A practical, non-certifying checklist for inventory, role mapping, risk review, evidence and monitoring.
Discover
Build an inventory with owners, suppliers, intended purposes, deployment regions and affected groups.
- Identify systems and model dependencies
- Map provider and deployer roles
- Record intended and actual uses
Assess
Screen for prohibited practices, high-risk criteria, transparency duties and GPAI model responsibilities. Document open questions and the legal basis for decisions.
- Check Article 5 and Article 6
- Review relevant Annexes
- Set review dates as guidance evolves
Operate
Assign control owners for documentation, oversight, testing, incident handling, training and change management according to applicable duties.
- Retain review evidence
- Track system changes
- Reassess when intended purpose changes
This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.
Read the AI Act ↗European Commission overview ↗