EU AI Act Readiness Self-Assessment

Free interactive assessment. Eight questions returning your EU AI Act role, risk classification, the obligations that attach and the current deadlines.

Most EU AI Act readiness material asks whether you have a policy. This asks what your system does, and returns the classification, the obligations that attach to it, and the dates those obligations attach on. It takes about three minutes and runs entirely in your browser — nothing you enter is transmitted or stored.

One thing worth knowing before you start, because a great deal of published guidance has not caught up with it. The high-risk deadlines moved. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and amended the application dates in Article 113. Obligations for Annex III high-risk systems moved from 2 August 2026 to 2 December 2027. Obligations for Annex I high-risk systems moved from 2 August 2027 to 2 August 2028. The 2 February 2025 and 2 August 2025 dates were not changed, and 2 August 2026 remains the general application date, including for the Article 50 transparency obligations.

What the assessment covers

Eight questions, in the order the Regulation itself works through them.

Your role. Provider, deployer, importer or distributor. The obligations differ sharply, and buying a system does not always make you a deployer — substantially modifying a high-risk system, or placing one on the market under your own name, makes you a provider.

Territorial reach. Scope is not limited to organizations established in the EU. It extends to providers placing systems on the Union market, and to non-EU providers and deployers where the output produced by the system is used in the Union.

Article 5 prohibited practices. Eight categories, prohibited since 2 February 2025, carrying the highest penalty tier. Two further prohibitions were added by the 2026 amendment and apply from 2 December 2026.

General-purpose AI models. Whether you develop or substantially fine-tune one, and whether cumulative training compute exceeds the 1025 floating point operation threshold at which Article 51(2) presumes high impact capabilities.

High-risk classification. Both routes — Annex I, where the AI is a safety component of a product already covered by Union harmonisation legislation, and Annex III, the eight listed areas: biometrics; critical infrastructure; education and vocational training; employment and workers' management; access to essential private and public services; law enforcement; migration, asylum and border control; and the administration of justice and democratic processes.

The Article 6(3) filter. An Annex III system can fall outside the high-risk classification where it does not pose a significant risk of harm, including by not materially influencing the outcome of decision-making. Four conditions can support that, but a system performing profiling of natural persons is always high-risk and cannot use the route. Relying on it is not self-certifying: Article 6(4) requires you to document the assessment, and Article 49 requires registration anyway.

Article 50 transparency. Direct interaction with people, synthetic content generation, emotion recognition and biometric categorisation, and deepfakes. These attach independently of risk classification.

The assessment

EU AI Act readiness self-assessment

Eight questions. Returns your likely role, risk classification, the obligations that attach, and the dates they attach on — under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Nothing is sent anywhere; this runs entirely in your browser.

Why most of this turns into an evidence problem

Read the provider and deployer obligations together and a pattern appears. Article 12 wants automatic logging of events over the system's lifetime. Article 26(6) wants the deployer to retain those logs for at least six months. Article 14 wants human oversight that is effective rather than nominal. Article 73 wants serious incidents reported on a clock that starts when you become aware of one.

Each of those is a claim about what happened at the moment a system acted, and claims of that kind can only be produced by something that was present at that moment. A quarterly attestation cycle and a spreadsheet inventory produce claims about what the organization intended. That distinction is the subject of runtime governance, and it is why tamper-evident audit logs are an architecture decision rather than a retention setting.

The practical test for any tool positioned as AI Act readiness is narrow: when a policy is violated, does it stop the action, or does it record that the action occurred. Both are useful. Only one of them produces the evidence the Regulation asks for.

EU AI Act solution · AI supervision evidence checklist · Board reporting · ISO/IEC 42001 · Human-in-the-loop · Glossary

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs