EU AI Act Self-Check

Audit Your AI Compliance

A 10-Point EU AI Act Self-Check for Businesses

Created by Vagelis Papaloukas, a software architect who builds EU AI Act- and GDPR-compliant AI systems in production. Not an influencer’s checklist: every point below maps to a real obligation.

What this is. A fast, plain-language self-assessment to see roughly where your organisation stands on the EU AI Act (Regulation (EU) 2024/1689) and adjacent GDPR duties. Answer honestly in ~10 minutes.

Who it’s for. Owners, managers, and ops/HR/IT leads at any company that uses AI, including staff quietly using ChatGPT, Copilot, or Claude. You don’t need to be technical.

What it is not. ⚠️ This is an educational self-check, not legal advice, and it doesn’t create a client relationship. It’s a starting point to find gaps, not a compliance certificate. Confirm specifics for your situation with qualified counsel.

How to score. For each of the 10 points: Yes = 2 · Partly = 1 · No = 0. Add them up (max 20). Bands are at the end.

The EU AI Act: the dates that actually matter

DateWhat applies
1 Aug 2024Regulation entered into force
2 Feb 2025Prohibited AI practices banned · AI-literacy duty begins (in force now, but a soft duty; see #4)
2 Aug 2025Rules for general-purpose AI (GPAI) models, governance, most penalties
2 Aug 2026Transparency duties (Art. 50: disclosing & labelling AI content) · GPAI enforcement begins
2 Dec 2026New prohibited practice (AI that generates non-consensual intimate imagery / CSAM) fully bites · AI-content marking deadline for systems already on the market before Aug 2026
2 Dec 2027High-risk systems (Annex III: HR, credit, biometrics, education…), delayed from Aug 2026
2 Aug 2028High-risk AI embedded in regulated products (Annex I), delayed from Aug 2027

⚠️ Updated 26 Jul 2026: the EU's "Digital Omnibus" is law: Regulation (EU) 2026/1744, published in the EU Official Journal on 24 Jul 2026, with entry into force 27 Jul 2026. It postpones the high-risk deadlines above, and makes two changes almost everyone is getting wrong. It added a new prohibited practice (so the bans did not stay untouched), and it softened the AI-literacy duty, from "ensure a sufficient level" to "support the development of" (see #4). Transparency (Art. 50) and GPAI enforcement are unchanged and apply from 2 Aug 2026, the nearest deadline on this page; if your system was already on the market before that date, the AI-content marking part gives you until 2 Dec 2026. The dates in the table above are the amended, in-force ones: plan against them. Fast-moving area, so verify current status before acting.

The 10-point self-check

Yes = 2 Partly = 1 No = 0
1. AI inventory: do you know what you're running?

Do you have a written list of every AI tool in use, including staff using public tools on their own?

You can’t govern what you can’t see. "Shadow AI" is the #1 blind spot.

2. Risk classification: have you sorted your AI by risk tier?

Have you checked whether any use is high-risk under Annex III (e.g. hiring/HR, credit scoring, biometrics, education assessment, critical infrastructure)?

High-risk carries the heaviest obligations. Most SMB uses are lower-risk, but you must confirm, not assume.

3. Prohibited practices: are you sure you’re not doing a banned one?

None of your AI does social scoring, emotion recognition of staff at work, manipulative/subliminal targeting, or untargeted face-scraping?

These are already illegal (since Feb 2025), and the Digital Omnibus added one more: AI that generates non-consensual intimate imagery or CSAM (fully biting by Dec 2026). A single "No" here is urgent regardless of your total.

4. AI literacy: are your people equipped (not "certified")?

Since Feb 2025 you have a duty to support your staff in developing "sufficient AI literacy." Do you have any training or policy in place?

Read this one carefully, because the market is lying to you about it. The Omnibus softened Article 4 from "ensure" to "support": it is an obligation of effort, not of result. The published text says it outright: "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual." (Art. 4, as amended by Regulation (EU) 2026/1744). So: no mandated format, no certificate, no measurable level, no approved provider. Do it because untrained staff are your real risk, not because an inspector is coming. Anyone selling you a "mandatory AI Act certification" is selling you fear.

5. Transparency: do you disclose AI to the people it touches?

Where AI chats with customers, or generates text/images/audio/video, do you clearly disclose it (and label synthetic/"deepfake" content)?

Article 50 transparency duties apply broadly from Aug 2026. If your system was already live before then, the machine-readable content-marking part gives you until Dec 2026. This is the near-term deadline that actually has teeth.

6. Human oversight: is a person accountable for AI-assisted decisions?

For any consequential decision AI helps make, can a competent human understand, review, and override it?

"The system decided" is not a defence. Human-in-the-loop is the core of trustworthy AI.

7. Data & GDPR: is personal data handled lawfully?

Do your AI uses have a lawful basis, data minimisation, and (where needed) a DPIA, and do you avoid pasting confidential or personal data into public AI tools?

The AI Act sits on top of GDPR; both still apply, including rules on automated decisions (Art. 22).

8. Vendor due diligence: do you know your AI suppliers’ posture?

For third-party and general-purpose AI (ChatGPT, Claude, Copilot, etc.), do you know each vendor's data handling and your own duties as a deployer?

Using someone else’s model doesn’t outsource your responsibility.

9. Governance: is there an owner, a policy, and a paper trail?

Is there a named person responsible for AI, a simple acceptable-use policy, and a basic record of decisions and monitoring?

If challenged, "we had it under control" needs evidence. Lightweight documentation is enough to start.

10. Roadmap: do you have a plan for the deadlines that apply to you?

Do you have a concrete plan to close your gaps: transparency & GPAI from Aug 2026, and high-risk (Annex III) by Dec 2027 if any of your uses qualify?

The near-term pressure with real teeth is transparency. Literacy is a soft duty. Do it anyway, because it's cheap and untrained staff are your actual risk. High-risk got more runway, so use it, don't ignore it.

Your score

Your total: 0 / 20

Answer all 10 questions to see your total.

15–20

Strong footing.

You’re ahead of most. Focus on maintaining, documenting, and monitoring as your AI use grows.

8–14

Partial.

You have real, closable gaps. Start with what has teeth now, transparency (#5) and oversight (#6), then literacy (#4: soft duty, but the cheapest risk you'll ever retire), then plan high-risk (#2) toward its 2027 deadline.

0–7

High exposure.

Treat this as a priority. Begin with an inventory (#1) and a risk sort (#2), and get staff literacy in place fast.

🚩 Any "No" on #3 (prohibited practices) is urgent. Address it immediately, regardless of your total.

What to do next

Most teams score lower than they expect on literacy, transparency, and oversight. The good news is those are the fastest to fix.

Want to know when these rules change?

Leave your email and I'll let you know when the rules in this checklist change, plus the occasional practical write-up. No spam.

This form is only used to send you these updates. This self-check remains educational, not legal advice.

Educational self-assessment. Not legal advice.

© 2026 Vagelis Papaloukas. Free to share unmodified.