The EU AI Act, as a checklist you can complete
The EU AI Act asks three things of an organisation: know which AI systems you use, classify them by risk level, and document the obligations of that level.
Free assessment in 3 minutes: 12 questions based on the articles of Regulation (EU) 2024/1689. Score and action plan included.
Updated: · Jacobo González Jaspe
-
Inventory
Which AI systems you use
-
Classification
Their risk level (Art. 6)
-
Documentation
The obligations of that level
—
—
Want to go through it together? Leave your email
Received. Your result is already on screen; I will write within one working day if there is anything to add.
EU AI Act: deployer-ready in two weeks
For companies that already use AI (a chat assistant, a copilot, a chatbot on the website) and want to have in order what Regulation (EU) 2024/1689 asks today of whoever uses it: the "deployer".
- An inventory of your AI uses Which AI tools your team uses, for which task and with which data. Everything else builds on it.
- An AI literacy plan and one training session What Art. 4 asks, applicable since 2 February 2025: proportionate measures so the people using AI know how it works and where it fails.
- Labelling and transparency The Art. 50 notices that apply to you, applicable since 2 August 2026: saying a chatbot is an AI and labelling generated content where required.
- Risk classification Each use, at its risk level and in writing. If one is high-risk (Annex III), we tell you and explain what that means.
- A written scope, agreed on the call What is in, what is out, who on your team takes part and on which dates. A fixed written quote after the call.
Two weeks from the signed scope, if your team can make the interviews and the training session in that window. If a use is high-risk, two weeks are not enough: we tell you on the call and propose a different scope.
Compliance pack
All 17 EU AI Act and GDPR templates, in one file
DPIA, FRIA, system register, human oversight, transparency and the rest. One Markdown file you open in any editor and fill in with your own facts.
One email, no automatic newsletter. Privacy
If something is unclear while you fill them in, book 15 minutes.
What applies, and when
Dates from Regulation (EU) 2024/1689. Each one is a step on the checklist, not a countdown.
Since 2 February 2025
Prohibited practices (Art. 5) and AI literacy for staff (Art. 4) already apply. They are the first two items on the checklist.
2 August 2026
General application, including the Article 50 transparency duties (whoever offers a chatbot must make clear it is an AI). The transition period in Regulation (EU) 2026/1744 covers only Article 50(2) marking of generated content, for systems already on the market.
2 December 2027
Obligations for Annex III high-risk systems. If none of your systems falls there, this item does not apply to you.
Risk classification
The EU AI Act classifies AI systems into four risk levels: unacceptable, high, limited, and minimal. Each level carries different obligations. Our tool helps you identify where your systems fall.
If you want us to review your systems with you, our local AI consulting starts with that classification. The text of the Regulation and the rest of the law cited here are in the regulation index.
View classification templates →EU AI Act: obligations and dates
What Regulation (EU) 2024/1689 asks of a Spanish SME, with the dates and the articles.
Does the AI Act apply to my SME if I only use ChatGPT?
Yes, as a "deployer" (Article 3(4)): since 2 February 2025 Article 4 applies to you, which asks you to take AI-literacy measures for your staff. High-risk obligations reach you only if you use AI for an Annex III use case, such as recruitment or creditworthiness assessment.
Using a third-party model does not make you a provider. Since Regulation (EU) 2026/1744, Article 4 asks for measures that support AI literacy, taking into account your staff's knowledge and the context of use, without requiring you to guarantee any individual's level. Article 50 adds transparency duties for deployers in specific cases: deep fakes, and AI-generated text published to inform the public without human review or editorial responsibility.
Which AI Act dates affect me?
Three have passed: prohibited practices and AI literacy since 2 February 2025, general-purpose AI models since 2 August 2025, and general application since 2 August 2026. Annex III high-risk obligations, originally due on that same date, apply from 2 December 2027: Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), adopted and in force since 27 July 2026, set that date.
The same Omnibus moves Annex I high-risk AI (AI inside Section A regulated products such as medical devices, lifts or toys; machinery moved to Section B and gets its AI requirements through delegated acts under Regulation (EU) 2023/1230 that must apply by 2 August 2028) from 2 August 2027 to 2 August 2028, and applies two new prohibited practices it adds to Article 5 from 2 December 2026. It was published in the Official Journal on 24 July 2026 and amends Article 113 of the Regulation.
Is my customer-service chatbot high-risk?
Usually not: answering enquiries is not listed in Annex III. What Article 50(1) does require is that the person knows they are talking to an AI, unless it is obvious; that duty falls on the system's provider, and if you put the chatbot into service under your own name or trademark, the provider may be you (Article 3(3)).
It becomes high-risk if the same system is used for one of the Annex III purposes, for example assessing people's creditworthiness or credit score, selecting candidates or deciding admission to an educational institution (points 3, 4 and 5). Article 50(5) requires the notice to be clear and distinguishable, at the latest at the first interaction.
What are the fines, and who enforces in Spain?
Article 99 sets three bands: up to EUR 35 million or 7% of worldwide turnover for prohibited practices; up to EUR 15 million or 3% for breaching the obligations listed in its paragraph 4, including those of deployers (Article 26) and the transparency duties (Article 50); and up to EUR 7.5 million or 1% for supplying incorrect, incomplete or misleading information to the authorities. For SMEs the lower figure of each pair applies. In Spain, the state agency for AI supervision is AESIA.
AESIA (the Spanish Agency for the Supervision of Artificial Intelligence) was created by Royal Decree 729/2023, which approves its statute, and is based in A Coruña. The 7% and 3% figures are calculated on the preceding financial year and, for larger companies, whichever is higher applies.
What is a "deployer"?
The natural or legal person, public authority or body that uses an AI system under its authority, except in a personal non-professional activity (Article 3(4)). If you buy an AI service and use it in your business, with your customers or staff, that is you.
The provider is whoever develops the system, or has it developed, and places it on the market or puts it into service under its own name or trademark (Article 3(3)). A deployer's duties include AI literacy (Article 4), transparency in the cases of Article 50 and, for high-risk systems, assigning human oversight to people with the necessary competence, training and authority (Article 26(2)).
Local AI simplifies compliance
When AI runs on your own hardware, part of the checklist gets shorter: no data transfers, no third-party processing agreements, and the audit trail stays under your control. The rest of your EU AI Act obligations remain yours.
Book a 15-minute callAESIA: Spain's AI Watchdog
Spain created AESIA, the agency that supervises AI, through Royal Decree 729/2023. It publishes guidance on applying the AI Act and coordinates the regulatory sandbox.
EU AI Act Risk Classification
Answer 6 questions to classify your AI system and get a compliance checklist.
Compliance Timeline
Compliance Checklist
VORLUX AI Recommendations
Need help with compliance?