Regulatory Compliance

AI governance and risk mitigation

17 templates and checklists for EU AI Act compliance, based on the articles of Regulation 2024/1689.

Where to start

1. Classify your risk → 2. Complete inventory → 3. Document with templates → 4. Request audit

Request compliance audit →

Enforcement timeline

Feb 2025 Prohibited practices in force
Aug 2025 GPAI obligations active
Aug 2026 Full enforcement: all obligations
Aug 2027 High-risk AI Annex I fully enforceable

Security and compliance built in

The templates cover the four pillars of compliance: risk assessment, governance, technical documentation and operational management. Each one points directly to the articles of Regulation 2024/1689.

If you would rather not fill them in alone, our local AI consulting adapts them to your system. The official text of every article cited is in the regulation index.

Risk Assessment

4 templates

AI Risk Classification

Art. 6

Determine the risk level (high/limited/minimal) of your AI systems under the EU AI Act.

View template →

AI Systems Inventory

Art. 49

Catalog all AI systems in your organization with risk classification.

View template →

Fundamental Rights Impact Assessment

Art. 27

Fundamental rights assessment required for high-risk AI deployments.

View template →

Prohibited Practices Checklist

Art. 5

Verify your systems do not use practices prohibited by Article 5.

View template →

Governance & Policy

4 templates

Corporate AI Policy

Art. 4

Governance structure, roles, procedures, and compliance framework.

View template →

AI Literacy Training Plan

Art. 4

Training plan with objectives, content, and assessment per Art. 4.

View template →

AI Acceptable Use Policy

Art. 4

Employee guidelines for using ChatGPT, Copilot, and AI tools.

View template →

AI Ethics Framework

ALTAI

Ethical guidelines based on the EU ALTAI framework.

View template →

Technical Documentation

4 templates

Technical Documentation (Annex IV)

Annex IV

Complete documentation requirements checklist for high-risk AI providers.

View template →

Conformity Assessment

Art. 43

Step-by-step conformity assessment process under the AI Act.

View template →

AI Transparency Notice

Art. 50

Mandatory disclosure template per Article 50.

View template →

Declaration of Conformity

Art. 47

Declaration of conformity per Article 47 and Annex V.

View template →

Operational Management

4 templates

AI Vendor Due Diligence

Art. 25

46+ questions to assess AI vendor compliance.

View template →

Incident Response Plan

Art. 73

Incident management protocol and reporting obligations.

View template →

Human Oversight Guide

Art. 14

Meaningful human oversight requirements for high-risk systems.

View template →

Shadow AI Detection

Art. 4

Checklist to identify unauthorized AI use in your organization.

View template →
Compliance

EU AI Act Risk Classification

Answer 6 questions to classify your AI system and get a compliance checklist.

0%

AI literacy and internal AI policy

What the AI Act asks about training, transparency notices and internal AI use, and what the GDPR adds, with the articles.

Do I have to train my employees in AI?

You have to take measures, but not guarantee a level: since 2 February 2025 Article 4 of the AI Act has required providers and deployers to act on their staff's AI literacy. Since 27 July 2026, in the wording given by Regulation (EU) 2026/1744, the duty is to "take measures to support" that literacy, without guaranteeing any specific level of any individual.

The original wording asked for measures to ensure, "to their best extent", a sufficient level of AI literacy. The Digital Omnibus on AI (Article 1, point 5, of Regulation 2026/1744) replaced Article 4: the measures take into account people's technical knowledge, experience, education and training, the context the systems are used in and the persons they are used on, and the Commission and Member States must support SMEs in particular, with practical examples published by the Commission. The Omnibus entered into force on 27 July 2026, the third day after its publication on 24 July, with no separate date for this article. According to the Commission no certificate is needed: an internal record of trainings and other initiatives is enough. If you use high-risk AI, Article 26(2) still requires the people overseeing it to have the necessary competence, training and authority.

Reviewed: Read the full guide →

Do I need an AI use policy?

Not literally: if you use systems that are not high-risk, the AI Act does not require a document called an "AI use policy". It does require AI-literacy measures (Article 4), and the GDPR requires you to be able to demonstrate that you process personal data properly (Articles 5(2) and 24); a short policy is the practical way to evidence both.

GDPR Article 24(2) provides that, where proportionate, the controller's measures include "appropriate data protection policies", and Article 32(4) requires it to ensure that anyone acting under its authority processes personal data only on its instructions. For Article 4, the Commission states that no certificate or specific governance structure is required (no AI officer, no board), and that an internal record of trainings and initiatives is enough. A short policy usually covers which tools are approved, which data is never entered, who reviews AI output before it is used externally, and how staff are trained and recorded. If you use Annex III high-risk AI, Article 26 adds its own obligations, applicable from 2 December 2027.

