • Document how transparency disclosures are implemented and where they appear in user interactions

Vendor documentation management:

  • Keep vendor documentation current. Data handling practices, model versions, and compliance certifications change after initial procurement review
  • Confirm vendor contracts include notification requirements when AI features or data handling terms change materially
  • Flag any vendor that cannot provide documentation sufficient to support your own compliance obligations for escalation and potential replacement

Completion signal: Technical documentation exists for every high-risk system and is current. Transparency disclosures are implemented for limited-risk systems. Vendor documentation is actively maintained, not filed once and forgotten.

6. Phase 5 Checklist: Logging and Audit Evidence

Log retention is one of the EU AI Act's most specific requirements for high-risk AI systems, and it is also one of the most commonly underimplemented. Storing logs is not sufficient. The logs need to be tied to the specific control or obligation they evidence, and they need to be producible on demand.

Log retention requirements:

  • Retain logs for high-risk AI systems for a minimum of six months from the date they are generated
  • Confirm logs cover the decisions made by each high-risk system, the data inputs, the outputs, and any human review actions taken
  • Ensure logs are tied to the specific control or obligation they evidence, not just stored generically in a repository
  • Confirm log retention survives vendor or tool changes. If a system is replaced or decommissioned, logs from its operation must be retained for the minimum period

Audit evidence production:

  • Build a process to produce audit evidence on request, not just after an incident surfaces a gap
  • Confirm the time from regulator request to evidence production is measured in hours, not weeks
  • Test the evidence production process before the first regulator inquiry, not during it
  • Include access governance records in the audit evidence set: who had access to each high-risk AI system, when it was granted, and when it was revoked

Completion signal: High-risk AI system logs are retained for at least six months. Evidence is tied to specific obligations. A production process exists and has been tested. Access governance records are included in the evidence set.

CloudEagle.ai generates continuous audit-ready logs for AI access events, policy enforcement interventions, and access reviews automatically, without requiring manual assembly before each audit cycle.

👉 AI Usage Control and Policy Enforcement

7. Phase 6 Checklist: Ongoing Monitoring and Enforcement Readiness

The August 2, 2026 enforcement date is not the finish line. The EU AI Act's obligations are continuous, and enforcement guidance is still evolving. A compliance program that was complete on August 2 needs to stay complete as the environment changes.

Ongoing monitoring:

  • Monitor for new AI systems entering the environment after the initial inventory, including new vendor AI feature activations and employee-adopted tools
  • Reassess risk classification when a system's use case, data inputs, or vendor configuration changes
  • Track enforcement developments from EU national supervisory authorities. Guidance on specific obligations is still being published
  • Review the prohibited practices list when new AI capabilities are considered for deployment. The list may expand through delegated acts

Enforcement readiness:

  • Assign clear internal ownership for responding to a regulator inquiry, with a named lead and a defined escalation path
  • Confirm the AI system register, technical documentation, and audit evidence are accessible to the response team without dependency on individual knowledge holders
  • Conduct a tabletop exercise simulating a regulator inquiry before one arrives
  • Review insurance and indemnification coverage for AI-related regulatory exposure

Completion signal: A monitoring process exists for new AI system adoption. A named owner is assigned for regulator response. The evidence package is accessible to the response team. A tabletop exercise has been conducted.

Is Your AI Program EU AI Act Ready?

Use this checklist to identify compliance gaps and keep your AI systems ready for regulatory review.
Download Checklist

Get Started

This EU AI Act compliance checklist covers the six phases from risk classification through ongoing enforcement readiness. The phase that determines whether everything else is auditable is Phase 2: building an AI inventory that is actually complete, including the shadow AI and embedded SaaS AI features that most compliance inventories miss.

CloudEagle's AI governance module produces the live AI inventory, continuous risk classification evidence, policy enforcement logs, and access governance records that phases two through six of this checklist require, automatically rather than assembled before each regulatory deadline.

Book a demo with CloudEagle.ai to see how much of your EU AI Act compliance evidence already exists before the formal compliance project starts.

Frequently Asked Questions

1. Are we a deployer if we just use AI-powered SaaS tools?
Yes, in most cases. A deployer is an organization using an AI system under its authority in a professional context. Using an AI-powered SaaS tool can make your organization a deployer.

2. What is the actual fine structure under the EU AI Act?
Fines depend on the violation. Prohibited practices can reach €35 million or 7% of global annual turnover. Other violations can reach €15 million or 3%, while misleading authorities can reach €7.5 million or 1%.

3. How is the EU AI Act different from SOC 2 or GDPR compliance work?
There is overlap in areas like inventory, access controls, logging, and documentation. The EU AI Act adds AI-specific requirements, including risk classification and human oversight for high-risk systems.

4. Do companies need to inventory every AI tool they use?
Yes. Organizations need visibility into the AI systems they deploy, including their purpose, risk classification, provider, and use cases. Without an inventory, it is difficult to determine which obligations apply.

5. Who is responsible for EU AI Act compliance?
Responsibility typically spans security, legal, compliance, IT, and business teams. The key is assigning clear ownership for each AI system so someone is accountable for its risk, controls, documentation, and ongoing compliance.

CloudEagle.ai recognized in the 2025 Gartner® Magic Quadrant™ for SaaS Management Platforms
Download now
gartner chart
5x
Faster employee
onboarding
80%
Reduction in time for
user access reviews
30k
Workflows
automated
$15Bn
Analyzed in
contract spend
$2Bn
Saved in
SaaS spend

Streamline SaaS governance and save 10-30%

Book a Demo with Expert
CTA image