See how Trussed maps to EU AI Act in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Compliance Guide

    EU AI Act August 2026 Deadline Checklist for High-Risk Systems

    From 2 August 2026, most Annex III high-risk AI systems must meet the EU AI Act’s core high-risk obligations, including lifecycle risk management, data governance, technical documentation, automatic logging, instructions for use, effective human oversight, and appropriate accuracy, robustness, and cybersecurity. Enterprises should first classify each AI or agent system, confirm whether they act as provider, deployer, or both, then map Articles 9-15 and the required conformity assessment pathway to operational controls, runtime governance, audit evidence, and accountable ownership.

    Direct answer

    From 2 August 2026, most Annex III high-risk AI systems must meet the EU AI Act’s core high-risk obligations, including lifecycle risk management, data governance, technical documentation, automatic logging, instructions for use, effective human oversight, and appropriate accuracy, robustness, and cybersecurity. Enterprises should first classify each AI or agent system, confirm whether they act as provider, deployer, or both, then map Articles 9-15 and the required conformity assessment pathway to operational controls, runtime governance, audit evidence, and accountable ownership.

    What the August 2026 deadline means for high-risk AI systems

    The August 2026 deadline is a practical planning point for enterprises using AI in regulated or operationally sensitive workflows. Most Annex III high-risk AI systems must be ready to show that the required obligations are not only written into policy, but reflected in how the system is designed, operated, monitored, and controlled.

    For AI leaders, the first step is classification. Each AI or agent system should be assessed to determine whether it falls within a high-risk category, and whether the enterprise acts as a provider, deployer, or both. That role determination shapes the required evidence, accountability model, and conformity assessment pathway.

    EU AI Act high-risk system compliance checklist

    Use this checklist to translate the supplied high-risk obligations into an operating model that can be owned, reviewed, and evidenced before deployment.

    • Classify each AI or agent system and confirm whether it falls within an Annex III high-risk use case.
    • Confirm whether the enterprise acts as provider, deployer, or both for each relevant system.
    • Map Articles 9-15 to specific controls, owners, evidence sources, and review cadences.
    • Establish lifecycle risk management that connects documented risks to deployed system behavior.
    • Maintain data governance controls that support the high-risk system’s intended use and compliance record.
    • Prepare technical documentation that reflects the actual system architecture, operation, and governance controls.
    • Enable automatic logging so runtime events can be traced, reviewed, and used as audit evidence.
    • Provide instructions for use that explain how the system should be operated, overseen, and escalated.
    • Define effective human oversight, including practical mechanisms to intervene, restrict, stop, or escalate system actions.
    • Assess and manage accuracy, robustness, and cybersecurity requirements in the context of the system’s use.
    • Map the required conformity assessment pathway to accountable ownership and supporting evidence.
    • Connect runtime governance, monitoring, and audit logging to the compliance record.

    Build the evidence file before the deadline, not after deployment

    High-risk compliance is easier to demonstrate when the evidence file is built as part of the system lifecycle. Documentation, logs, risk decisions, oversight mechanisms, and operational controls should be aligned before the system is placed into production or used in a regulated process.

    A procedure can describe what should happen, but the evidence file should also show what did happen. For AI systems that can act through tools, permissions, and multi-step workflows, this means preserving a traceable record of system actions, policy checks, approvals, escalations, and human interventions.

    Mapping high-risk obligations to operational controls
    EU AI Act focus Operational question Evidence to maintain
    Lifecycle risk management How are risks identified, assessed, mitigated, reviewed, and connected to deployed behavior? Risk register, mitigation decisions, runtime controls, review records, and ownership assignments.
    Data governance How is data governed for the intended use of the high-risk system? Data governance records, quality checks, use constraints, and documentation of relevant decisions.
    Technical documentation Does documentation reflect how the AI or agent system actually operates? Architecture descriptions, system purpose, control mappings, oversight model, and change history.
    Automatic logging Can the enterprise show what the system did and when required checks occurred? Runtime events, system actions, permission usage, tool calls, approvals, escalations, and audit logs.
    Instructions for use Do operators and deployers understand safe and compliant use of the system? Use instructions, operational limits, escalation paths, oversight procedures, and update records.
    Human oversight Can a human intervene effectively before or during a regulated system action? Intervention mechanisms, stop or escalation controls, approval workflows, and evidence of oversight.
    Accuracy, robustness, and cybersecurity Are system performance, resilience, and security governed for the intended operating context? Control records, monitoring outputs, cybersecurity reviews, robustness checks, and remediation history.

    How Articles 9-15 translate into runtime governance controls

    For many enterprises, the hardest gap is between documented policy and runtime enforcement. A procedure may say that a human can intervene, but an AI agent architecture still needs a practical mechanism for stopping an action, restricting tool access, or escalating a decision before it affects a regulated process. The same issue appears in risk management and logging: a risk register is incomplete if production systems cannot show what the AI did, which permissions it used, and whether a required policy check occurred.

    Runtime governance controls help connect the compliance record to the deployed system. For agentic systems, this includes identity for AI agents, least-privilege permissions, tool approval workflows, runtime policy enforcement, monitoring, and audit logging. These controls do not replace the legal requirements, but they make several of the required controls technically demonstrable, especially where the system can take multi-step actions or call external tools.

    1. Classify the system and role

      Determine whether the system is an Annex III high-risk AI system, then confirm whether the enterprise acts as provider, deployer, or both.

    2. Map obligations to controls

      Connect Articles 9-15 and the required conformity assessment pathway to named controls, owners, and evidence sources.

    3. Enforce controls at runtime

      Use runtime governance to restrict tool access, apply least privilege, require approvals, monitor activity, and record relevant events.

    4. Maintain audit evidence

      Keep documentation, logs, oversight records, and policy enforcement evidence aligned with the deployed system over time.

    Runtime governance is not a substitute for legal compliance

    Runtime governance controls do not replace the EU AI Act’s legal requirements. They help make several required controls technically demonstrable, especially where AI agents can take multi-step actions or call external tools.

    Key governance decisions for AI leaders

    AI leaders should make several decisions early, before the compliance program becomes a documentation exercise disconnected from engineering and operations.

    • Which AI and agent systems are in scope for the August 2026 high-risk obligations?
    • Who owns classification, role determination, and conformity assessment planning?
    • How are Articles 9-15 mapped to operational controls rather than only policy statements?
    • Which runtime events, decisions, permissions, tool calls, approvals, and escalations must be logged?
    • How can human oversight be exercised in practice, including stopping an action, restricting access, or escalating a decision?
    • How will documentation stay current when the deployed system, tools, permissions, or workflows change?

    August 2026 readiness at a glance

    Readiness depends on translating high-risk obligations into a working operating model. The deadline, the Article 9-15 obligations, and the enterprise control focus should be reviewed together so teams can connect policy, engineering, runtime governance, and audit evidence.

    Operationalize high-risk AI governance at runtime

    Trussed AI supports runtime governance and security for enterprise AI agents, including policy enforcement, agent identity, permissions, least privilege, tool approval workflows, monitoring, and audit logging.

    Explore Runtime Governance