EU AI Act Readiness Check
Ten operating questions drawn from the regulation itself — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
The EU AI Act applies to providers placing AI systems on the EU market and deployers using them in the EU — wherever the provider sits. Obligations are phased: prohibitions and AI literacy first (Feb 2025), general-purpose AI (Aug 2025), high-risk systems from Aug 2026.
1.Inventory: do you know every AI system in use — built, bought, or embedded in the tools you rent — and whether you are its provider or deployer?
Arts. 3, 16, 25–26 — roles and obligations
2.Prohibitions: have all AI uses been screened against the banned practices — social scoring, manipulative techniques, emotion inference at work or school, untargeted facial scraping?
Art. 5 — prohibited AI practices
3.Classification: is the risk class of each AI system documented — including a reasoned high-risk determination against the Annex III use cases?
Art. 6 — classification of AI systems
4.Risk management: for each high-risk system, is there an iterative, documented risk-management system running through the lifecycle?
Art. 9 — risk management
5.Data governance: are the data sets behind high-risk systems governed — relevant, representative, examined for bias — with provenance on record?
Art. 10 — data and data governance
6.Logging: do high-risk systems produce automatic event logs, kept for the required period — at least six months for deployers?
Arts. 12, 26 — logging and record-keeping
7.Human oversight: do high-risk systems run with competent, trained human oversight that can intervene or shut them down?
Art. 14 — human oversight
8.Transparency: do people know when they interact with an AI system — chatbots identified, synthetic content labelled as such?
Art. 50 — transparency obligations
9.General-purpose AI: if you build on foundation models, do you have the provider documentation — and, if you are a provider, the policy and copyright compliance?
Arts. 53–55 — general-purpose AI
10.Literacy and impacts: do staff have AI literacy appropriate to their role — and, if you are a public body or run credit scoring or insurance pricing, a fundamental-rights impact assessment?
Arts. 4, 27 — AI literacy and fundamental-rights impact assessment
EU AI Act readiness
Answer to scoreWhat the score means
80–100% · Low risk
Controls exist and can mostly be shown. Next step: continuous evidence — the system inventory, classifications and logs should read from live state.
40–79% · Medium / High
The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with the prohibited-practices screen and the system inventory — the EU AI Act framework page maps both to operating controls.
The EU AI Act frameworkEvery score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.