Non-legal readiness assessment

EU AI Act Readiness Checker

Identify possible obligation areas, unresolved classification questions, evidence gaps, control weaknesses, and prioritised actions for an AI system or use case.

This tool does not declare legal compliance. Results depend on the information supplied and should be validated by appropriate legal, risk, technical, and operational specialists.
AI governance readiness illustrationA shield, checklist, and connected controls representing AI Act readiness.

How it works

Complete one assessment for a defined AI system, model, product, or use case. Use a cross-functional group where possible.

1. Describe the context

Record operator role, territorial connection, purpose, affected people, decision impact, risk hypothesis, and GPAI involvement.

2. Assess control evidence

Rate governance, oversight, documentation, logging, data, resilience, monitoring, incidents, literacy, and accountability.

3. Review and act

Use the score, confidence notice, classification questions, evidence gaps, and prioritised actions to plan specialist review and remediation.

Readiness assessment

Required fields are marked with an asterisk. Avoid entering personal, confidential, or sensitive information.

Organisation and scope

Use a neutral project identifier if confidentiality is a concern.

Role or team is sufficient.

Select the role for this specific system or model.

Select Uncertain where specialist review is needed.

20–180 characters. Example: “Ranks job applicants for recruiter review using CV and assessment data.”

Choose the highest reasonably foreseeable impact.

Classification indicators

Review exact legal conditions and exceptions.

Use Uncertain unless a documented classification review supports the selection.

Governance and evidence readiness

“Documented and operating” means the control has an owner, approved procedure, retained evidence, and is used in practice.

Governed record of systems, models, owners, purposes, roles, data, users, geography, risk, status, and evidence.

Named accountable roles, decision rights, supply-chain duties, approvals, and escalation.

Role-based competence and training for people operating or overseeing AI systems.

Assessment of AI interaction notices, generated-content marking, deepfake labelling, and related disclosures.

Competent people can understand limitations, intervene, override, stop, and escalate.

Data provenance, relevance, quality, representativeness, bias controls, access, and issue handling.

Controlled evidence of design, purpose, versions, limitations, tests, metrics, risks, and changes.

Appropriate event logs, retention, integrity, access controls, review, and retrievability.

Defined metrics, thresholds, resilience, security, adversarial testing, and release criteria.

Production monitoring, drift and harm signals, feedback, corrective actions, and reporting.

Severity criteria, response, evidence preservation, notification decisions, root cause, and remediation.

Affected groups, impacts, safeguards, residual risk, consultation, and approval where relevant.

Notes and confirmation

Up to 500 characters. Do not enter personal, confidential, or sensitive information.

The server processes the submitted form to generate the result. No external API is used. Browser exports are generated locally. Storage depends on the site’s existing hosting and logging configuration.

Methodology, limitations, and appropriate use

Designed for early readiness planning, workshops, procurement review, and evidence-gap prioritisation.

Transparent scoring

Twelve control areas receive equal weight. Classification uncertainty and prohibited-practice indicators reduce the score because strong controls cannot compensate for unresolved scope questions.

Important limitations

The tool does not apply every definition, exception, annex, standard, code, guidance document, national rule, sector law, or contractual requirement. Legal classification may require specialist review.

Use the result well

Validate classification first, assign accountable owners, define evidence acceptance criteria, track remediation, and reassess after material design, vendor, data, purpose, or deployment changes.

Continue from readiness screening into governance design, accountability, vendor assurance, and implementation planning.

Frequently asked questions

Practical guidance for using the assessment responsibly.

Is this checker legal advice?

No. It is a structured readiness and issue-spotting tool. Legal classification can depend on detailed facts, definitions, exclusions, exceptions, guidance, standards, and regulatory interpretation.

Does a high score mean the organisation is compliant?

No. A high score indicates stronger documented-control readiness and fewer stated uncertainties. It does not prove that controls operate effectively, the system is correctly classified, or every legal requirement has been addressed.

Who should complete the assessment?

Use a cross-functional group including the AI-system owner, operations, legal or compliance, privacy, security, data governance, procurement, model risk, internal audit, and affected business functions.

Can the EU AI Act apply to organisations outside the EU?

Potentially. Territorial scope can reach certain providers and deployers outside the EU when a system is placed on the EU market, put into service in the EU, or its output is used in the EU.

How should prohibited-practice indicators be assessed?

Review the exact statutory conditions, affected persons, purpose, method, context, exceptions, and applicable date. Where an indicator may be present, restrict the relevant use and obtain qualified review.

What makes an AI system high-risk?

Potential routes include certain safety components or products covered by specified product legislation and certain listed use cases. Intended purpose and significance of risk can also matter.

What changes when general-purpose AI is involved?

Responsibilities depend on whether the organisation consumes, integrates, modifies, or provides the GPAI model and whether systemic-risk rules may apply.

What evidence should be retained?

Evidence may include inventories, purpose statements, role and scope decisions, risk records, data governance records, technical documentation, logs, testing, oversight procedures, training, monitoring, incidents, supplier evidence, approvals, and corrective actions.

How often should the assessment be repeated?

Repeat it before procurement or deployment, at major release gates, after material changes, after serious incidents, and periodically during production monitoring.

How should “not applicable” be used?

Use it only where a documented classification or scope analysis explains why the control does not apply.

What does the confidence level mean?

Confidence reflects how many scope, role, classification, GPAI, prohibited-practice, and control selections remain uncertain or not assessed. It is not a statistical confidence interval.

Does the tool transmit data externally?

No external API or library is used. The submitted form is processed by the site server, while CSV and JSON files are created in the browser. Hosting logs or deliberate server-side storage may still process request data.