Self-survey

EU AI Act readiness self-survey

Twelve quick checks across the four foundations of the EU AI Act: knowing your AI, ruling out prohibited practices, meeting the high-risk obligations, and being transparent about interactions and synthetic content. Prohibited-practice bans applied from 2 February 2025; the bulk of the Act kicks in on 2 August 2026.

About 8 minutes

Where should we send the result?
1 Scope and inventory Know what AI you have and in what role you use it.

Do you maintain an inventory of every AI system your organisation develops, deploys, or uses?

For each AI system, do you know whether you act as provider, deployer, importer, or distributor?

Have staff who operate or use AI systems received AI-literacy training appropriate to their role?

2 Prohibited practices Rule out the outright bans in Art. 5.

Are you confident none of your AI systems use subliminal, manipulative, or deceptive techniques likely to cause significant harm?

Are you confident none of your AI systems perform general-purpose social scoring, workplace emotion recognition, or untargeted facial scraping?

Have you screened use cases in law enforcement, biometric identification, or vulnerability targeting against the Art. 5 prohibitions?

3 High-risk obligations For any AI system classified as high-risk under Art. 6 + Annex III.

Have you classified each AI system against Annex I (product-safety route) and Annex III (use-case route)?

For your high-risk systems, do you have a documented, iterative risk-management system (Art. 9) plus Annex-IV-compliant technical documentation (Art. 11)?

Do your high-risk systems generate automatic logs (Art. 12) and provide effective human oversight controls (Art. 14)?

Are you ready to complete the Art. 43 conformity assessment and register each system in the EU database before placing it on the market?

4 Transparency and GPAI Applies regardless of risk classification – chatbots, synthetic content, deep-fakes, and general-purpose AI.

Do AI systems that interact with people disclose that they are AI, and is AI-generated content marked in a machine-readable way?

If you provide a general-purpose AI model, do you publish a training-data summary, a copyright policy, and downstream documentation for integrators?

We email the result to you. Nothing is shared without consent.