EU AI Act audit-readiness checklist
Select your role and risk tier to build the exact evidence pack an auditor expects — every obligation expanded to the document you must produce, the audit red flags, and the deadline. Nothing leaves your browser.
Provider — obligations & evidence
Disclose AI interaction to usersby 2026-08-02
Mark AI-generated content machine-readablyby 2026-08-02
Declare accuracy metrics in instructions for useby 2027-12-02
Fails an audit
- Accuracy levels/metrics not declared in the instructions for use.
- Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
Evidence robustness / resilienceby 2027-12-02
Fails an audit
- Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
- No clear version control / traceability between document versions and system versions.
Evidence AI-specific cybersecurityby 2027-12-02
Fails an audit
- Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
Run a lifecycle risk-management systemby 2027-12-02
Fails an audit
- Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
- No clear version control / traceability between document versions and system versions.
Govern training, validation and test databy 2027-12-02
Fails an audit
- Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
Draw up & maintain the Annex IV technical fileby 2027-12-02
Fails an audit
- Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
- No clear version control / traceability between document versions and system versions.
- No compliance matrix mapping each requirement to the specific evidence that satisfies it.
Classify the system against Article 6 / Annex IIIby 2027-12-02
Fails an audit
- Relying on the Article 6(3) 'not significant risk' exception without a documented justification.
Register in the EU databaseby 2027-12-02
Complete conformity assessment before marketby 2027-12-02
Deployer — obligations & evidence
Disclose deepfakesby 2026-08-02
Assign human oversight and use per instructions (deployer)by 2027-12-02
Fails an audit
- Deployer does not retain the automatically-generated logs of the high-risk system within its control.
Classify the system against Article 6 / Annex IIIby 2027-12-02
Fails an audit
- Relying on the Article 6(3) 'not significant risk' exception without a documented justification.
Register in the EU databaseby 2027-12-02
GPAI model provider — obligations & evidence
GPAI provider documentation & copyrightby 2025-08-02
Mark AI-generated content machine-readablyby 2026-08-02
Not sure of your risk tier? How to classify under Article 6 →
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.