AI Act checker: where does your company stand?
Tick off 67 requirements of the EU AI Act and ISO/IEC 42001 in ten areas, from risk classification to human oversight. You see your score for each area straight away; the full assessment with open items and recommendations comes by email.
Last updated: 24 September 2026 · no account · your ticks stay in your browser
The checklist
The EU AI Act and ISO/IEC 42001
The EU AI Act, Regulation (EU) 2024/1689, is the EU regulation on artificial intelligence and applies directly in every member state. ISO/IEC 42001 is the international management-system standard for AI. It gives you the structure in which the obligations can be met and evidenced: scope, policy, risk assessment, monitoring and internal audit. The checklist covers both in one pass and marks for each item whether it comes from the regulation, from the standard, or from both.
What the checklist covers
- AI risk classification — inventory, risk class of each system, prohibited practices, general-purpose AI models.
- AI governance and organisation — responsibilities, AI policy, scope of the management system.
- AI risk management — risk analysis before use, AI-specific risks, residual risks.
- High-risk AI — conformity assessment, technical documentation, registration, post-market monitoring.
- Transparency and labelling — chatbots, AI-generated content, deepfakes (Article 50).
- Data quality and data governance — training data, bias checks, GDPR and DPIA.
- Human oversight and control — override, shutdown, review of consequential decisions.
- AI management system in operation — life cycle, incidents, changes, suppliers.
- Training and AI literacy — the Article 4 obligation and role-based training.
- Performance evaluation and improvement — metrics, internal audit, management review.
Which dates apply
- Since 2 February 2025 — prohibited practices (Article 5) and AI literacy (Article 4).
- Since 2 August 2025 — rules for general-purpose AI models.
- Since 2 August 2026 — transparency obligations (Article 50), governance and penalties.
- From 2 December 2027 — high-risk obligations for systems under Annex III.
- From 2 August 2028 — high-risk obligations for systems under Annex I.
The two high-risk dates were moved by the Digital Omnibus, Regulation (EU) 2026/1744. The background is on our page the EU AI Act explained.
The risk classes
- Unacceptable risk — prohibited practices under Article 5.
- High risk — the detailed obligations of Chapter III for systems under Annex I or Annex III.
- Limited risk — transparency obligations under Article 50.
- Minimal risk — no specific obligations; the AI literacy duty in Article 4 still applies to everyone who uses AI.
Check where you stand
Tick what is already in place. Your score updates as you go. At the end you can request the full assessment by email: open items by priority and recommendations for each area.
Start the AI Act checklist →What happens with your details
The checklist runs in your browser, and your ticks are stored there. Only when you request the assessment do we receive your email address, your optional name and company, and the IDs of the items you ticked. You decide in the form whether we may also send you occasional updates on NIS2, AI and data protection; you can unsubscribe at any time. Details in our privacy policy.
Frequently asked questions
Is the AI Act checker free?
Yes. The checklist is free and needs no account. Your ticks are stored in your own browser. Only if you request the full assessment by email do we receive your email address, your optional name and company, and the IDs of the items you ticked.
What do I get by email?
The full assessment of your answers: your overall score, your score for each of the ten areas, the open items sorted by priority and recommendations for each area. The score itself is shown on screen while you fill in the checklist.
Does the AI Act apply to my company if we only use AI tools?
Usually yes, as a deployer. The AI literacy obligation in Article 4 and the transparency obligations in Article 50 apply regardless of company size. Most of the high-risk obligations only apply if you use or provide a system that falls under Annex I or Annex III.
Were the high-risk deadlines postponed?
Yes. Regulation (EU) 2026/1744 moved the high-risk obligations to 2 December 2027 for systems under Annex III and to 2 August 2028 for systems under Annex I. The prohibitions, the AI literacy obligation and the transparency obligations were not postponed.
Does the checklist replace a legal assessment?
No. It shows where your organisation stands against the requirements of the EU AI Act and ISO/IEC 42001 and where the gaps are. Whether a specific AI system is high-risk, and what follows from that, still has to be assessed case by case.
From checklist to documented evidence
The TSMONDO AI Manager takes you through classification, roles, obligations and the documents — locally, on your own machine, with no cloud account.