EU AI Act High-Risk Deployer Compliance Pack
In brief
The EU AI Act High-Risk Deployer Compliance Pack is a free XLSX and DOCX checklist for EU AI Act. For organisations using a high-risk AI system: every recorded EU AI Act deployer duty as a per-system checklist, a log of notices to workers and affected people, notice templates and the dates that apply.
- Format
- XLSX and DOCX · Checklist
- Version
- v2, built 6 Oct 2026
- Duties cited
- 9 from 1 instruments
- Rows from the records
- 49
- Frameworks
- EU AI Act
- Written for
- Deployer / user organisation, Public authority / government body, Provider / developer
- Price and licence
- Free · CC BY 4.0
What's inside
- Checklist sheet: one row per deployer duty with status, owner and evidence, to copy per system
- Notices log for workers, affected persons and users
- Document: worker and affected-person notice templates and a section per duty
- Deployer duties and EU AI Act deadlines sheets
Preview
The sheets and sections of version v2, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Deployer checklist
| AI system | Duty | Reference | Status ▾ | Owner | Evidence link | Applies from | Record |
|---|---|---|---|---|---|---|---|
| Do not deploy or provide AI for prohibited practices | Article 5 | 2025-02-02 | https://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices | ||||
| Ensure AI literacy of staff operating AI systems | Article 4 | 2025-02-02 | https://aipolicytracker.org/obligations/eu-ai-act-ai-literacy | ||||
| Design high-risk systems to log events automatically | Article 12; Article 26(6) for deployers | 2027-12-02 | https://aipolicytracker.org/obligations/eu-ai-act-record-keeping | ||||
| Enable and assign effective human oversight | Article 14; Article 26(2) for deployers | 2027-12-02 | https://aipolicytracker.org/obligations/eu-ai-act-human-oversight | ||||
| Complete conformity assessment, CE marking and EU database registration | Articles 43, 47, 48 and 49; Annex VIII | 2027-12-02 | https://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration | ||||
| Use high-risk AI as instructed, monitor it and inform affected people | Article 26 | 2027-12-02 | https://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations |
Copy the block of rows once per high-risk AI system you deploy. Each row is a recorded EU AI Act duty for deployers, with its reference and record.
Sheet: Notices log
| AI system | Who was told ▾ | How (notice, letter, intranet, form) | Date | Notice text or link | Sent by |
|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | |||||
A record of every notice given about a high-risk system in use: to workers before it is used at work, and to people it makes or supports decisions about.
Sheet: Deployer duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Do not deploy or provide AI for prohibited practices | Prohibited practices | EU AI Act | European Union | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | Article 5 | 2025-02-02 | Article 5 bans placing on the market, putting into service or using AI for listed practices, including subliminal or manipulative techniques that cause signific | Prohibited-practice screening record; AI system inventory | Clause 6.1.2 and Annex A control on AI system impact assessment | GOVERN 1.1, MAP 1.1 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-prohibited-practices |
| Ensure AI literacy of staff operating AI systems | AI literacy and training | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 4 | 2025-02-02 | Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with t | AI literacy training programme | Clause 7.2 Competence and 7.3 Awareness | GOVERN 2.2 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-ai-literacy |
| Design high-risk systems to log events automatically | Record keeping and logging | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 12; Article 26(6) for deployers | 2027-12-02 | High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operati | Logging specification and retention policy | Annex A control on event logging | MEASURE 2.x, MANAGE 4.1 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-record-keeping |
| Enable and assign effective human oversight | Human oversight | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 14; Article 26(2) for deployers | 2027-12-02 | High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, av | Human oversight procedure and role assignment | Annex A control on human oversight | GOVERN 3.2, MANAGE 2.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-human-oversight |
| Complete conformity assessment, CE marking and EU database registration | Conformity assessment and registration | EU AI Act | European Union | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | Articles 43, 47, 48 and 49; Annex VIII | 2027-12-02 | Before placing a high-risk system on the market, providers must complete the applicable conformity assessment (internal control or notified-body assessment depe | EU declaration of conformity; EU database registration record | Clause 9 Performance evaluation; internal audit | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration | |
| Use high-risk AI as instructed, monitor it and inform affected people | Governance and accountability | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 26 | 2027-12-02 | Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input dat | Deployment checklist and oversight assignment; Worker and affected-person notices | Annex A controls on responsible use of AI systems | MANAGE 3.x, GOVERN 5.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations |
Every recorded EU AI Act duty for deployers, with its source reference, evidence examples and framework mappings.
