# EU AI Act — Discovery checklist for AI teams

_Questions to ask in discovery or sprint planning, to surface the right considerations early.
This is a prompt for your team's own thinking — **not legal advice, and not an assessment or
classification of your product.** For anything that carries legal weight, consult qualified counsel._

## Scope & role
- [ ] Is what we're building an "AI system" as the Act defines it, and does it reach EU users?
- [ ] Are we the provider (we build / put it on the market) or the deployer (we use it)? Could we be both?
- [ ] Do any exemptions plausibly apply (e.g. certain research, purely internal tooling)?

## Risk & rights
- [ ] Does any part touch a prohibited practice (Article 5)?
- [ ] Does it fall under a high-risk use case (Article 6 / Annex III)?
- [ ] Who could be affected if the system is wrong — and how would they notice or push back?
- [ ] What's the worst realistic outcome, and who owns it?

## Design surfaces
- [ ] Where does a human stay in the loop — and can they actually override in time? (Article 14)
- [ ] How do we disclose that this is AI, and surface its confidence and limits? (Articles 50, 13)
- [ ] What do we log, and who can review those decisions afterwards? (Article 12)
- [ ] What evidence would we point to if someone asked us to prove any of the above?

## Timeline
- [ ] Which phase-in dates apply to us (prohibitions Feb 2025; GPAI Aug 2025; most obligations Aug 2026)?
- [ ] Who's tracking new harmonised standards and guidance as they land?

---
Read the official text: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Self-check your risk tier: https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/
