Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Are we ready for the EU AI Act?

Updated

Readiness under Regulation (EU) 2024/1689 is not one deadline. Article 113 staggers it: 2 February 2025, 2 August 2025, 2 August 2026, and 2 August 2027 for Article 6(1). Not legal advice. This page does not determine that the Act applies to YOU.

EU AI Act readiness, last verified 10 September 2026 against Articles 2, 3, 4, 6, 9 to 15, 16, 17, 18, 19, 26, 49, 50, 51 to 55, 71, 73 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office readiness materials are Commission materials — guidance, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not file with the AI Office and does not register in the EU database.

This is a preparation list, not a compliance verdict

Audience: a founder, CTO, CISO, or compliance owner who needs one place to see what the AI Act asks, when each part started applying, and what an organisation can usefully do before anyone comes asking. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Working through it is not a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk. Completing every row does not make anyone compliant.

The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Every checklist row below carries the article it rests on and the Article 113 limb that puts that article in force. A readiness list without dates is a to-do list; a readiness list with the wrong dates is worse than none. Last verified 10 September 2026. Not legal advice.

  • Statute versus standard versus guidance versus product: the cited articles of 2024/1689 are legal requirements only if they apply. ISO/IEC 42001:2023 is a management-system standard, not a legal substitute for the Act. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office readiness materials are Commission materials — guidance, not the regulation. Every 'do this' below that is not tied to an article is a ShipReadyMetrics recommendation. This page labels which kind of text each claim rests on.
  • The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. The AI-audit-evidence guide on this site is the evidence-request-by-role page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
  • This page does not invent a 2 August 2026 date for Annex I product-embedded high-risk systems. Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. It also does not date Article 4 or Chapter II from 2 August 2026: Article 113(a) is 2 February 2025. Those dates are not one number.

Scope questions — a decision tree that produces questions, not findings

Work down the rows. Each answer narrows what could apply; none of them is a determination. If a row cannot be answered from documents the organisation already holds, that is the finding worth writing down. Counsel applies Articles 2, 3 and 6 to YOUR facts. Last verified 10 September 2026. Not legal advice.

Scope questions, not findings (not a determination that the Act applies to YOU; not a classification of YOUR system; not legal advice)
QuestionWhat the cited text points atWhat this page does not do
Does the Act reach us at all?Articles 2 and 3 — an AI system or general-purpose AI model placed on the Union market, put into service in the Union, or producing output used in the Union, together with the Article 2 exclusions.Does not run applicability for YOU. Does not determine that the Act applies to YOU.
For each system, which role are we in?Article 3 definitions with Articles 16, 22, 23, 24, 25 and 26 — provider, authorised representative, importer, distributor, deployer. The same organisation can hold different roles for different systems, and Article 25 can move a role.Does not determine that YOU are a provider or a deployer. The provider-vs-deployer guide on this site is that page.
Is anything we do a prohibited practice?Article 5, in Chapter II, which Article 113(a) applies from 2 February 2025. This is the row that is already overdue if the answer was never checked.Does not find a prohibited practice and does not clear one.
Is any system high-risk?Article 6 with Annex I and Annex III, and the Article 6(3) route to concluding a listed system is not high-risk.Does not classify YOUR system as high-risk and does not run Article 6(3).
Do we provide a general-purpose AI model?Articles 51 to 55 in Chapter V, applied from 2 August 2025 by Article 113(b), except Article 101. Systemic risk under Articles 51 and 55 is a further, separate question.Does not designate YOUR model and does not find systemic risk. The GPAI-requirements and GPAI-systemic-risk guides on this site are those pages.
Do any transparency duties bite regardless of tier?Article 50 — interaction with natural persons, synthetic content marking, emotion recognition and biometric categorisation, and deep fakes or public-interest text.Does not decide which Article 50 limbs apply to YOUR system.
If the answer to every question above is no, is anything owed?Article 4 AI literacy still reaches providers and deployers of AI systems, in force from 2 February 2025 under Article 113(a). A documented not-in-scope conclusion is itself worth keeping.Does not find that nothing is owed. A no answer recorded without reasoning is not a conclusion.

