aistack
Book consultation →
← All articles
AI Regulation

AI Act checklist: are you ready? Questions and answers

A quick AI Act readiness test plus answers to the questions companies most often ask us. Made to share and to print.

July 2026·8 min read·Milan Janoštík·
AI ActRegulationGovernance
Editorial infographic: a vertical checklist of rows, several of them completed in green, beside a circular progress ring that fills as more items are ticked.

The third part of the series is the shortest and most practical. It is not for reading front to back, but for going through and ticking off. First test quickly where your company stands with the AI Act, then find answers to the questions companies most often ask us about the regulation. The detailed explanation of each point is in the first two parts.

Quick test: does the AI Act apply to you?

The answer is almost always yes. The AI Act does not only concern companies that build AI. It concerns anyone who uses AI in their company, which means you too, if you have a chatbot, generate content, screen CVs, or let an assistant work over company data. So the question is not whether, but which of your systems fall where, and what you therefore have to do.

The readiness checklist

Go through the points below. The more of them you can tick with a clear conscience, the better placed you are. The points you cannot tick are your to-do list.

AreaYou are ready when you can say yes
InventoryWe have a list of every place AI runs in the company, including tools people switched on themselves
Risk classificationFor each system we know whether it is minimal, limited or high risk
Your roleWe know where we are only a user (deployer) and where we could become a provider
TransparencyWhere AI talks to people or creates content, it is clearly marked
AI literacyThe people working with AI know what it can do, where the limits are, and when to verify output
Human oversightOn sensitive decisions AI prepares the material, but a person approves it
Audit trailWe can trace who asked what, with which data, and what the system answered
Your dataWe know where our data sits while working with AI, and who can access it
OwnerA specific person in the company is accountable for AI and its compliance
The readiness items are ticked off one by one as the progress ring fills

Frequently asked questions

Does the AI Act apply to a small company?

Yes. The AI Act does not distinguish by company size, but by what the AI is used for. A small company with a chatbot has the transparency duty just like a large one. The law does take smaller players into account on fines, though: for small and medium businesses and startups it takes the lower of the two possible amounts, not the higher.

Is anything in force already, or do we have time?

Part of the law applies today. The bans on the riskiest practices and the AI literacy duty have applied since February 2025. The rules for large models, the governance structure and the fines since August 2025. The transparency duty from August 2026. Only high risk is deferred. Anyone waiting for one big deadline has missed that most duties are already running.

We heard the deadlines moved. What does that mean?

In July 2026 the Digital Omnibus package took effect and deferred the duties for high-risk systems. Standalone Annex III systems have until 2 December 2027, and systems embedded in products until 2 August 2028. The other deadlines stayed. The deferral is room to prepare, not a signal to do nothing, because preparing for high risk takes months.

We use Claude over our data. Does that make us compliant?

No, and anyone claiming otherwise is not telling the truth. No single tool makes your company compliant with the AI Act, because compliance is largely about process and people: about classifying systems by risk, about training, about who owns what. What infrastructure built the right way does do is remove most of the technical friction. The audit trail appears on its own, permissions stay under your control, and data stays with you.

The honest answer
You do not buy compliance, you build readiness
The difference is fundamental. Compliance is a state you have to maintain through process and people. Readiness is the foundation it stands on, and that largely sits in the technical architecture. We build that foundation and help you map the rest. A promise of turnkey compliance from one tool is a red flag.

Are we a provider or a deployer?

Almost certainly a deployer, meaning a user. A provider is whoever develops an AI system and places it on the market under their own name. If you take finished tools and use them, you are a deployer and your duties are lighter. Watch out, though: if you re-label someone else’s system with your name, change it substantially, or deploy it for a high-risk purpose, you can become a provider with all of a provider’s duties.

What does high risk actually mean?

High risk means specific uses named in the law, where AI decides things that change people’s lives: hiring and evaluating employees, assessing creditworthiness for a loan, insurance risk, access to essential services, biometrics, critical infrastructure. One line always holds: the moment a system profiles specific individuals, it is high-risk without exception. Ordinary internal tools with no effect on people’s rights do not belong here.

Are we at risk of a fine?

Fines exist and they are high: up to 35 million euro or 7 percent of worldwide turnover for banned practices, less for other breaches. But they are not there to frighten. Supervision aims at real wrongdoing, not at a company that honestly labels AI content and keeps human oversight. The best defence against a fine is demonstrable readiness, not perfection.

Who supervises this in Czechia?

As of 28 July 2026 it is not yet settled. The AI Act applies directly in Czechia, but the accompanying law naming the supervisory authorities is still in parliament awaiting its third reading. The draft names the Czech Telecommunication Office as the main supervisor, the Czech National Bank for the financial sector, and the data-protection office for biometrics. Until the law passes, treat these roles as proposed, not confirmed.

Where should we start?

With the inventory and risk classification. There is no point dealing with oversight or documentation for a system you do not yet know someone in the company is using. Make the list, classify each system by risk, and focus on the handful that fall into transparency or high risk. The whole step-by-step process is in the second part of the series.

Where to start with us
We map where you are and build the foundation
If you do not know where to start, we begin together with the inventory and risk classification. At the end you know which of your systems fall where, what you already have and what you are missing. And the infrastructure that meets the larger part of the technical requirements through how it is built, we can build right away. Write to us; a short call is enough.

This part closes the series. The first part explains the whole AI Act, the second walks through implementation step by step, this one gives the quick test and the answers. If you want to see what readiness would look like specifically in your case, get in touch. We start from where you stand today.