EU AI Act Self-Check
Audit Your AI Compliance
A 10-Point EU AI Act Self-Check for Businesses
Created by Vagelis Papaloukas, a software architect who builds EU AI Act- and GDPR-compliant AI systems in production. Not an influencer’s checklist: every point below maps to a real obligation.
What this is. A fast, plain-language self-assessment to see roughly where your organisation stands on the EU AI Act (Regulation (EU) 2024/1689) and adjacent GDPR duties. Answer honestly in ~10 minutes.
Who it’s for. Owners, managers, and ops/HR/IT leads at any company that uses AI, including staff quietly using ChatGPT, Copilot, or Claude. You don’t need to be technical.
What it is not. ⚠️ This is an educational self-check, not legal advice, and it doesn’t create a client relationship. It’s a starting point to find gaps, not a compliance certificate. Confirm specifics for your situation with qualified counsel.
How to score. For each of the 10 points: Yes = 2 · Partly = 1 · No = 0. Add them up (max 20). Bands are at the end.
The EU AI Act: the dates that actually matter
| Date | What applies |
|---|---|
| 1 Aug 2024 | Regulation entered into force |
| 2 Feb 2025 | Prohibited AI practices banned · AI-literacy duty begins (in force now, but a soft duty; see #4) |
| 2 Aug 2025 | Rules for general-purpose AI (GPAI) models, governance, most penalties |
| 2 Aug 2026 | Transparency duties (Art. 50: disclosing & labelling AI content) · GPAI enforcement begins |
| 2 Dec 2026 | New prohibited practice (AI that generates non-consensual intimate imagery / CSAM) fully bites · AI-content marking deadline for systems already on the market before Aug 2026 |
| 2 Dec 2027 | High-risk systems (Annex III: HR, credit, biometrics, education…), delayed from Aug 2026 |
| 2 Aug 2028 | High-risk AI embedded in regulated products (Annex I), delayed from Aug 2027 |
⚠️ Updated 26 Jul 2026: the EU's "Digital Omnibus" is law: Regulation (EU) 2026/1744, published in the EU Official Journal on 24 Jul 2026, with entry into force 27 Jul 2026. It postpones the high-risk deadlines above, and makes two changes almost everyone is getting wrong. It added a new prohibited practice (so the bans did not stay untouched), and it softened the AI-literacy duty, from "ensure a sufficient level" to "support the development of" (see #4). Transparency (Art. 50) and GPAI enforcement are unchanged and apply from 2 Aug 2026, the nearest deadline on this page; if your system was already on the market before that date, the AI-content marking part gives you until 2 Dec 2026. The dates in the table above are the amended, in-force ones: plan against them. Fast-moving area, so verify current status before acting.
The 10-point self-check
Your score
Your total: 0 / 20
Answer all 10 questions to see your total.
Strong footing.
You’re ahead of most. Focus on maintaining, documenting, and monitoring as your AI use grows.
Partial.
You have real, closable gaps. Start with what has teeth now, transparency (#5) and oversight (#6), then literacy (#4: soft duty, but the cheapest risk you'll ever retire), then plan high-risk (#2) toward its 2027 deadline.
High exposure.
Treat this as a priority. Begin with an inventory (#1) and a risk sort (#2), and get staff literacy in place fast.
🚩 Any "No" on #3 (prohibited practices) is urgent. Address it immediately, regardless of your total.
What to do next
Most teams score lower than they expect on literacy, transparency, and oversight. The good news is those are the fastest to fix.
Want to know when these rules change?
Leave your email and I'll let you know when the rules in this checklist change, plus the occasional practical write-up. No spam.