Deadline-anchored readiness checklist

Each row names what to prepare, the article it rests on, and the Article 113 limb that puts that article in force. Preparing a row is not compliance with it, and no row is a determination that the article binds YOU. Last verified 10 September 2026. Not legal advice.

Readiness items with their in-force dates (not YOUR obligations; not a compliance verdict; not legal advice)
Readiness itemIn force fromKind of textLast verified
Know whether any practice the organisation runs falls under the prohibitions2 February 2025 — Article 113(a) applies Chapters I and II, and Article 5 sits in Chapter II.Article 5 of 2024/1689. Legal requirement, only if it applies. This page does not find a prohibited practice.10 September 2026
Take measures towards a sufficient level of AI literacy for staff and others operating AI systems on the organisation's behalf2 February 2025 — Article 113(a), because Article 4 sits in Chapter I.Articles 3(56) and 4 of 2024/1689. Legal requirement, only if it applies. This product does not run YOUR literacy programme.10 September 2026
If the organisation provides a general-purpose AI model, assemble the Article 53 documentation, the copyright policy, and the sufficiently detailed training-content summary2 August 2025 — Article 113(b) applies Chapter V, with the exception of Article 101.Article 53 of 2024/1689. Legal requirement, only if it applies. The GPAI-requirements, copyright-policy and training-data-transparency guides on this site are those pages.10 September 2026
If a provided model has systemic risk, stand up the Article 55 track, including serious-incident reporting to the AI Office without undue delay2 August 2025 — Article 113(b), with the exception of Article 101.Articles 51 and 55 of 2024/1689. Legal requirement, only if it applies. This product does not file with the AI Office.10 September 2026
Maintain an inventory that can answer, per system, purpose, role, tier, GPAI status, owner, and which governance artefacts existNo article requires an inventory in those words. It is how the questions above become answerable before someone asks them.ShipReadyMetrics recommendation, informed by Annex VIII field shapes and ISO/IEC 42001:2023 practice. Not a legal requirement in itself. The ai-inventory-requirements guide on this site is that page.10 September 2026
For high-risk systems, run the Article 9 risk-management system as a continuous iterative process across the lifecycle2 August 2026 residual under Article 113, except Article 6(1) and corresponding obligations on 2 August 2027 under Article 113(c).Article 9 of 2024/1689. Legal requirement, only if it applies. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page.10 September 2026
Draw up the Article 11 technical documentation before placing on the market or putting into service, and keep it up to date2 August 2026 residual, except Article 113(c) cases on 2 August 2027.Article 11 of 2024/1689 and Annex IV. Legal requirement, only if it applies. The technical-documentation guide on this site is that page.10 September 2026
Ensure the system technically allows automatic recording of events over its lifetime, and decide who keeps those logs and for how long2 August 2026 residual, except Article 113(c) cases on 2 August 2027.Articles 12, 19 and 26(6) of 2024/1689. Legal requirements, only if they apply. At least six months for logs; the Article 18 ten-year figure is documentation, not logs.10 September 2026
Design for human oversight, and assign natural persons with competence, training, authority and support2 August 2026 residual, except Article 113(c) cases on 2 August 2027.Articles 14 and 26(2) of 2024/1689. Legal requirements, only if they apply. The AI-ownership-accountability guide on this site is that page.10 September 2026
Meet the Article 15 accuracy, robustness and cybersecurity requirements, and be able to show how they were tested2 August 2026 residual, except Article 113(c) cases on 2 August 2027.Article 15 of 2024/1689. Legal requirement, only if it applies. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.10 September 2026
Satisfy the Article 50 transparency duties that apply, per characteristic, across tiers2 August 2026 residual.Article 50 of 2024/1689. Legal requirement, only if it applies. Applicability is per characteristic, so a high-risk chatbot can owe Article 50(1) too.10 September 2026
Keep the Article 18 documentation at the disposal of national competent authorities for 10 years from placing on the market or putting into service2 August 2026 residual, except Article 113(c) cases on 2 August 2027.Article 18 of 2024/1689. Legal requirement, only if it applies. The evidence-retention-checklist guide on this site is that page.10 September 2026
If Article 49 applies, register in the EU database referred to in Article 71 before placing on the market or putting into service2 August 2026 residual, except Article 113(c) cases on 2 August 2027.Articles 49 and 71 of 2024/1689 and Annex VIII. Legal requirement, only if it applies. This product does not register in the EU database.10 September 2026
Have a serious-incident path that can report to the market-surveillance authorities of the Member States where the incident occurred, within the Article 73 outer caps2 August 2026 residual under Article 113, because Article 73 sits in Chapter IX.Articles 3(49) and 73 of 2024/1689. Legal requirement, only if it applies. This page does not start a clock. The AI-incident-reporting guide on this site is that page.10 September 2026
For Annex I product-embedded high-risk systems, plan against the later date rather than the general one2 August 2027 — Article 113(c) keeps Article 6(1) and the corresponding obligations there.Articles 6(1) and 113(c) of 2024/1689. Legal requirement, only if it applies. This page does not invent a 2 August 2026 date for Annex I.10 September 2026