Reviewed: Read the full guide →

Do I have to tell my customers they are talking to an AI?

If it is a chatbot, usually yes: since 2 August 2026 Article 50(1) requires that people interacting with an AI system are informed of it, unless this is obvious. Formally it is the provider's duty, but if you build your own assistant on a third-party model and put it into service under your name, the provider may be you (Article 3(3)).

As a deployer, Article 50(4) requires you to disclose that content is artificial in two cases: deep fakes (image, audio or video that appears authentic) and AI-generated or manipulated text you publish to inform the public on matters of public interest, unless it has undergone human review or editorial control and someone holds editorial responsibility. The notice must be clear and distinguishable, at the latest at the first interaction or exposure (Article 50(5)). Article 25, which turns into a provider anyone who puts their name on a system or modifies it, only concerns high-risk systems. Article 50 applies from 2 August 2026; Regulation (EU) 2026/1744 only gives until 2 December 2026 for the machine-readable marking of Article 50(2) in generative systems placed on the market before 2 August 2026, and does not change paragraphs 1 and 4.

Reviewed: Read the full guide →

What if an employee uses ChatGPT on their own ("shadow AI")?

The most immediate risk is data protection: if they paste customers' or employees' personal data into a personal account, that processing escapes your instructions, and as controller you are expected to have taken steps to prevent it (GDPR Articles 29 and 32(4)). In addition, the AI Act defines a deployer by use "under its authority" and only excludes personal non-professional activity, so use for work tasks is unlikely to fall outside your Article 4 duty.

GDPR Article 29 prevents anyone acting under the controller's authority from processing personal data except on its instructions, and Article 32(4) requires the controller to take steps to ensure this. If a provider processes data on your company's behalf, Article 28 requires a processing contract, which an account the employee opened personally does not create between your company and that provider. The AI Act does not expressly address unauthorised AI, but the Commission confirms that a company whose employees use ChatGPT to, for example, write advertising copy or translate text is subject to Article 4 and should inform them of risks such as hallucination. In practice: inventory what is being used, offer an approved alternative (local, or under a processing contract), set which data is never entered, and train your staff.

Reviewed: Read the full guide →

Who should receive the training?

The people in your organisation who operate or use AI systems, and those who do so on your behalf without being employees, such as contractors or service providers (Article 4). It does not have to be the same for everyone: the measures are tailored to each person's knowledge, experience and training and to the context the AI is used in.

The Commission reads "other persons dealing with the operation and use of AI systems on their behalf" as people within your organisational remit who are not employees: a contractor, a service provider or even a client, and accepts different training levels per group. It also warns that, in many cases, asking staff to read the instructions for use may be ineffective. People with a degree or experience in AI development normally count as AI-literate, though it is worth checking that they know your organisation's specific systems and their legal and ethical aspects. For high-risk systems, Article 26(2) additionally requires the people exercising human oversight to have the necessary competence, training and authority.

Reviewed: Read the full guide →

What should AI literacy training cover?

At a minimum, that your staff understand what AI is and how it works, which AI systems your organisation uses, and what their opportunities and risks are. According to the Commission, from there it is tailored to your organisation's role (provider or deployer), to the risk of the systems and to what each person already knows.

Article 4, as worded by Regulation (EU) 2026/1744, asks you to take into account people's technical knowledge, experience, education and training and the context the systems are used in. The Commission adds that simply asking staff to read the instructions for use may be ineffective, and that people using generative tools to, for example, draft or translate text should know specific risks such as hallucination. In practice a common module for everyone plus one per role is usually enough: people who use AI daily, people who review its output before it goes out, and people who decide which tools are approved.

Reviewed: Read the full guide →

How do I show I comply with Article 4, and can I be fined?

With an internal record of trainings and other initiatives: the Commission states that no certificate and no specific governance structure are required. National authorities supervise Article 4 from 2 August 2026 and may impose penalties or other measures, taking into account proportionality and the nature, gravity and intentionality of the infringement.

A useful record notes who received which training and when, which AI systems each group uses, and what material or policy they were given; the linked training-plan template does that. You do not need to appoint an AI officer or set up a board to comply with Article 4, although one can help organise it. If you also process personal data with AI, the same record helps demonstrate accountability under GDPR Article 5(2).

Reviewed: Read the full guide →

GDPR and AI: personal data in AI tools

What the GDPR asks when you use personal data with AI tools, in the cloud or locally, with the articles and what is still unsettled.

Can I put customer data into ChatGPT or another cloud AI?

