Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

EU AI Act Requirements: A Practical Checklist

The EU AI Act requires providers and deployers of high-risk AI systems to complete a risk management system, data governance review, technical documentation, human oversight design, and conformity assessment before the system reaches an EU market, with obligations phasing in between February 2025 and August 2027. Below is a practical, checklist-style breakdown of what actually needs to get done, in the order most compliance teams tackle it.

Who the EU AI Act Actually Applies To

The Act applies to any organization that places an AI system on the EU market or whose AI system's output is used in the EU, regardless of where the company is headquartered. That means a SaaS company in Toronto or Waterloo selling into European enterprise accounts is in scope the moment its product touches an EU user, even without an EU office. Canadian tech companies expanding into Europe often discover this obligation only after a prospect's procurement team asks for it during due diligence, which is too late to start from zero.

Three roles carry distinct duties: providers (who build or substantially modify the system), deployers (who use it under their own authority), and importers or distributors. Most Canadian SaaS vendors are providers. If you also use third-party AI internally for hiring, credit decisions, or fraud detection, you may simultaneously be a deployer with a separate set of obligations.

Step One: Classify Your AI System's Risk Tier

Everything downstream depends on this classification, so it belongs first on the checklist.

  • Unacceptable risk: social scoring, manipulative or subliminal techniques, and most real-time biometric identification in public spaces are banned outright as of February 2025.
  • High-risk: systems used in employment, credit scoring, insurance underwriting, education admissions, critical infrastructure, law enforcement, and medical devices carry the full obligation set described below.
  • Limited risk: chatbots, deepfake generators, and emotion-recognition tools mainly require transparency, telling the user they are interacting with AI.
  • Minimal risk: spam filters, recommendation engines, and most internal productivity tools have no new obligations.

Get this classification wrong and you either over-invest in controls a minimal-risk tool doesn't need, or under-invest and miss a conformity assessment a high-risk system requires. This is exactly the gap our EU AI Act readiness engagement starts by closing, before any documentation work begins.

Core Checklist for High-Risk AI Systems

If your classification lands in the high-risk tier, the Act requires the following, in roughly the order auditors expect to see them built.

1. Risk Management System

A documented, continuous process that identifies, evaluates, and mitigates risks across the AI system's lifecycle, not a one-time assessment filed away after launch.

2. Data Governance and Quality

Training, validation, and testing datasets must be relevant, representative, and checked for bias. You need to document data provenance and be able to explain why a dataset is fit for the system's intended purpose.

3. Technical Documentation

A file (the Act's Annex IV documentation) covering the system's design, capabilities, limitations, and performance metrics. This is the artifact regulators and enterprise customers will ask to see first.

4. Record-Keeping and Logging

Automatic logging of events throughout the system's operation, retained long enough to allow traceability and post-incident investigation.

5. Transparency to Deployers

Clear instructions for use, so the organization deploying your AI understands its capabilities, limitations, and appropriate human oversight measures.

6. Human Oversight

Design controls that let a human intervene, override, or halt the system's output. This can't be bolted on after the fact, it needs to be part of the system architecture.

7. Accuracy, Robustness, and Cybersecurity

Testing that demonstrates the system performs consistently and resists adversarial manipulation, tampering, and unauthorized access.

8. Conformity Assessment and CE Marking

Before market placement, high-risk systems must pass a conformity assessment, either self-assessed against harmonized standards or reviewed by a notified body, and carry the CE marking.

9. Registration in the EU Database

Most high-risk systems must be registered in the publicly accessible EU database before deployment.

10. Post-Market Monitoring

An ongoing plan to track performance in production and report serious incidents to the relevant authority.

The Compliance Timeline You Need to Plan Against

  • February 2025: prohibitions on unacceptable-risk practices and AI literacy obligations took effect.
  • August 2025: governance rules and obligations for general-purpose AI model providers began applying.
  • August 2026: the bulk of high-risk system obligations become enforceable, including the checklist items above.
  • August 2027: obligations extend to high-risk AI embedded in already-regulated products, such as medical devices and machinery.

Twelve months sounds like runway, but conformity assessment, documentation, and human oversight redesign are not fast work when they're layered on top of an existing product roadmap. Teams that start scoping now avoid a compressed rebuild in mid-2026.

Why This Matters for Canadian Companies Specifically

Canadian obligations don't disappear because the EU AI Act exists, they stack. PIPEDA still governs personal data handling nationally, Quebec's Law 25 imposes its own automated decision-making disclosure requirements for Quebec residents, and CPCSC readiness is increasingly a procurement gate for federal and enterprise Canadian buyers. A company selling AI-driven products from Ottawa or Montreal into both the EU and Canadian public sector needs a control set that satisfies all three regimes without building three separate programs. We map this overlap directly for clients pursuing both EU market access and Canadian frameworks like CPCSC Level 1, so evidence gets reused rather than duplicated.

Vancouver and Calgary AI startups selling into European insurance and fintech buyers face a similar pattern: the deal doesn't close until legal or procurement sees evidence of AI Act readiness, not just a promise to comply later. Building the documentation trail before it's requested, rather than scrambling during a due diligence deadline, is the difference between a smooth close and a stalled one.

Common Mistakes That Slow Down Readiness

  • Treating the risk classification as a one-time exercise instead of revisiting it every time the system's use case expands.
  • Writing technical documentation after the system ships instead of building it alongside development, which turns a documentation task into an archaeology project.
  • Assuming a SOC 2 report covers AI-specific obligations. It doesn't, human oversight design and conformity assessment fall outside a typical SOC 2 scope.
  • Underestimating how long conformity assessment takes when a notified body review is required rather than self-assessment.

Getting Started

The fastest path is a scoping call that classifies your system's risk tier, maps what you already have against the checklist above, and flags the gaps that need the most lead time before August 2026. Traztech runs this as part of its EU AI Act readiness service, working alongside Canadian tech companies from Toronto to Vancouver that need to satisfy European regulators without losing months to a compliance program built from scratch. If your AI system also touches employment, credit, or fraud decisions, it's worth reviewing alongside our broader ISO 42001 readiness work, since the two frameworks share significant control overlap.

If you're not sure which tier your AI system falls into, or you know it's high-risk and need a realistic timeline to August 2026, get in touch and we'll walk through where you stand.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation