Skip to content

AI Governance / Readiness Assessment

EU AI Act readiness assessment

A fixed-scope assessment that tells you exactly where you stand under the EU AI Act: which of your AI systems are in scope, what role you hold for each, which risk class applies, and what to fix before each staged deadline — starting with the transparency obligations that apply from 2 August 2026.

Built for AI product leaders, legal, compliance and DPOs who need a defensible answer, not another framework diagram.

The clock is staged — and the first deadline is now

The AI Act phases in. Two stages already bind; the next lands in weeks, not years.

In force now

Prohibited practices & AI literacy

Bans on unacceptable-risk AI and the duty to ensure staff AI literacy already apply.

2 August 2026

Transparency obligations (Art. 50)

Chatbots must disclose they are AI; synthetic media and deepfakes must be labelled. If you deploy a customer-facing assistant, this is your deadline.

2 December 2027

High-risk AI systems (Annex III)

Full obligations for high-risk uses — HR screening, credit, education, essential services — including risk management, data governance and human oversight.

2 August 2028

High-risk in regulated products (Annex I)

AI embedded in machinery, medical devices and other regulated products completes the phase-in.

What the assessment covers

AI system inventory

Every AI system you build, buy or embed — including the assistants inside SaaS tools your teams already use — catalogued with owner, purpose and data touched.

Role classification

Provider, deployer, importer or distributor — your obligations depend on the role, and many organisations hold different roles for different systems.

Risk-class mapping

Each system mapped to prohibited / high-risk / transparency-risk / minimal-risk, with the reasoning recorded so the classification is defensible.

Gap list & remediation roadmap

What the applicable obligations require, what you can already evidence, and a prioritised, owned roadmap to close the difference before the relevant deadline.

What you receive

  • AI system inventory (workbook you keep and maintain)
  • Role and risk classification per system, with reasoning
  • Obligation map against the staged deadlines that apply to you
  • Gap analysis with severity and deadline exposure
  • Prioritised remediation roadmap with suggested owners
  • Board-ready summary of exposure and next steps

Fixed-scope engagement with a quote after the scoping call. Typical completion within 2–4 weeks of scoping.

One inventory, two regimes

If AI touches personal data, GDPR and the AI Act run in parallel — and duplicate programmes waste the evidence you already hold. The assessment reuses your GDPR audit outputs, extends your DPIAs into AI risk assessments where the same system is in scope, and keeps a single inventory feeding both regimes — so your RoPA, DPIA register and AI system inventory tell one consistent story to any regulator who asks.

How it runs

1. Scoping call

Systems, teams and timelines — we agree the assessment boundary and the people we need.

2. Inventory & classification

Structured discovery across product, engineering and operations; each system roled and risk-classed.

3. Gap assessment

Applicable obligations tested against your current documentation, controls and contracts.

4. Roadmap & readout

Prioritised remediation plan, deadline exposure and a board-ready readout — typically within 2–4 weeks of scoping.

Questions, answered

Do we need this if we only use AI tools, rather than build them?

Usually yes. Deployers have their own obligations — transparency towards the people who interact with the AI, human oversight, and input-data responsibility. The assessment tells you which of your tools carry duties and which are genuinely low-risk.

What does the 2 August 2026 deadline actually require?

From that date, people must be told when they are interacting with an AI system (unless it is obvious), and AI-generated or manipulated content — including deepfakes — must be labelled. If you run a customer-facing chatbot or publish synthetic media, those disclosures need to be in place.

Did the 2025 simplification package delay everything?

No. The Digital Omnibus moved the high-risk phases (now 2 December 2027 for Annex III and 2 August 2028 for Annex I products) but the transparency obligations kept their 2 August 2026 date, and prohibitions and AI literacy have applied since 2025. The deadline most SMEs face first did not move.

How does this relate to the GDPR work we have already done?

Closely — and that saves you effort. Your RoPA, DPIAs and vendor register already describe much of what the AI Act asks about. We reuse that evidence: one inventory feeds both regimes, and DPIAs extend naturally into AI risk assessments rather than starting from scratch.

What if the assessment finds high-risk systems?

That is the point of doing it now: the high-risk obligations are the heaviest and the December 2027 deadline is workable if you start with a roadmap — and very tight if you discover the classification late. The roadmap sequences the work so the evidence exists before the date, not after.

How long does it take, and what do you need from us?

A typical scope completes within 2–4 weeks: a scoping call, access to the people who own the systems, and existing documentation where it exists. No system access is required — the assessment works from interviews and documents.

Book an AI Act readiness consultation

Tell us what you build or deploy and we will come back within one business day with a scoped, fixed-fee proposal. No system access required; NDAs welcome.

Prefer email? info@privacycoreservices.com

We typically respond within one business day.

We use the information you provide to respond to your enquiry, assess the service requested and manage follow-up. Please do not include passwords, special-category data or confidential client records. See our Privacy Notice.

Reviewed by Zuzana Ruddock, Certified DPO and EU General Data Protection Regulation Practitioner (certified by the International Board for IT Governance Qualifications). Last reviewed: 11 July 2026. This page is general information, not legal advice.