Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What belongs on an AI due diligence checklist?

Last verified

An AI due diligence checklist covers model inventory, training-data provenance and rights, governance and risk, and whether the EU AI Act, ISO/IEC 42001, or NIST AI RMF is even in play. This page does not determine that the Act applies to YOU. It is not legal advice.

AI due diligence checklist, last verified 10 September 2026 against Regulation (EU) 2024/1689 (EU AI Act) including Article 113 dates, ISO/IEC 42001:2023, NIST AI RMF 1.0, and the OECD AI Principles. The Act is a legal requirement only if it applies. ISO 42001 is a standard. NIST AI RMF is a framework. Not legal advice. Not investment advice.

Four kinds of text — do not collapse them

Audience: an investor or acquirer evaluating an AI-driven company. This page is not legal advice and not investment advice. Kind of text: Regulation (EU) 2024/1689 is law if it applies. ISO/IEC 42001:2023 is a certifiable management-system standard. NIST AI RMF 1.0 is voluntary framework guidance. OECD AI Principles are intergovernmental principles. A dedicated ISO 42001 versus EU AI Act guide is not on this site yet. Naming it is not a link.

Applicability decision aid — not YOUR determination

Last verified 10 September 2026 against Article 113. This table does not determine that the Act applies to YOU and does not start a clock.

AI-instrument decision aid (not YOUR applicability; not legal advice; last verified 10 September 2026)
QuestionIf the facts lean yesKind of textWhat this page does not do
Does the target place AI systems or GPAI models on the Union market, put them into service in the Union, or deploy them where output is used in the Union?Ask counsel whether Regulation (EU) 2024/1689 applies and in which role (provider vs deployer).Legal requirement — only if the Act applies.Does not classify YOU or the target as a provider or deployer.
Is the target a GPAI-model provider?GPAI duties in the Act (including systemic-risk overlay if thresholds are met) are a different lane from high-risk system duties.Legal requirement if the Act applies. Open the EU AI Act docs hub on this site.Does not compute systemic-risk thresholds for the target.
Has the target claimed ISO/IEC 42001?Ask for the certificate scope and SoA. A certificate is not a finding that the EU AI Act is discharged.Standard — not a substitute for the Act.Does not treat ISO 42001 as a legal waiver.
Do they map to NIST AI RMF?Useful governance evidence. Voluntary unless a contract incorporates it.Framework / guidance.Does not treat a RMF worksheet as Union-market compliance.

Diligence checklist — inventory through monitoring

Last verified 10 September 2026. Not legal advice.

  • Model and system inventory: name, purpose, provider vs embedded third-party, where it runs.
  • Training-data provenance and rights: licenses, scraping claims, personal-data story — for counsel.
  • Evaluation and monitoring: metrics, red-teaming, drift, human oversight.
  • AI-authored-code share and secret-scanning on that path. Open the AI-generated-code risk page on this site.
  • Article 113 reminder (not YOUR dates): general application 2 August 2026; Annex I product-embedded high-risk 2 August 2027; GPAI duties from 2 August 2025. Those dates are not one number. This page does not start a clock.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice. Not investment advice.

  • Walk the decision aid with counsel. Do not mark “EU AI Act in-scope” in a tool and treat that as applicability.
  • Open the EU AI Act docs hub and the ISO 42001 / EU AI Act framework pages on this site.
  • Collect inventory, risk register, and evaluation evidence before the first investor call.
  • If you already have a session: signed-in app → Compliance → AI inventory and AI risk register. Naming those surfaces is not a public href.

Checklist

Question list. Not a determination. Not legal advice.

  • Is there a current AI inventory?
  • Has counsel been asked about Union-market facts?
  • Is ISO 42001 being treated as distinct from the Act?
  • Is AI-authored code measured rather than guessed?

Where this shows up in ShipReady Metrics

AI inventory, AI risk register (ISO 42001 / EU AI Act mapping), AI-authored-code floor, and AI ROI scoring. Marking a framework in-scope is not a determination that the Act applies. The product does not file with the AI Office and does not start a clock.

Primary sources (last verified 10 September 2026)

Regulation (EU) 2024/1689, including Article 113 dates. ISO/IEC 42001:2023. NIST AI RMF 1.0. OECD AI Principles. Not legal advice.

Frequently asked questions