Only with three things in place: a legal basis (GDPR Article 6), in practice a processor contract that meets Article 28 so the provider processes the data only on your behalf and, if the data leaves the European Economic Area, a transfer mechanism under Chapter V. If any is missing, do not enter personal data; and health data and the other special categories in Article 9 are prohibited unless one of its exceptions applies.

If the provider processes the data on your behalf, you are the controller and it is your processor (Article 4, points 7 and 8). Article 28(1) requires you to use only providers with sufficient guarantees, and Article 28(3) requires a contract that, among other things, binds it to process the data only on your documented instructions and to delete or return it at the end. Check which terms you are accepting: the consumer version and the business or API version of the same provider can have different terms. If the data goes to the United States, Implementing Decision (EU) 2023/1795 of 10 July 2023 finds an adequate level of protection only for organisations on the EU-US Data Privacy Framework List. The General Court upheld it on 3 September 2025 (Case T-553/23), but that judgment is under appeal before the Court of Justice (Case C-703/25 P), so it is worth following. For destinations without an adequacy decision you need Article 46 safeguards, such as standard contractual clauses. And even with all of that in place, the data minimisation principle (Article 5(1)(c)) asks you to send only what is needed: remove or pseudonymise names when the task does not require them.

Reviewed: Read the full guide →

Do I need a DPIA to use AI?

Not always: GDPR Article 35 requires an impact assessment when processing, in particular using new technologies, is likely to result in a high risk to people. Using AI does not trigger it on its own, but the Spanish AEPD's list says that processing meeting two or more of its criteria requires one in most cases, and the use of new technologies is one of those criteria.

Article 35(3) always requires one in three cases: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; large-scale processing of special categories or criminal-offence data; and large-scale systematic monitoring of a publicly accessible area. The AEPD's Article 35(4) list, based on the Article 29 Working Party's WP248 guidelines, adds eleven criteria, including profiling, automated decisions, special categories, large-scale processing, data on vulnerable people and the use of new technologies or an innovative use of established technologies. The AEPD itself says the list is not exhaustive: if your own analysis finds a high risk, the DPIA is mandatory even if you do not match the list. Drafting generic text with an assistant, with no personal data, does not require one; scoring candidates or customers with a model meets several criteria (profiling, automated decisions, new technologies) and normally does. The assessment is done before processing starts, with the minimum content in Article 35(7), and if it indicates a high risk you do not mitigate with your measures, Article 36 requires you to consult the AEPD before processing.

Reviewed: Read the full guide →

Does local AI comply with the GDPR automatically?

No. Running the model on your own hardware removes the processor contract and the international transfers with the model provider, but the rest of the GDPR stays the same: you need a legal basis, to inform people, to secure the data, to limit how long you keep it and to handle their rights.

What goes away is specific: if no third party processes the data on your behalf during inference, there is no model processor for Article 28 to apply to and no Chapter V transfer. What remains: the Article 6 legal basis (and an Article 9 exception if special categories are involved), the information duties in Articles 13 and 14, the Article 5 principles (purpose limitation, minimisation, accuracy, storage limitation), Article 32 security, which now depends entirely on you, the rights in Articles 15 to 22 and, where the risk is high, the Article 35 DPIA. Two caveats: if a company maintains the equipment for you and processes the data on your behalf, it is your processor and you need a contract with it; and if the model produces inaccurate statements about specific people and you use them, the accuracy principle in Article 5(1)(d) applies all the same. Local reduces the risk surface; it does not replace compliance.

Reviewed: Read the full guide →

Do I have to tell people that I use AI with their data?

The GDPR does not ask for a line saying "we use AI", but it does require you to say why you process the data, on what legal basis, who receives it (the AI provider included) and whether it is transferred outside the European Economic Area (Articles 13 and 14). And if you take decisions based solely on automated processing with legal or similarly significant effects (Article 22), you must say so and give meaningful information about the logic involved.

If you collect the data from the person, the information is given when you obtain it (Article 13); if you obtain it from another source, within a reasonable period and at the latest within one month, or at the first communication with them (Article 14(3)). A provider that processes the data counts as a recipient even when it is your processor (Article 4(9)). If you are going to use data you already hold for a new purpose, such as analysing it with a model for something other than what you told people, Articles 13(3) and 14(4) require you to inform them before you do. For Article 22 decisions, Articles 13(2)(f) and 14(2)(g) require you to disclose their existence, the logic involved and the envisaged consequences, and where the decision is based on a contract or explicit consent, Article 22(3) requires at least that the person can obtain human intervention, express their point of view and contest the decision. Beyond the GDPR, the AI Act adds its own notices from 2 August 2026, such as telling someone they are talking to a chatbot (Article 50).

