AI Regulatory Compliance
Tracker
Track compliance across the EU AI Act, NIST AI RMF, ISO 42001, and emerging US and UK AI regulations. Includes requirement mapping, gap analysis, and remediation tracking for your AI governance programme.
Why You Need an AI Regulatory Compliance Tracker
AI regulation has accelerated dramatically since 2024. Organisations now face overlapping compliance obligations across multiple jurisdictions and frameworks, and without a structured tracker, gaps are inevitable.
The Compliance Tracker
Expand each section to view the compliance requirements and assessment framework. Complete the status fields for each requirement to build your gap analysis.
Step 1: Classify Each AI System by Risk Tier
Unacceptable Risk (Prohibited)
Compliance required: 2 Feb 2025 (in force)Real-time biometric surveillance in public spaces; social scoring by public authorities; exploitation of vulnerabilities of specific groups; subliminal manipulation. The June 2026 omnibus added AI-generated non-consensual intimate imagery and CSAM. These systems must be withdrawn immediately.
High Risk (Annex III)
Compliance required: 2 Dec 2027 (deferred by the June 2026 omnibus)Employment and HR decisions; education and vocational training; access to essential services (credit, insurance, benefits); law enforcement; migration and asylum; administration of justice. Full obligations apply.
Limited Risk
Compliance required: 2 Aug 2026 (Art. 50(2) marking for systems on the market before then: 2 Dec 2026)AI systems that interact with natural persons (chatbots); AI that generates or manipulates content (deepfakes, synthetic media). Transparency obligations only, must disclose AI nature.
Minimal Risk
No additional obligationsAll other AI systems, spam filters, AI-powered games, recommendation systems not in Annex III contexts. No additional obligations under the EU AI Act beyond existing law.
Key High-Risk AI Obligations (Annex III systems)
How to Implement This Compliance Tracker
Follow these five steps to turn this template into a live compliance tracking programme with regular reporting to your governance committee.
FAQ
Frequently Asked Questions
Which AI regulations apply to my organisation?
What is the EU AI Act compliance deadline?
How does ISO 42001 relate to the EU AI Act?
What are the penalties for EU AI Act non-compliance?
Map your AI tools to regulatory requirements automatically
Aona maps your AI tool usage to EU AI Act, ISO 42001, and NIST AI RMF requirements automatically, identifying gaps, generating evidence, and giving your compliance team real-time visibility into your regulatory posture.