Free Download · Annex III deadline December 2027

EU AI Act
High-Risk AI Readiness Checklist

55 check items covering prohibited AI uses, all eight Annex III high-risk categories, and every conformity obligation: risk management, data governance, transparency, human oversight, conformity assessment, and post-market monitoring. Open in any browser and print as PDF.

Built by CISM-certified consultants · Based on EU Regulation 2024/1689 · Annex III deadline: December 2027

This checklist consists of

55
Check Items
12
Key Articles
5
Print Pages
Cyvra & EU AI Act

We guide organisations through AI Act compliance

The checklist maps your gaps. Cyvra builds the risk management system, technical documentation, and conformity assessment needed to meet the December 2027 deadline.

Scope Assessment
We assess whether your AI systems fall within Annex III high-risk categories, identify prohibited use exposures, and determine whether GPAI obligations apply to your models or tools.
Technical Documentation
We build your Annex IV technical documentation package: risk management system, data governance records, validation results, instructions for use, and post-market monitoring plan.
Conformity Assessment
We lead you through the Article 43 self-assessment procedure, prepare the EU declaration of conformity (Annex V), and register your system in the EU AI database before the deadline.
Netherlands-based, delivery in English and Dutch
CISM-certified lead consultants with 20+ years of hands-on experience
We write the documentation alongside your team, not just deliver a gap report
Track record across financial services, healthcare, and hospitality
What's Inside

Full EU AI Act obligation coverage

Every compliance step from initial scope check through to post-market monitoring, based on EU Regulation 2024/1689.

Art. 5
Prohibited AI Practices Screening
Subliminal manipulation, exploiting vulnerabilities, social scoring, criminal risk profiling, facial recognition database scraping, emotion recognition in workplaces, biometric categorisation by sensitive characteristics, real-time remote biometric ID (law enforcement)
8 checks
Annex III
High-Risk Scope Assessment
All eight Annex III categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice
8 checks
Arts. 9–11
Risk Management, Data Governance & Technical Documentation
Lifecycle risk management system, data representativeness and bias controls, Annex IV technical documentation package including training methodology and validation results
24 checks
Arts. 12–15
Record-Keeping, Transparency, Oversight & Robustness
Automatic logging, instructions for use, human-machine interface requirements, override mechanisms, accuracy levels, adversarial robustness, and cybersecurity measures
21 checks
Arts. 43, 49, 53–55, 72
Conformity, Registration, GPAI & Post-Market
Self-assessment procedure, EU declaration of conformity, EU AI database registration, GPAI model obligations, systemic risk requirements, and post-market monitoring plan
15 checks
55 check items total
How to Use

Up and running in minutes

No software to install. Works in Chrome, Edge, or Firefox.

1
Start with the scope screen
Page 2 walks you through prohibited uses (Article 5) and all eight Annex III categories. If none apply, general transparency obligations under Article 50 still need checking.
2
Mark each obligation
Click any status badge to cycle YES / PARTIAL / NO / N/A. The compliance score on page 5 updates live. Click into Evidence or Notes to type directly.
3
Use the summary to prioritise
The page 5 summary counts your gaps and calculates a readiness score. Share it with your team, legal counsel, or bring it to a Cyvra assessment to build a remediation plan.
4
Save as PDF
Use Ctrl+P to print or export as PDF. The layout is optimised across five pages for sharing with your board, auditor, or competent authority.
Common Questions

EU AI Act: what organisations ask

Does the EU AI Act apply if we are not an AI company?
Yes. The AI Act applies to any organisation that places a high-risk AI system on the EU market or puts one into service, even if that organisation did not build the system. If you use an AI tool in recruitment, credit decisioning, access to essential services, or any Annex III context, you are a deployer and have your own obligations under Article 26. The checklist's scope screen will tell you within minutes whether your use cases are in scope.
When does the Annex III deadline apply?
2 December 2027 is the enforcement date for high-risk AI systems listed in Annex III, delayed from August 2026 by the Digital Omnibus amendments of June 2026. Prohibited practices (Article 5) have been enforceable since 2 February 2025. Article 50 transparency obligations (chatbot disclosure, synthetic content labelling, deepfake marking) took effect 2 August 2026. GPAI model obligations (Articles 53–55) apply from August 2025. Systems covered by product safety legislation face an additional delay to August 2028.
What are the fines for non-compliance?
Fines for deploying prohibited AI systems reach €35 million or 7% of global annual turnover (whichever is higher). Non-compliance with high-risk AI obligations can result in fines of up to €15 million or 3% of global turnover. Providing incorrect information to authorities carries fines of up to €7.5 million or 1% of turnover. Enforcement is by national market surveillance authorities and the EU AI Office.
Does using ChatGPT or Claude via API make us subject to the GPAI provisions?
Using a GPAI model via API as a downstream deployer does not make you a GPAI provider. The GPAI obligations (Articles 53–55) apply to the model provider, not the organisation integrating it into a product or service. However, if you use a GPAI model as a component in a high-risk AI system, your system-level obligations (Articles 9–15) still apply in full, and you must ensure the model provider gives you sufficient information to meet them.

Download the checklist

No email, no sign-up. Download it, use it across your AI portfolio, and share it with your legal and compliance team. When the results show gaps you need to close before December 2027, that is where Cyvra comes in.

Download Free Checklist Read our EU AI Act guide

EU Regulation 2024/1689 • 55 check items • 5 pages • Interactive HTML

Ready for the December 2027 deadline?

We identify which systems are in scope, build the documentation, and complete the conformity assessment before enforcement begins.

Talk to our team