Market Launch Advisory Services
DE/EN

AI Act Checklist: 7 Points for Your Conformity Assessment

Since 2 August 2026, the core transparency obligations of the EU AI Act have been binding. For many companies entering the German market, this is no longer a topic for the future. It is current law, with direct consequences for procurement, contract design and day to day operations.

At the same time, we regularly see a pattern in our projects: many companies have an AI strategy on paper. A reliable answer to whether their actual AI usage reflects that strategy is often missing. Current surveys confirm this. 98 percent of companies have an AI strategy, yet only 39 percent have top management actively steering actual usage. At the same time, 75 percent of knowledge workers already use AI in daily work, often without official approval. This exact gap between the strategy paper and daily practice is where the real compliance risk emerges.

The following checklist covers the seven points that a reliable conformity assessment cannot do without.

1. Risk classification: Do you know where each system belongs?

The AI Act sorts AI systems by a risk based approach, from minimal risk to high risk. For every system in use, it must be documented and justified which class it falls into. Companies that have not captured this in a structured way cannot prove it in tenders and audits. Procurement departments increasingly ask for exactly this before a contract is signed, regardless of the statutory deadline.

Pyramid of the four EU AI Act risk classes: unacceptable, high risk, limited risk, minimal risk
The four EU AI Act risk classes at a glance.

2. Role clarification: Provider, deployer, or both?

Obligations differ fundamentally depending on the role. Many mid-sized companies are effectively deployers of AI systems, for example when they integrate a third party AI tool into internal processes, without having captured this in a structured way. This ambiguity is one of the most common pitfalls we see in first conversations.

3. Labelling obligation under Article 50: Is your content covered?

Since 2 August, AI generated images, videos and text used for professional purposes must be labelled in the EU. This applies to advertising as much as to product photos in online retail. Notably, a recent study shows that a visible AI-generated label worsens perception of a product, even when the photo was actually taken by a human. This turns correct, but not overcautious, labelling into a genuine design question, not just a legal formality.

4. Shadow AI: Is unapproved usage happening internally?

The gap mentioned above, between AI strategy and actual usage, is more than a footnote. When employees in sensitive areas such as HR, finance or legal independently turn to unapproved AI tools, a compliance gap emerges that is hard to explain in an audit. A reliable inventory of tools actually in use, not just the officially licensed ones, belongs at the start of every conformity assessment.

5. Data processing and hosting: Where does your data actually live?

With growing use of AI agents, an often underestimated question moves to the foreground: where is data processed, and under which legal framework? The US CLOUD Act allows US authorities, under certain conditions, to access data regardless of where it is stored, even when it formally sits within the EU. For companies handling sensitive data, this is a factor that should shape vendor selection, not something checked only afterwards.

6. Contractual allocation of responsibility: Who is liable if something goes wrong?

Who bears responsibility when an AI system malfunctions, the software vendor or the deploying company? Without a clear contractual arrangement, the deployer carries the risk by default. This question should be settled before a system is introduced, not once it becomes a problem.

7. Governance process: Is there a structured framework instead of case by case decisions?

The final point is also the most important one, because it makes the other six actually workable. A strong practical example comes from the Sparkassen financial group. Its communications unit has already established AI governance processes to the point where it now serves as a blueprint for other financial services providers. The decisive difference to many other companies lies not in technology, but in organisational anchoring: clear responsibilities, documented approval processes, regular review instead of a one-off policy.

How the seven points connect

None of these points works in isolation. A clean risk classification without role clarification stays incomplete. Correct labelling without a governance process is a one-off success, not a system. This exact interplay is what separates companies that turn compliance readiness into a competitive advantage in tenders from those that start from zero with every new requirement.

Important update: The high-risk obligations originally scheduled for 2 August 2026 have been postponed under the EU Digital Omnibus package, to 2 December 2027 for standalone high-risk systems under Annex III, and to 2 August 2028 for AI embedded in regulated products under Annex I. What remains binding from 2 August 2026 are the Article 50 transparency obligations and the start of active fine enforcement. Procurement departments are still asking these seven questions in tenders today, because preparing for a foreseeable obligation in practice starts earlier than the statutory deadline.

You will find the complete self-check with all seven points as a structured template in our AI Act conformity assessment whitepaper.

Download the whitepaper

Picture of Jörg Tschauder

Jörg Tschauder

Founder & Senior GTM Advisor

Bereit für Ihre DACH-Expansion?

Jörg Tschauder

Gründer & Senior GTM Advisor bei Market Launch Advisory Services. 25+ Jahre Erfahrung in internationalem Technologie-GTM, Enterprise Sales und DACH-Markteintritt.