Skip to main content
TOOLS

EU AI Act Readiness Check

Ten operating questions drawn from the regulation itself — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.

The EU AI Act applies to providers placing AI systems on the EU market and deployers using them in the EU — wherever the provider sits. Obligations are phased: prohibitions and AI literacy first (Feb 2025), general-purpose AI (Aug 2025), high-risk systems from Aug 2026.

0/10
  1. 1.Inventory: do you know every AI system in use — built, bought, or embedded in the tools you rent — and whether you are its provider or deployer?

    Arts. 3, 16, 25–26 — roles and obligations

  2. 2.Prohibitions: have all AI uses been screened against the banned practices — social scoring, manipulative techniques, emotion inference at work or school, untargeted facial scraping?

    Art. 5 — prohibited AI practices

  3. 3.Classification: is the risk class of each AI system documented — including a reasoned high-risk determination against the Annex III use cases?

    Art. 6 — classification of AI systems

  4. 4.Risk management: for each high-risk system, is there an iterative, documented risk-management system running through the lifecycle?

    Art. 9 — risk management

  5. 5.Data governance: are the data sets behind high-risk systems governed — relevant, representative, examined for bias — with provenance on record?

    Art. 10 — data and data governance

  6. 6.Logging: do high-risk systems produce automatic event logs, kept for the required period — at least six months for deployers?

    Arts. 12, 26 — logging and record-keeping

  7. 7.Human oversight: do high-risk systems run with competent, trained human oversight that can intervene or shut them down?

    Art. 14 — human oversight

  8. 8.Transparency: do people know when they interact with an AI system — chatbots identified, synthetic content labelled as such?

    Art. 50 — transparency obligations

  9. 9.General-purpose AI: if you build on foundation models, do you have the provider documentation — and, if you are a provider, the policy and copyright compliance?

    Arts. 53–55 — general-purpose AI

  10. 10.Literacy and impacts: do staff have AI literacy appropriate to their role — and, if you are a public body or run credit scoring or insurance pricing, a fundamental-rights impact assessment?

    Arts. 4, 27 — AI literacy and fundamental-rights impact assessment

0%

EU AI Act readiness

Answer to score

What the score means

80–100% · Low risk

Controls exist and can mostly be shown. Next step: continuous evidence — the system inventory, classifications and logs should read from live state.

40–79% · Medium / High

The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.

0–39% · Critical

Start with the prohibited-practices screen and the system inventory — the EU AI Act framework page maps both to operating controls.

The EU AI Act framework

Every score

Bring it to a demo — walked through against your actual obligations, not generic advice.

Book a demo

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

Frequently Asked Questions

Who does the EU AI Act apply to?
Providers placing AI systems on the EU market and deployers using them in the EU — wherever the provider sits. Most companies are deployers: the obligations cover the AI built into the tools you rent, not only systems you trained.
When do the obligations bite?
Prohibited practices and AI literacy from February 2025; general-purpose AI obligations from August 2025; most high-risk system requirements from August 2026, with a year more for AI embedded in regulated products. The phased calendar is on the framework page.
What counts as a high-risk AI system?
High-risk is defined by use case — Annex III lists areas like employment decisions, credit scoring, education, essential services and biometrics — plus safety components of regulated products under Annex I. The classification must be documented per system, and that reasoning is what the check scores.
Is the score an official EU AI Act assessment?
No. It is an indicative maturity score from ten questions drawn from the regulation — not an assessment of record. Market surveillance authorities judge compliance against the full regulation; the check tells you where the gaps are.