Toolkit · Compliance · about 5 minutes

EU AI Act Readiness Check

Obligations under the AI Act depend on what a system does rather than what sector you are in, and most software lands in transparency rather than high-risk. This starts with classification, because spending on high-risk controls before classifying is the most expensive mistake in this area.

23 questions. Nothing is sent anywhere as you answer, the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.

0 of 23 answered0%

Classification

What you are, and what your systems are. Everything else follows from this.

Have you inventoried every AI system you provide or deploy, including AI embedded in tools you bought rather than built?

Most inventories miss AI inside HR platforms, support tooling and analytics products.

Have you confirmed that none of your systems performs a prohibited practice?

Social scoring, exploiting vulnerabilities of specific groups, certain biometric categorisation, and untargeted scraping of facial images. No documentation makes these lawful.

Have you classified each system against the risk tiers, rather than assuming?

For each system, do you know whether you are the provider or the deployer?

Fine-tuning, rebranding or substantially changing the intended purpose can make you the provider of a new system, which carries the heavier obligations.

High-risk obligations

Only if a system is high-risk. If none are, this section does not apply to you.

Is there human oversight designed in, such that a person can genuinely intervene rather than nominally supervise?

Is there a risk management system running across the lifecycle rather than a one-off assessment?

Is training, validation and testing data governed, including examination for bias and gaps that could produce discriminatory outcomes?

Does the system log its operation automatically, with records retained?

Is there technical documentation sufficient for an authority to assess conformity?

Have accuracy, robustness and cybersecurity been assessed against the intended purpose and documented?

Transparency

Cheap to meet, expensive to be caught missing. Applies well below the high-risk tier.

Are users told when they are interacting with an AI system rather than a person?

Is synthetic content marked as artificially generated in a machine-readable way?

Are deepfakes and manipulated media disclosed as such?

Do deployers receive instructions for use covering capabilities, limitations and intended purpose?

General-purpose models

Only if you train or substantially modify a general-purpose model.

Do you maintain technical documentation and information for downstream providers building on the model?

Is there a policy for complying with EU copyright law, including reservation of rights?

Can you publish a sufficiently detailed summary of the content used for training?

This applies whether or not the training data was publicly available.

If the model may present systemic risk, do you perform model evaluation, adversarial testing and incident reporting?

Governance and conformity

The management scaffolding, which is where ISO 42001 does most of its work.

For any high-risk system, has a conformity assessment been completed before placing it on the market?

Is there a quality management system covering AI development and deployment?

Are AI roles and accountabilities assigned, with someone owning this at management level?

Are AI suppliers assessed, including what obligations they carry and what flows to you?

Is there a process for reporting serious incidents involving an AI system?

More in the toolkit