// ai act checklist
AI Act checklist
for AI teams.
Two questions and you have your list. Tick what you already have, the browser remembers it, and take it away as a PDF whenever you want.
// how to use it
Two questions and you have your list.
Block E, the evidence folder, is for everyone. And block F is what you get to cross off your worries.
What you tick is saved in this browser only. Nothing is sent anywhere.
// block a · in force since february 2025
What you should already have.
// block b · before 2 august 2026
Transparency (art. 50).
// block c · if you build with ai
Your own product or process.
// block d · your provider
The questions to ask.
- Do you store prompts and responses? Yes or no. "Your data is safe" is not an answer.
- If you do, for how long, what for, and can I turn it off?
- Where is it physically processed and stored, and under which jurisdiction does the provider sit? An EU datacenter belonging to a company subject to the Cloud Act is not the same as a European provider.
- Is my data used to train models? Where does the contract say so?
- Do you have a DPA ready to sign, a list of sub-processors and architecture documentation on request?
- What model documentation can you give me for my own traceability? Version, model card, changelog of model changes.
- Does your analytics work without my content? The most revealing question: if they need your content to operate, their incentive is to retain it.
// block e · for everyone
The evidence folder.
Your first AI Act exam probably will not come from a regulator: it will come from a large client at a renewal, a tender or a due diligence. Keep a folder with this in it.
// block f · breathe
What you get to cross off your worries.
- You do not need any mandatory certification. There is no "AI Act seal" to buy. Be wary of anyone selling you one.
- The high-risk obligations are postponed. To December 2027 and August 2028, and they only apply if your use falls in the Annex III areas. Most enterprise uses do not.
- The general-purpose model obligations are not yours. They belong to whoever develops the model: OpenAI, Alibaba, Z.ai. Using models, open or closed, through an API or on your own infrastructure, does not transfer them to you.
- GDPR is neither replaced nor duplicated. If you already comply, most of the data work is done. The AI Act adds the layer about using AI, it does not redo the data layer.
- Nothing has to stop on 2 August. For the AI-user profile, what is required is light (blocks A and B) and takes days, not months.
Need open-model AI on European infrastructure?
That is what we run: open-weight models on EU GPUs, zero logs, European company. If you want to go through your specific case, write to us.
talk_to_us →This is general information, not legal advice. Sources: Regulation (EU) 2024/1689, the Commission GPAI guidelines (July 2025) and the AI Office FAQ.
helmcode.com · Printed on
// get started
START BURNING TOKENS
Skip the AI infra work. Deploy your first private inference endpoint today.
Flat rate. EU data. OpenAI API compatible.