AI Governance / Readiness Assessment
EU AI Act readiness assessment
A fixed-scope assessment that tells you exactly where you stand under the EU AI Act: which of your AI systems are in scope, what role you hold for each, which risk class applies, and what to fix before each staged deadline — starting with the transparency obligations that apply from 2 August 2026.
Built for AI product leaders, legal, compliance and DPOs who need a defensible answer, not another framework diagram.
The clock is staged — and the first deadline is now
The AI Act phases in. Two stages already bind; the next lands in weeks, not years.
Prohibited practices & AI literacy
Bans on unacceptable-risk AI and the duty to ensure staff AI literacy already apply.
Transparency obligations (Art. 50)
Chatbots must disclose they are AI; synthetic media and deepfakes must be labelled. If you deploy a customer-facing assistant, this is your deadline.
High-risk AI systems (Annex III)
Full obligations for high-risk uses — HR screening, credit, education, essential services — including risk management, data governance and human oversight.
High-risk in regulated products (Annex I)
AI embedded in machinery, medical devices and other regulated products completes the phase-in.
What the assessment covers
AI system inventory
Every AI system you build, buy or embed — including the assistants inside SaaS tools your teams already use — catalogued with owner, purpose and data touched.
Role classification
Provider, deployer, importer or distributor — your obligations depend on the role, and many organisations hold different roles for different systems.
Risk-class mapping
Each system mapped to prohibited / high-risk / transparency-risk / minimal-risk, with the reasoning recorded so the classification is defensible.
Gap list & remediation roadmap
What the applicable obligations require, what you can already evidence, and a prioritised, owned roadmap to close the difference before the relevant deadline.
What you receive
- AI system inventory (workbook you keep and maintain)
- Role and risk classification per system, with reasoning
- Obligation map against the staged deadlines that apply to you
- Gap analysis with severity and deadline exposure
- Prioritised remediation roadmap with suggested owners
- Board-ready summary of exposure and next steps
Fixed-scope engagement with a quote after the scoping call. Typical completion within 2–4 weeks of scoping.
One inventory, two regimes
If AI touches personal data, GDPR and the AI Act run in parallel — and duplicate programmes waste the evidence you already hold. The assessment reuses your GDPR audit outputs, extends your DPIAs into AI risk assessments where the same system is in scope, and keeps a single inventory feeding both regimes — so your RoPA, DPIA register and AI system inventory tell one consistent story to any regulator who asks.
How it runs
1. Scoping call
Systems, teams and timelines — we agree the assessment boundary and the people we need.
2. Inventory & classification
Structured discovery across product, engineering and operations; each system roled and risk-classed.
3. Gap assessment
Applicable obligations tested against your current documentation, controls and contracts.
4. Roadmap & readout
Prioritised remediation plan, deadline exposure and a board-ready readout — typically within 2–4 weeks of scoping.
Questions, answered
Do we need this if we only use AI tools, rather than build them?
Usually yes. Deployers have their own obligations — transparency towards the people who interact with the AI, human oversight, and input-data responsibility. The assessment tells you which of your tools carry duties and which are genuinely low-risk.
What does the 2 August 2026 deadline actually require?
From that date, people must be told when they are interacting with an AI system (unless it is obvious), and AI-generated or manipulated content — including deepfakes — must be labelled. If you run a customer-facing chatbot or publish synthetic media, those disclosures need to be in place.
Did the 2025 simplification package delay everything?
No. The Digital Omnibus moved the high-risk phases (now 2 December 2027 for Annex III and 2 August 2028 for Annex I products) but the transparency obligations kept their 2 August 2026 date, and prohibitions and AI literacy have applied since 2025. The deadline most SMEs face first did not move.
How does this relate to the GDPR work we have already done?
Closely — and that saves you effort. Your RoPA, DPIAs and vendor register already describe much of what the AI Act asks about. We reuse that evidence: one inventory feeds both regimes, and DPIAs extend naturally into AI risk assessments rather than starting from scratch.
What if the assessment finds high-risk systems?
That is the point of doing it now: the high-risk obligations are the heaviest and the December 2027 deadline is workable if you start with a roadmap — and very tight if you discover the classification late. The roadmap sequences the work so the evidence exists before the date, not after.
How long does it take, and what do you need from us?
A typical scope completes within 2–4 weeks: a scoping call, access to the people who own the systems, and existing documentation where it exists. No system access is required — the assessment works from interviews and documents.
Book an AI Act readiness consultation
Tell us what you build or deploy and we will come back within one business day with a scoped, fixed-fee proposal. No system access required; NDAs welcome.
Prefer email? info@privacycoreservices.com