Reviewed: Read the full guide →

Can I use personal data to train or fine-tune a model?

It can be lawful, but it is not automatic: training or fine-tuning is processing with its own purpose, which needs a legal basis and, if you reuse data collected for something else, must pass the compatibility test in GDPR Article 6(4). Legitimate interest can work in some cases, according to the European Data Protection Board's Opinion 28/2024, provided you pass its three-step test.

The purpose limitation principle (Article 5(1)(b)) prevents processing data in a way that is incompatible with the purposes you collected it for. If you rely neither on consent nor on a law, Article 6(4) requires you to weigh, among other factors, the link between the two purposes, the context of collection and your relationship with the people, the nature of the data, the possible consequences and the safeguards, such as encryption or pseudonymisation. EDPB Opinion 28/2024, adopted on 17 December 2024, recalls that there is no hierarchy between legal bases and sets out the Article 6(1)(f) legitimate-interest test: a lawful, clearly articulated and real interest; processing that is necessary, with no less intrusive way; and people's rights not overriding it, where their reasonable expectations weigh in. It also warns that a model trained on personal data cannot in all cases be considered anonymous, and it leaves special categories outside its analysis; processing them remains prohibited unless an Article 9(2) exception applies. Under legitimate interest, people keep the Article 21 right to object. One open point: the proposed "Digital Omnibus" Regulation (COM(2025) 837) would change the GDPR on legitimate interest for AI and on the definition of personal data, but according to the European Parliament it is still going through the legislative process and changes nothing above today.

Reviewed: Read the full guide →

What do I do if someone asks for their data to be erased from a model?

Reply within one month (GDPR Article 12(3)) and, if one of the grounds in Article 17(1) applies, erase the data wherever you hold it: conversation logs, knowledge bases and documents the assistant consults, and fine-tuning datasets. Removing data from the weights of a model that is already trained is technically hard, and there is not yet a settled view on how far that obligation reaches.

Erasure is not absolute: Article 17(1) grants it, among other cases, when the data is no longer needed, when consent is withdrawn, when the person successfully objects (Article 21) or when the processing was unlawful, and Article 17(3) sets out exceptions, such as the defence of legal claims. The one month can be extended by two further months for complex requests, if you say so within the first month. If you use a third-party model you have not trained on your data, the request concerns what you process, and if the provider is your processor, Article 28(3)(e) requires it to help you respond. If you have fine-tuned a model on personal data, EDPB Opinion 28/2024 recalls that such a model is not anonymous in all cases, so the rights can reach it; it cites output filters and post-training techniques that attempt to remove or suppress personal data as measures, and notes that authorities can order the erasure of the dataset or of the model itself if it was trained unlawfully. The AEPD's AI guidance asks for training data to be erased once no longer needed, or for a justification of why it cannot be, and recalls that in Spain erasure goes together with the blocking of data under Article 32 of the LOPDGDD (the Spanish data protection act). If you will not act on the request, Article 12(4) requires you to explain why within the month and to mention the right to complain to the AEPD.

Reviewed: Read the full guide →

Who is controller and who is processor when I use an AI provider?

Normally you are the controller, because you decide why and how the data is processed (GDPR Article 4(7)), and the provider is your processor when it processes the data on your behalf (Article 4(8)). If the provider uses that data for its own purposes, such as training its models, it becomes a controller for that use.

As controller, you are responsible for the processing and must be able to demonstrate compliance (Article 5(2)). With a processor, Article 28 requires one with sufficient guarantees, a written contract with the minimum content in Article 28(3) (documented instructions, confidentiality, Article 32 security, help with rights and with the DPIA, deletion or return at the end, audits) and your prior authorisation before it engages other processors (Article 28(2)). Article 28(10) provides that a processor that determines the purposes and means of processing is considered a controller for that processing, and the AEPD's AI guidance applies this to providers: any additional processing they carry out for their own purposes makes them controllers for it. If you and the provider jointly decide purposes and means, you are joint controllers (Article 26): you need an arrangement that allocates the obligations, and the person can exercise their rights against either of you. What counts is who decides the purposes and means, so read the contract together with the provider's data-use policy before entering personal data.

Reviewed: Read the full guide →

Need help with compliance?

I run full EU AI Act compliance audits: I assess your organisation, find the gaps and hand you an action plan.

Book a consultation
The EU AI Act now applies: a checklist you can complete

Tell us what you want to run

Tell us what you want to run and on what budget. We will tell you which hardware you need, which model fits, and what to expect from it, before you spend anything.

First call free, 15 min Local-first: your data stays on your network Open tools and guides

69 free guides · 17 compliance templates