On February 2, 2025, the first five articles of the EU AI Act took effect. If your organization operates in Europe or deploys AI systems used by European entities, you're now subject to enforcement. Articles 4 and 5 establish baseline obligations: AI literacy requirements and prohibited practices. This checklist helps you verify whether you've met these initial compliance requirements.
Prerequisites
Before working through this checklist, confirm:
- Scope determination complete: You've documented which of your operations fall under EU AI Act jurisdiction (providers or deployers of AI systems in Europe).
- Executive sponsorship secured: Leadership has committed resources to AI governance.
- Cross-functional team identified: You have representatives from Legal, IT Security, Privacy, HR, and relevant business units available.
Checklist Items
1. Inventory all AI systems in use across the organization
What to do: Document every AI system your employees use, whether officially sanctioned or shadow IT. Include generative AI tools, decision-support systems, and automated processing tools.
Requirement: Article 4 prerequisite.
Good looks like: A living register that captures system name, vendor, business purpose, user groups, and data processed. Update monthly. If an employee downloaded a new AI app last week, you know about it this week.
2. Establish an AI governance board or equivalent oversight mechanism
What to do: Create a cross-functional body where First Line operating functions meet with Second Line risk management (Compliance, Privacy, Legal, IT Security) to set AI usage rules.
Requirement: Article 4 governance prerequisite.
Good looks like: Regular meetings, documented decisions, clear escalation paths. The board reviews new AI use-cases before deployment and revisits existing systems when risks change. You have meeting minutes that show actual debate, not rubber-stamping.
3. Define AI literacy requirements for each role category
What to do: Based on Article 4's requirement for "sufficient level of AI literacy," specify what different employee groups need to understand. Developers need deeper technical knowledge than end-users.
Requirement: Article 4.
Good looks like: Written competency frameworks that account for "technical knowledge, experience, education and training and the context the AI systems are to be used in." A customer service rep using an AI chatbot needs different literacy than a data scientist building models. Each framework includes measurable learning objectives.
4. Implement AI literacy training programs
What to do: Deliver training that covers AI opportunities, risks, and potential harms specific to your organization's use-cases.
Requirement: Article 4.
Good looks like: Role-based training with completion tracking. Content addresses your actual AI systems, not generic "what is AI" modules. Training includes scenarios relevant to employees' daily work. You can produce completion records showing who was trained, when, and on what topics.
5. Document prohibited AI practices you will not adopt
What to do: Review Article 5's prohibited practices and create explicit policies forbidding them. Key prohibitions include subliminal manipulation, crime prediction based solely on profiling, and emotion inference in workplace/education settings (except medical/safety uses).
Requirement: Article 5.
Good looks like: A clear policy document that lists prohibited uses in plain language. Each prohibition includes examples of what would violate it. The policy is distributed to all employees who procure, develop, or deploy AI systems.
6. Screen existing AI systems against Article 5 prohibitions
What to do: Audit your current AI inventory to verify none violate Article 5.
Requirement: Article 5.
Good looks like: Documented review of each system in your inventory with a clear pass/fail determination. If you find a system that deploys manipulative techniques or predicts criminal behavior through profiling, you have a remediation plan with timeline. Your legal team has signed off on the analysis.
7. Build third-party AI risk into vendor management
What to do: Update vendor due diligence and contract management to address AI risks. Contractors and business partners may use prohibited AI practices on your behalf.
Requirement: Article 5.
Good looks like: Vendor questionnaires ask specifically about AI use. Contracts include representations that vendors won't use prohibited AI practices when providing services to you. You have a process to monitor ongoing vendor AI adoption, not just a one-time assessment at contract signing.
8. Create an AI use-case approval workflow
What to do: Before any new AI system goes live, require a structured review that checks literacy requirements and prohibited practices.
Requirement: Articles 4 and 5.
Good looks like: A documented process that can't be bypassed. The workflow includes checkpoints for AI literacy assessment and Article 5 compliance. Approvals are traceable, and rejections come with written rationale.
9. Establish monitoring for shadow AI adoption
What to do: Implement technical and procedural controls to detect when employees adopt AI tools without approval.
Requirement: Article 4.
Good looks like: Network monitoring flags unknown AI services. Regular surveys ask employees what tools they're using. Your IT Security team reviews SaaS adoption quarterly. When you find shadow AI, you have a process to evaluate it rather than simply blocking it.
10. Document your approach to AI ethics and tone at the top
What to do: Capture senior management's commitment to ethical AI use in writing. Make it clear that speed of adoption doesn't trump responsible deployment.
Requirement: Article 4.
Good looks like: A statement from the CEO or Board that sets expectations. It acknowledges uncertainty about some AI risks while committing to careful adoption. This statement is referenced in training materials and reinforced in town halls. Employees can articulate the company's AI principles without looking them up.
Common Mistakes
Treating AI literacy as a one-time training event: Article 4 requires ongoing literacy as AI systems and risks evolve. Your training program needs regular updates, not an annual refresh.
Assuming technical teams don't need literacy training: Developers and data scientists need training too, focused on regulatory obligations and ethical considerations they may not encounter in technical documentation.
Ignoring white-label AI in third-party services: Your CRM vendor may have embedded AI features you don't realize you're using. Third-party due diligence must explicitly ask about AI capabilities.
Waiting for "high-risk" AI requirements before acting: Articles 4 and 5 apply now, regardless of risk tier. The literacy and prohibition requirements aren't contingent on later classification work.
Writing policies without enforcement mechanisms: A prohibition on manipulative AI means nothing if you can't detect violations or don't act when you find them.
Next Steps
The EU AI Act will introduce tiered risk requirements for different AI use-cases. Your compliance program will need processes to assess AI risks and implement proportionate controls. Start building that muscle now:
- Develop a risk assessment methodology for AI systems.
- Map your existing risk management framework to AI-specific concerns.
- Identify gaps between current capabilities and what tiered oversight will require.
Articles 4 and 5 are just the beginning. If you can't demonstrate AI literacy and prohibit the most egregious practices, you won't be ready for the more sophisticated requirements coming next.




