A practical, non-certifying checklist for inventory, role mapping, risk review, evidence and monitoring.
Discover
Build an inventory with owners, suppliers, intended purposes, deployment regions and affected groups.
- Identify systems and model dependencies
- Map provider and deployer roles
- Record intended and actual uses
Assess
Screen for prohibited practices, high-risk criteria, transparency duties and GPAI model responsibilities. Document open questions and the legal basis for decisions.
- Check Article 5 and Article 6
- Review relevant Annexes
- Set review dates as guidance evolves
Operate
Assign control owners for documentation, oversight, testing, incident handling, training and change management according to applicable duties.
- Retain review evidence
- Track system changes
- Reassess when intended purpose changes
Record the classification decision
For each use case, store the intended purpose, actors, affected people, relevant Article 5 screen, Article 6 route, Annex analysis and Article 50 question. Link the conclusion to a current source and named reviewer. An unresolved issue should remain visible with an owner and deadline rather than being silently marked complete.
Use the classification guide ↗Match controls to the role
A provider may need design evidence, documentation, conformity work and post-market monitoring for a high-risk system. A deployer may need instructions, trained oversight, monitoring and context-specific information duties. A general-purpose model provider has a separate Chapter V workstream. Use a responsibility matrix so each control has an owner and the contract handoff is understood.
Compare provider and deployer duties ↗Create review triggers
Set a reassessment when intended purpose, user population, data source, model version, output use or distribution geography changes. Capture incidents, complaints and material performance differences from the original assessment. Keep the current version and earlier decisions traceable so a new reviewer can see why a system was classified and what changed.
Build an AI system inventory ↗Use dates as a planning input
Different provisions have different application dates, and transition rules can depend on when a system or model was placed on the market. Record the provision alongside its date and cite the current official source. Do not treat the later high-risk application milestones as a postponement of prohibited-practice, AI literacy, general-purpose model or transparency duties.
Check the application timeline ↗This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.
Read the AI Act ↗European Commission overview ↗