Like GDPR, the EU AI Act is proven through documentation, not intentions. As a deployer - a company using AI tools rather than building them - your obligations cluster around three articles: AI literacy (Art. 4), deployer duties (Art. 26) and transparency (Art. 50). This checklist turns those into a concrete record-keeping list, and shows where the AI documentation overlaps with your existing GDPR records. For the full background, see the EU AI Act compliance pillar.
- Deployer documentation maps to three articles: 4 (literacy), 26 (deployer duties), 50 (transparency).
- Much of it extends records you already keep for GDPR - don't build a parallel system.
- AI literacy and oversight apply now; the documentation and transparency duties cluster around 2 August 2026.
The Deployer Documentation Checklist
What do I actually need to record?
- AI system inventory - every AI tool in use, its purpose, and the data it processes.
- Risk classification per use case - the class for each use, with the reasoning.
- AI literacy records (Art. 4) - who was trained, on what, and when.
- Human oversight (Art. 26) - how a person stays in control of automated decisions, documented per high-risk use.
- Purpose limitation (Art. 26) - each system used only for its documented purpose.
- DPIA (Art. 35 GDPR) - for high-risk use; supplemented by a FRIA (Art. 27 AI Act) only for public bodies, private providers of public services, and deployers using the system for creditworthiness or life/health insurance risk assessment.
- Transparency measures (Art. 50) - where you disclose AI use (chatbots, AI content, automated decisions).
- Vendor information - what your AI providers supply about their systems.
No item left blank: a gap is a finding, exactly as it is under GDPR.
Deployer Documentation Pack (Art. 4/26/50, DOCX)
Where AI Act and GDPR Documentation Overlap
Do I keep two separate sets of records?
No - and you shouldn't. Most AI use processes personal data, so your AI records extend your GDPR ones. The AI system inventory builds on your ROPA; the DPIA you already run for high-risk processing is supplemented by a FRIA; your AI literacy training combines with GDPR staff training. Keeping them in one workflow avoids the contradictions that two separate systems produce - see integrated GDPR + AI Act compliance.
How Specific Does It Need to Be?
Is a general statement enough?
No - same standard as GDPR. "We oversee our AI" is a placeholder; "a named reviewer checks every AI-screened application before rejection, logged in the ATS" is documentation. The more consequential the use, the more specific the record. An authority asks for evidence, not assurances.
ETHYX builds this deployer documentation from the same workflow as your GDPR records, so the AI and data-protection sides never drift apart - with a certified DPO to sign it off.