Sheet: Deadlines
| Date | Milestone | Instrument | Jurisdiction | Source reference | Status | Confidence | Note | Record |
|---|---|---|---|---|---|---|---|---|
| 2024-08-01 | Entry into force | EU AI Act | European Union | Article 113 | passed | high | Twentieth day after publication in the Official Journal. | https://aipolicytracker.org/policies/eu-ai-act |
| 2025-02-02 | Prohibited practices and AI literacy apply (Chapters I and II) | EU AI Act | European Union | Article 113(a) | passed | high | Article 5 bans and Article 4 literacy duties apply. | https://aipolicytracker.org/policies/eu-ai-act |
| 2025-08-02 | General-purpose AI, governance, notified bodies and penalties apply | EU AI Act | European Union | Article 113(b) | passed | high | Chapter V (GPAI models), Chapter III Section 4, Chapter VII, Chapter XII (except Article 101) and Article 78 apply. | https://aipolicytracker.org/policies/eu-ai-act |
| 2026-08-02 | General application and Article 50 transparency duties | EU AI Act | European Union | Article 113, as amended by Regulation (EU) 2026/1744 | passed | medium | Default application date for the remainder of the Regulation. Regulation (EU) 2026/1744 did not move this date or the Article 50 transparency duties, according | https://aipolicytracker.org/policies/eu-ai-act |
| 2026-12-02 | Two further Article 5 prohibitions apply (non-consensual intimate imagery and child sexual abuse material generation) | EU AI Act | European Union | Regulation (EU) 2026/1744 amending Articles 5 and 113 | scheduled | medium | Added by Regulation (EU) 2026/1744. Recorded from secondary reporting; confirm the exact wording and date against the Official Journal. | https://aipolicytracker.org/policies/eu-ai-act |
| 2027-08-02 | General-purpose models placed on the market before 2 August 2025 must comply | EU AI Act | European Union | Article 111(3) | scheduled | medium | Transitional period for models already on the market. | https://aipolicytracker.org/policies/eu-ai-act |
Document outline (DOCX)
- EU AI Act: high-risk deployer compliance pack
- The system
- Notice to workers (template)
- Notice to affected persons (template)
- Duties, one by one
- Do not deploy or provide AI for prohibited practices
- Ensure AI literacy of staff operating AI systems
- Design high-risk systems to log events automatically
- Enable and assign effective human oversight
- Complete conformity assessment, CE marking and EU database registration
- Use high-risk AI as instructed, monitor it and inform affected people
- Carry out a fundamental rights impact assessment before deployment
- Disclose AI interaction and label synthetic content
- Report serious incidents to market surveillance authorities
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
- Deployers must ensure input data they control is relevant and representative
- Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
- Employers must inform workers and their representatives before using high-risk AI at work
- Public authorities must register their use of high-risk AI and must not use unregistered systems
- Deployers must use the provider's transparency information in their data protection impact assessment
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
- Deployers must tell natural persons that a high-risk AI system is used in decisions about them
- Deployers of emotion recognition or biometric categorisation must inform exposed persons
- Deployers must disclose deepfakes and AI-generated text published on matters of public interest
- Deployers must explain individual decisions taken with high-risk AI on request
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v2), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Deployer checklist" and "Notices log" sheets for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Deployer checklist", "Deployer duties" and "Deadlines" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (EU AI Act: high-risk deployer compliance pack, Duties, one by one) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (9)
Each is cited in the file with its source reference and a link back to the record.
- Provide deployers with clear instructions for use
- Enable and assign effective human oversight
- Disclose AI interaction and label synthetic content
- Employers must inform workers and their representatives before using high-risk AI at work
- Deployers must tell natural persons that a high-risk AI system is used in decisions about them
- Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way
- Deployers of emotion recognition or biometric categorisation must inform exposed persons
- Deployers must disclose deepfakes and AI-generated text published on matters of public interest
- Deployers must explain individual decisions taken with high-risk AI on request
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v2 | 9710140e23e4 | Dataset c6967b988bb5 → 9710140e23e4. | |
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the EU AI Act High-Risk Deployer Compliance Pack?
Checklist sheet: one row per deployer duty with status, owner and evidence, to copy per system. Notices log for workers, affected persons and users. Document: worker and affected-person notice templates and a section per duty. Deployer duties and EU AI Act deadlines sheets.
Which duties does it cite?
9 recorded duties from EU AI Act, including Article 13, Article 14; Article 26(2) for deployers, Article 50, Article 26(7), Article 26(11) and Article 50(2). Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on deployer / user organisation, public authority / government body and provider / developer. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v2 was built on 6 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.