AIPolicyTracker
ChecklistFree · sent to your work emailEU AI Act

EU AI Act High-Risk Deployer Compliance Pack

Formats: XLSX and DOCX · Version v2 · Built from dataset 9710140e23e4 · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The EU AI Act High-Risk Deployer Compliance Pack is a free XLSX and DOCX checklist for EU AI Act. For organisations using a high-risk AI system: every recorded EU AI Act deployer duty as a per-system checklist, a log of notices to workers and affected people, notice templates and the dates that apply.

Format
XLSX and DOCX · Checklist
Version
v2, built 6 Oct 2026
Duties cited
9 from 1 instruments
Rows from the records
49
Frameworks
EU AI Act
Written for
Deployer / user organisation, Public authority / government body, Provider / developer
Price and licence
Free · CC BY 4.0

What's inside

  • Checklist sheet: one row per deployer duty with status, owner and evidence, to copy per system
  • Notices log for workers, affected persons and users
  • Document: worker and affected-person notice templates and a section per duty
  • Deployer duties and EU AI Act deadlines sheets

Preview

The sheets and sections of version v2, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Deployer checklist · 8 columns · 20 rows from the records
First rows of the Deployer checklist sheet
AI systemDutyReferenceStatus ▾OwnerEvidence linkApplies fromRecord
Do not deploy or provide AI for prohibited practicesArticle 52025-02-02https://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices
Ensure AI literacy of staff operating AI systemsArticle 42025-02-02https://aipolicytracker.org/obligations/eu-ai-act-ai-literacy
Design high-risk systems to log events automaticallyArticle 12; Article 26(6) for deployers2027-12-02https://aipolicytracker.org/obligations/eu-ai-act-record-keeping
Enable and assign effective human oversightArticle 14; Article 26(2) for deployers2027-12-02https://aipolicytracker.org/obligations/eu-ai-act-human-oversight
Complete conformity assessment, CE marking and EU database registrationArticles 43, 47, 48 and 49; Annex VIII2027-12-02https://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration
Use high-risk AI as instructed, monitor it and inform affected peopleArticle 262027-12-02https://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations

Copy the block of rows once per high-risk AI system you deploy. Each row is a recorded EU AI Act duty for deployers, with its reference and record.

Sheet: Notices log · 6 columns · blank, 100 rows ready to fill
First rows of the Notices log sheet
AI systemWho was told ▾How (notice, letter, intranet, form)DateNotice text or linkSent by
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

A record of every notice given about a high-risk system in use: to workers before it is used at work, and to people it makes or supports decisions about.

Sheet: Deployer duties · 14 columns · 20 rows from the records
First rows of the Deployer duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Do not deploy or provide AI for prohibited practicesProhibited practicesEU AI ActEuropean UnionProvider / developer, Deployer / user organisation, Public authority / government bodyLegal requirementArticle 52025-02-02Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause significProhibited-practice screening record; AI system inventoryClause 6.1.2 and Annex A control on AI system impact assessmentGOVERN 1.1, MAP 1.1Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices
Ensure AI literacy of staff operating AI systemsAI literacy and trainingEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 42025-02-02Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with tAI literacy training programmeClause 7.2 Competence and 7.3 AwarenessGOVERN 2.2Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-ai-literacy
Design high-risk systems to log events automaticallyRecord keeping and loggingEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 12; Article 26(6) for deployers2027-12-02High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operatiLogging specification and retention policyAnnex A control on event loggingMEASURE 2.x, MANAGE 4.1Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-record-keeping
Enable and assign effective human oversightHuman oversightEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 14; Article 26(2) for deployers2027-12-02High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avHuman oversight procedure and role assignmentAnnex A control on human oversightGOVERN 3.2, MANAGE 2.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-human-oversight
Complete conformity assessment, CE marking and EU database registrationConformity assessment and registrationEU AI ActEuropean UnionProvider / developer, Deployer / user organisation, Public authority / government bodyLegal requirementArticles 43, 47, 48 and 49; Annex VIII2027-12-02Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depeEU declaration of conformity; EU database registration recordClause 9 Performance evaluation; internal auditSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration
Use high-risk AI as instructed, monitor it and inform affected peopleGovernance and accountabilityEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 262027-12-02Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input datDeployment checklist and oversight assignment; Worker and affected-person noticesAnnex A controls on responsible use of AI systemsMANAGE 3.x, GOVERN 5.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations

Every recorded EU AI Act duty for deployers, with its source reference, evidence examples and framework mappings.

Sheet: Deadlines · 9 columns · 9 rows from the records
First rows of the Deadlines sheet
DateMilestoneInstrumentJurisdictionSource referenceStatusConfidenceNoteRecord
2024-08-01Entry into forceEU AI ActEuropean UnionArticle 113passedhighTwentieth day after publication in the Official Journal.https://aipolicytracker.org/policies/eu-ai-act
2025-02-02Prohibited practices and AI literacy apply (Chapters I and II)EU AI ActEuropean UnionArticle 113(a)passedhighArticle 5 bans and Article 4 literacy duties apply.https://aipolicytracker.org/policies/eu-ai-act
2025-08-02General-purpose AI, governance, notified bodies and penalties applyEU AI ActEuropean UnionArticle 113(b)passedhighChapter V (GPAI models), Chapter III Section 4, Chapter VII, Chapter XII (except Article 101) and Article 78 apply.https://aipolicytracker.org/policies/eu-ai-act
2026-08-02General application and Article 50 transparency dutiesEU AI ActEuropean UnionArticle 113, as amended by Regulation (EU) 2026/1744passedmediumDefault application date for the remainder of the Regulation. Regulation (EU) 2026/1744 did not move this date or the Article 50 transparency duties, according https://aipolicytracker.org/policies/eu-ai-act
2026-12-02Two further Article 5 prohibitions apply (non-consensual intimate imagery and child sexual abuse material generation)EU AI ActEuropean UnionRegulation (EU) 2026/1744 amending Articles 5 and 113scheduledmediumAdded by Regulation (EU) 2026/1744. Recorded from secondary reporting; confirm the exact wording and date against the Official Journal.https://aipolicytracker.org/policies/eu-ai-act
2027-08-02General-purpose models placed on the market before 2 August 2025 must complyEU AI ActEuropean UnionArticle 111(3)scheduledmediumTransitional period for models already on the market.https://aipolicytracker.org/policies/eu-ai-act

Document outline (DOCX)

  1. EU AI Act: high-risk deployer compliance pack
  2. The system
  3. Notice to workers (template)
  4. Notice to affected persons (template)
  5. Duties, one by one
  6. Do not deploy or provide AI for prohibited practices
  7. Ensure AI literacy of staff operating AI systems
  8. Design high-risk systems to log events automatically
  9. Enable and assign effective human oversight
  10. Complete conformity assessment, CE marking and EU database registration
  11. Use high-risk AI as instructed, monitor it and inform affected people
  12. Carry out a fundamental rights impact assessment before deployment
  13. Disclose AI interaction and label synthetic content
  14. Report serious incidents to market surveillance authorities
  15. Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
  16. Deployers must ensure input data they control is relevant and representative
  17. Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
  18. Employers must inform workers and their representatives before using high-risk AI at work
  19. Public authorities must register their use of high-risk AI and must not use unregistered systems
  20. Deployers must use the provider's transparency information in their data protection impact assessment
  21. Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
  22. Deployers must tell natural persons that a high-risk AI system is used in decisions about them
  23. Deployers of emotion recognition or biometric categorisation must inform exposed persons
  24. Deployers must disclose deepfakes and AI-generated text published on matters of public interest
  25. Deployers must explain individual decisions taken with high-risk AI on request

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v2), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Deployer checklist" and "Notices log" sheets for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Deployer checklist", "Deployer duties" and "Deadlines" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (EU AI Act: high-risk deployer compliance pack, Duties, one by one) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (9)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

  • EU AI Act European Union · Partially applicable

Version history

Versions of EU AI Act High-Risk Deployer Compliance Pack
VersionBuiltDatasetWhat changed
v29710140e23e4Dataset c6967b988bb5 → 9710140e23e4.
v1c6967b988bb5First version, built from dataset c6967b988bb5.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the EU AI Act High-Risk Deployer Compliance Pack?

Checklist sheet: one row per deployer duty with status, owner and evidence, to copy per system. Notices log for workers, affected persons and users. Document: worker and affected-person notice templates and a section per duty. Deployer duties and EU AI Act deadlines sheets.

Which duties does it cite?

9 recorded duties from EU AI Act, including Article 13, Article 14; Article 26(2) for deployers, Article 50, Article 26(7), Article 26(11) and Article 50(2). Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on deployer / user organisation, public authority / government body and provider / developer. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v2 was built on 6 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.