30 Days Gen AI Risk Trial -Start Now
Skip to main content
Free Template · Regulatory Compliance

AI Regulatory ComplianceTracker

Track compliance across the EU AI Act, NIST AI RMF, ISO 42001, and emerging US and UK AI regulations. Includes requirement mapping, gap analysis, and remediation tracking for your AI governance programme.

Updated July 2026
4 frameworks
EU AI Act, NIST, ISO 42001, US state laws
Dec 2027
EU AI Act Annex III high-risk deadline
35M
max penalty for prohibited AI
Free
to use and customise

Why You Need an AI Regulatory Compliance Tracker

AI regulation has accelerated dramatically since 2024. Organisations now face overlapping compliance obligations across multiple jurisdictions and frameworks, and without a structured tracker, gaps are inevitable.

Dec 2027
EU AI Act high-risk deadline moved to December 2027
The digital omnibus adopted in June 2026 deferred Annex III high-risk obligations to 2 December 2027, and to 2 August 2028 for AI embedded in Annex I products. Article 50 transparency duties still start on 2 August 2026; only the Article 50(2) machine-readable marking duty gets a transition, to 2 December 2026, for generative AI systems already on the market before that date. The work continues.
3 frameworks
Overlapping requirements need unified tracking
EU AI Act, ISO 42001, and NIST AI RMF have overlapping but non-identical requirements. Without a unified tracker, gaps appear between frameworks.
Jan 2026
US state AI laws are now in force
Texas TRAIGA and Illinois HB 3773 took effect on 1 January 2026, California SB 53 is live, and Colorado's rewritten SB 26-189 arrives on 1 January 2027. Organisations with US operations need to map which laws cover which systems.
Audit
Compliance evidence must be maintained over time
Regulators expect evidence of ongoing compliance, not a point-in-time snapshot. A tracker provides the audit trail that demonstrates systematic compliance management.

The Compliance Tracker

Expand each section to view the compliance requirements and assessment framework. Complete the status fields for each requirement to build your gap analysis.

Step 1: Classify Each AI System by Risk Tier

Unacceptable Risk (Prohibited)

Compliance required: 2 Feb 2025 (in force)

Real-time biometric surveillance in public spaces; social scoring by public authorities; exploitation of vulnerabilities of specific groups; subliminal manipulation. The June 2026 omnibus added AI-generated non-consensual intimate imagery and CSAM. These systems must be withdrawn immediately.

High Risk (Annex III)

Compliance required: 2 Dec 2027 (deferred by the June 2026 omnibus)

Employment and HR decisions; education and vocational training; access to essential services (credit, insurance, benefits); law enforcement; migration and asylum; administration of justice. Full obligations apply.

Limited Risk

Compliance required: 2 Aug 2026 (Art. 50(2) marking for systems on the market before then: 2 Dec 2026)

AI systems that interact with natural persons (chatbots); AI that generates or manipulates content (deepfakes, synthetic media). Transparency obligations only, must disclose AI nature.

Minimal Risk

No additional obligations

All other AI systems, spam filters, AI-powered games, recommendation systems not in Annex III contexts. No additional obligations under the EU AI Act beyond existing law.

Key High-Risk AI Obligations (Annex III systems)

Risk Management System (Art. 9)
☐ Not Started ☐ In Progress ☐ Implemented
Data Governance (Art. 10)
☐ Not Started ☐ In Progress ☐ Implemented
Technical Documentation (Art. 11)
☐ Not Started ☐ In Progress ☐ Implemented
Record Keeping / Logging (Art. 12)
☐ Not Started ☐ In Progress ☐ Implemented
Transparency to Users (Art. 13)
☐ Not Started ☐ In Progress ☐ Implemented
Human Oversight (Art. 14)
☐ Not Started ☐ In Progress ☐ Implemented
Accuracy & Robustness (Art. 15)
☐ Not Started ☐ In Progress ☐ Implemented
Fundamental Rights Impact Assessment
☐ Not Started ☐ In Progress ☐ Implemented

How to Implement This Compliance Tracker

Follow these five steps to turn this template into a live compliance tracking programme with regular reporting to your governance committee.

1
Build your AI system register
Before tracking compliance, build a complete inventory of all AI systems you develop, deploy, or procure. Record use case, data inputs, decision type, affected populations, and operating jurisdictions.
2
Classify your AI systems under the EU AI Act
Apply the EU AI Act risk classification to each system: Unacceptable / High Risk (Annex III) / Limited Risk / Minimal Risk. Classify conservatively, if in doubt, treat as High Risk.
3
Map requirements and assess current compliance status
For each applicable regulation and risk tier, map specific requirements to your current controls. Assign a status: Not Started, In Progress, or Implemented. Be honest about gaps.
4
Prioritise gaps and create a remediation roadmap
Prioritise gaps by regulatory enforcement timeline, likelihood of scrutiny, severity of penalty, and remediation feasibility. Create a roadmap with owners, target dates, and resource requirements.
5
Establish monitoring for emerging regulations
Assign a named owner to monitor regulatory developments per jurisdiction. Set a quarterly review cadence to update the tracker and reassess risk classifications as guidance evolves.
FAQ

Frequently Asked Questions

The regulations that apply depend on where your organisation is based, where your customers or affected individuals are located, and what your AI systems do. The EU AI Act applies to any organisation that places an AI system on the EU market or whose AI systems affect individuals in the EU, regardless of where the organisation is incorporated. ISO 42001 is a voluntary standard but increasingly expected by enterprise customers and auditors. NIST AI RMF is voluntary and US-focused but widely adopted globally. US state laws (Colorado, Illinois, Texas, California) apply if you have customers or employees in those states.
Get started

Map your AI tools to regulatory requirements automatically

Aona maps your AI tool usage to EU AI Act, ISO 42001, and NIST AI RMF requirements automatically, identifying gaps, generating evidence, and giving your compliance team real-time visibility into your regulatory posture.