Legal requirement versus guidance versus ShipReady recommendation

The table below labels each text. Do not treat a readiness score as conformity, do not treat a standard as the article, and do not treat a product surface as a determination. Last verified 10 September 2026. Not legal advice.

Statute versus standard versus guidance versus product (not a ranking; not legal advice; last verified 10 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/1689, Articles 2 to 55 and 71 to 73Legal requirements — scope, roles, prohibitions, high-risk requirements, GPAI duties, transparency, registration, and serious-incident reporting, each only if it applies.Does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk.
Regulation (EU) 2024/1689 Article 113Legal requirement of the application dates. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; residual 2 August 2026; Article 113(c) Article 6(1) and corresponding obligations 2 August 2027.Does not collapse those into one deadline and does not invent a 2 August 2026 date for Annex I.
ISO/IEC 42001:2023Best practice / standard. An AI management system standard that can operationalise much of the list above. Not a legal substitute for the Act.Does not treat an ISO 42001 certificate as CE marking, as an Article 43 conformity assessment, or as discharging any article.
NIST AI RMF 1.0 (NIST AI 100-1, January 2023)Guidance, not law. Voluntary US agency framework.Does not treat a Govern, Map, Measure or Manage activity as an AI Act duty.
European Commission AI Act pages and AI Office readiness materialsCommission materials. Guidance, not the regulation, however useful.Does not treat a Commission readiness page as rewriting an article or a date.
This product's readiness surfacesShipReady recommendation: an obligation map of frameworks the organisation marked in-scope, an AI inventory, an AI risk register, and collected evidence. Not a legal determination.Readiness is not compliance. Marking eu_ai_act in-scope is not applicability. Does not file with the AI Office, does not register in the EU database, does not issue certifications, and does not affix CE marks.

What to do now

As of last verification on 10 September 2026, Chapters I and II have applied since 2 February 2025 under Article 113(a); Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 since 2 August 2025 under Article 113(b), except Article 101; the residual second paragraph applied the rest from 2 August 2026; and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. The list below is operational preparation. It is not a determination that any of it binds YOU. Walk it with counsel.

  • Start with the two rows that are already years old rather than the newest ones: the Article 5 prohibitions and Article 4 AI literacy both date from 2 February 2025 under Article 113(a).
  • Build the inventory before the policies. Every other row on this page is answered per system, and a policy written without knowing which systems exist is a document, not a control.
  • Ask counsel the scope questions in one sitting and write down the answers with their reasoning — including the negative ones. A documented not-in-scope conclusion is the cheapest artefact on this page and the one most often missing.
  • Separate the two log numbers and the two GPAI dates in whatever you circulate internally: 10 years for the Article 18 documentation, at least six months for Article 19 and Article 26(6) logs; 2 August 2025 for Chapter V, 2 August 2026 for the residual.
  • The AI-audit-evidence guide on this site is the evidence-request-by-role page. The how-shipreadymetrics-supports-ai-governance guide on this site is the honest product map. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Checklist

This is a question list, not a compliance verdict, and not a filing. Walk it with counsel. The requirements-in-force-2026 guide on this site is the Article 113 dates page.

  • Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
  • Have the Article 5 prohibitions been checked against what the organisation actually does? Chapter II has applied since 2 February 2025.
  • Is there a written AI literacy measure, and does it cover the people who operate systems on the organisation's behalf? Article 4 has applied since 2 February 2025.
  • Is there one inventory row per AI system, each with a named owner and a declared role?
  • For each system that might be high-risk, does Article 11 documentation exist, and is it current?
  • Who keeps the logs, for how long, and under whose control — Article 19 for providers, Article 26(6) for deployers?
  • Is there a serious-incident path that could actually be executed inside the Article 73 outer caps, if that article applies?
  • If the organisation provides a GPAI model, is the Chapter V work dated from 2 August 2025 rather than 2 August 2026?
  • Does completing this checklist make YOU compliant? No. It is preparation, and it is not a determination that the Act applies to YOU.
  • Document the assessment, including every not-in-scope decision and the reasoning. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.

If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking in-scope is not applicability: marking eu_ai_act in-scope is not a determination that the Act applies to YOU, is not a classification of YOUR systems, and is not auto-filing. A named human still owns the assessment.

This product does not file with the AI Office, does not file with a market-surveillance authority, does not register in the EU database, does not issue certifications, does not affix CE marks, and is not a notified body. It does not start a clock and does not decide any of the scope questions above. The cyber risk register lives under Security and is a different register from the AI risk register. ShipReady Passport is a shareable posture snapshot, not legal conformity.

This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.

Primary sources (last verified 10 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 2, 3, 4, 5, 6, 9 to 15, 16, 17, 18, 19, 25, 26, 49, 50, 51 to 55, 71, 73 and 113 and Annexes I, III, IV and VIII, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. Commission AI Act pages and AI Office readiness materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.

The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a dated readiness map distilled from Regulation (EU) 2024/1689, with ISO/IEC 42001:2023 labelled as a standard and Commission and AI Office materials labelled as guidance, not the regulation. Whether the Act applies to YOU, which role YOU are in, and which obligations bite are legal questions for counsel on your facts. This page does not start a clock and does not file with the AI Office.

Does completing this checklist make us compliant?

No. Working through it is operational preparation. Compliance under Regulation (EU) 2024/1689 depends on which articles apply to YOU, in which role, for which systems — and on what was actually done, not on what a checklist records. This page does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. A named human still owns the assessment.

Is there one EU AI Act deadline?

No. Article 113 of Regulation (EU) 2024/1689 staggers application: Chapters I and II from 2 February 2025 under point (a); Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 from 2 August 2025 under point (b), with the exception of Article 101; the residual second paragraph from 2 August 2026; and Article 6(1) with the corresponding obligations from 2 August 2027 under point (c). Those dates are not one number.

Do Annex I product-embedded high-risk obligations start on 2 August 2026?

No. Article 113(c) of Regulation (EU) 2024/1689 keeps Article 6(1) and the corresponding obligations of the Regulation on 2 August 2027. The general residual application date of 2 August 2026 is not that date. This page does not invent a 2 August 2026 date for Annex I. Last verified 10 September 2026.

Does marking EU AI Act in-scope in ShipReady mean the Act applies to us?

No. The bundled framework key eu_ai_act is a starter subset of controls the organisation can mark in-scope on the obligation map. That mark is a statement the organisation made about itself. It is not an applicability determination, not a classification of your systems, not a conformity determination, and not auto-filing. Counsel applies Articles 2, 3 and 6 to YOUR facts.

Does ShipReady file anything with the AI Office or the EU database?

No. This product does not file with the AI Office, does not file with a market-surveillance authority, and does not register anything in the EU database referred to in Article 71, which the Commission sets up and maintains. It records facts the organisation entered, collects evidence the organisation supplied, and supports a human review over both. It does not issue certifications and does not affix CE marks.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.