June 14, 2026 Regulation

EU AI Act Checklist: Infrastructure Requirements for High-Risk AI Systems

By Thorsten Litzki · Litzki Systems LLC

tl;dr

Key findings

  • •  High-risk AI under Annex III is subject to binding infrastructure requirements — not just documentation obligations.
  • •  Art. 50 is the core technical obligation: transparency and provenance must be demonstrable; the machine-readable marking requirement (para. 2) applies only to providers of generative AI systems.
  • •  The Conformity Assessment Dossier (Art. 43) needs concrete evidence — not general statements.
  • •  Infrastructure evidence such as CERTavia can be integrated directly into the CAD dossier.

Step 1: Am I affected? — Annex III check

The EU AI Act distinguishes between general-purpose AI systems and high-risk AI. High-risk AI is exhaustively defined in Annex III (DE). Before you work through the infrastructure checklist, make sure your system is actually affected.

Typical Annex III categories:

  • Biometric systems (identification, categorization, emotion recognition)
  • AI in critical infrastructure (energy, water, transport)
  • AI in education (assessment, admission)
  • AI in employment and workforce management (screening, evaluation)
  • AI for essential private and public services (credit, insurance)
  • AI in law enforcement and migration control
  • AI in the administration of justice

Not sure whether you're affected? The CERTavia quick test (DE) helps with the assessment.

Step 2: Checklist Art. 9 — Risk management system

Art. 9 requires a documented risk management system spanning the AI system's entire lifecycle.

Risk identification and analysis for all known and foreseeable risks
Risk management measures documented and implemented
Residual risks assessed and accepted or mitigated
Risk management system continuously updated (post-market monitoring)

Step 3: Checklist Art. 50 — Transparency, marking, provenance

Art. 50 is the critical technical requirement. Here are concrete infrastructure checkpoints:

Infrastructure cybersecurity

TLS 1.2 or 1.3 on all production endpoints — no outdated protocol versions
Strong cipher suites (ECDHE, AES-GCM) — no RC4, DES, 3DES
DNSSEC enabled and fully validated for all relevant domains
HTTP security headers implemented: HSTS, CSP, X-Frame-Options, Referrer-Policy
Email security: SPF, DKIM, DMARC with an enforcement policy (reject or quarantine)

Robustness and availability

Failover and redundancy concept documented
Backup plans in place for critical AI components
Evidence of infrastructure state available for a defined reference date

The CERTavia scan checks all technical parameters from the cybersecurity checklist automatically and delivers cryptographically signed evidence.

Step 4: Checklist Art. 17 — Quality management system

QMS documentation created and kept up to date
Data governance processes defined (training, validation, test data)
Change management for AI models and infrastructure documented
Post-market monitoring system established

Step 5: Checklist Art. 43 — Conformity Assessment Dossier

The Conformity Assessment Dossier (CAD) (DE) under Art. 43 is the formal evidence submitted to market surveillance authorities. It must contain concrete evidence — not general statements.

System description and intended purpose of the AI system
Technical documentation (architecture, data, methods)
Risk management system documentation (Art. 9)
Infrastructure evidence under Art. 50 — cryptographically signed and verifiable
Transparency documentation for users (Art. 13)
EU declaration of conformity (Art. 47)

Timeline: what applies from when?

The EU AI Act has been in force since August 2024. The transparency obligations under Art. 50 apply from August 2, 2026. The transition period for high-risk AI under Annex III was postponed via the AI Omnibus (finally adopted by the Council on June 29, 2026) to December 2, 2027 (Annex I to August 2, 2028). From the respective date, systems must be demonstrably compliant before being placed on the EU market or put into service.

Important: this means infrastructure must be demonstrably compliant by a reference date before the respective regulatory deadline. Retroactive evidence will be harder to establish.

Next steps

Once you've worked through this checklist, you have an overview of your compliance status. The technical infrastructure evidence under Art. 50 is often the gap that can be closed fastest — because it's automated and available in 90 seconds.

Get started with the free CERTavia scan and receive your CERTIFIED/FAILED verdict instantly, with a full cluster report.

Infrastructure evidence

Infrastructure evidence for your CAD dossier

Cryptographically signed, machine-readable, in 90 seconds — directly integrable into your conformity assessment process.