EU AI Act Readiness
The EU AI Act applies in phases: prohibited practices and AI literacy from 2 February 2025, general-purpose AI obligations from 2 August 2025, most high-risk system obligations from 2 August 2026, with some categories later, and a Commission proposal to adjust the high-risk timeline under review. A readiness assessment has to say which version of the law, which date and which obligation it is talking about.
This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice, a conformity assessment, or a determination of an AI system's legal classification, which should be confirmed with qualified counsel.
The companies this problem finds first.
Companies placing AI systems on the EU market or whose outputs are used in the EU
Providers and deployers of systems in Annex III areas: employment, credit, education, essential services, biometrics, critical infrastructure
General-purpose AI model providers and companies building on them
Non-EU companies with EU users
The moments that turn this from a someday into a now.
- Customer asks for AI Act role and risk classification
- Launch of an AI feature affecting EU individuals
- Procurement questionnaire with AI Act questions
- Board or regulator question about high-risk exposure
- Approaching obligation date
11 areas, one control library.
Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.
Role determination: provider, deployer, importer, distributor
Prohibited-practice screening
Risk classification: high-risk, limited-risk transparency, minimal
General-purpose AI model obligations
Risk management system and data governance
Technical documentation and record-keeping
Transparency and human oversight
Accuracy, robustness and cybersecurity
Quality management and conformity assessment
Post-market monitoring and incident reporting
AI literacy
Deliverables you can hand to a buyer, a board or a regulator.
- Date- and version-aware applicability position per AI system: legal source, effective date, obligation date, applicability date, assessment version, for counsel review
- AI system register with role and risk classification
- Obligation-by-obligation readiness with evidence
- Technical documentation gap list
- Obligation calendar
- Remediation roadmap
The sources every control cites.
Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.
- EU AI Act (Regulation (EU) 2024/1689)
- ISO/IEC 42001:2023 (AI Management System)
- NIST AI Risk Management Framework (AI RMF 1.0)
- General Data Protection Regulation (Regulation (EU) 2016/679)
What each executive gets out of it.
CEO
Know which obligations reach which products, and when, before customers and regulators ask.
CFO
Programme scoped by actual risk classification rather than a blanket reading of the Act.
CTO / engineering
Technical documentation, logging and oversight requirements translated into engineering work.
General counsel
Every applicability position dated, versioned and sourced, with change triggers recorded.
CISO / security lead
AI Act cybersecurity and robustness obligations mapped onto existing AI security controls.
Integrated capabilities, not a separate programme.
Engagement tiers
AI Governance · Compliance · Continuous Assurance. Tiers describe depth and cadence; there is no per-regulation price.
Usually bought by
General counsel, Chief product officer, CTO / engineering, CISO / security lead, CEO
Part of these packages
AI Company · EU Expansion
The objections, answered directly.
The Act reaches providers and deployers whose systems or outputs are used in the EU, regardless of where the company sits.
Which is why every position here is dated and versioned against a named legal source and re-evaluated when the source changes, rather than assumed.
Start with the free check.
Free check: a short, scored indicator of where you stand and the evidence that would close each gap. A consultant follows up to scope the full readiness engagement.