5 signs your company isn't AI Act ready

None of these require a lawyer to spot. If two or more apply, you have a real gap, not a theoretical one.

  • You can't list every AI system in use. Not just the ones IT deployed — the CV-screening tool marketing signed up for, the chatbot on the website, the model embedded in a vendor's SaaS product. If there's no inventory, there's no way to know your exposure.
  • No system has been risk-classified. The AI Act's obligations scale with risk tier. Without classification, you don't know whether you're looking at a light transparency duty or the full high-risk documentation package.
  • No one is named as responsible for human oversight. Article 26(2) requires deployers to assign oversight to someone with "the necessary competence, training and authority" — a policy that names no one satisfies nothing.
  • Nobody has training records for AI literacy. Article 4 requires it, and "we're a tech company, everyone understands AI" is not documentation.
  • You've never checked whether an AI system also needs a data protection impact assessment. Most consequential AI systems process personal data, which pulls in GDPR obligations most teams don't connect back to their AI project.

What a real maturity assessment actually checks

A useful assessment doesn't ask how you feel about compliance — it checks specific, auditable facts across the frameworks that actually apply to a company using or building AI in the EU market:

DomainWhat it checks
AI ActSystem inventory, risk classification per system, human oversight assignment, technical documentation for high-risk systems, incident reporting process.
Data GovernanceWhether training and operational data has an owner, a quality process, and a documented lineage.
GDPRLegal basis for processing personal data through AI systems, and whether a DPIA has been run where required.
ISO/IEC 42001Whether an AI management system exists at all, even informally, with assigned roles per Clause 5.3.
NIS2Whether AI systems that touch critical services or infrastructure fall under separate security obligations.

A score with no breakdown by domain isn't useful — you need to know which of these five areas is dragging the average down, because that's where the next 90 days of work should go.

What it costs to skip this

Article 99 of the AI Act sets three penalty tiers: up to €35 million or 7% of global annual turnover for prohibited practices under Article 5; up to €15 million or 3% for non-compliance with provider, deployer or transparency obligations; and up to €7.5 million or 1% for supplying incorrect or misleading information to authorities. SMEs are fined the lower of the euro figure or the percentage, not both.

In practice, most companies never reach a fine — they lose a deal because a customer's procurement team asked for evidence of AI governance and got silence instead. A documented assessment is often what unblocks that conversation.

Do this first: before buying any tool or template, run the free 12-question assessment — it takes 5 to 12 minutes and tells you exactly which of the five domains above needs attention first, at no cost.

After the diagnostic: what to do with the gaps

The assessment's real value is the priority order it gives you, not the score itself. A company scoring low on "governance structure" should read the AI Governance Responsibilities RACI before anything else — most other gaps trace back to nobody being named as owner. A company scoring low on risk classification specifically should go straight to how to classify AI systems by risk.

Frequently asked questions

How do I know if my company needs to comply with the AI Act?

If you develop, sell, or use AI systems that affect people located in the EU — regardless of where your company is headquartered — the AI Act applies to you. That includes something as ordinary as a CV-screening tool, a chatbot, or a credit-scoring model.

What happens if I don't run any kind of assessment?

Nothing happens immediately — but you're operating blind. Article 99 sets fines up to €35M or 7% of global turnover for prohibited practices, up to €15M or 3% for other obligations, and up to €7.5M or 1% for supplying incorrect information to authorities. An assessment is what tells you which tier, if any, applies to you.

Is a free online diagnostic actually useful, or just a lead magnet?

It depends on what it measures. A useful one checks specific, auditable things — do you have a system inventory, has each system been risk-classified, is there a named human-oversight owner, do you have training records — rather than asking vague opinion questions. That's the difference between a real gap analysis and a marketing quiz.

How long does a maturity assessment take?

A useful self-assessment across AI Act, Data Governance, GDPR and ISO 42001 basics takes 5 to 12 minutes if you already know your AI footprint. If you don't know your AI footprint, that itself is the first gap the assessment will surface.