World Model Readiness
Engraved governance instrument

For your company

Governance & Compliance

Module · Deadlines are not a strategy

The EU AI Act Compliance Check

The AI Act regulates use cases, not tools, and its duties arrive in stages through 2027. This module checks the five load-bearing pieces: risk classification, high-risk duties, the literacy obligation, your provider-versus-deployer roles, and whether anyone owns the work.

Question 1 of 5 · Use cases classified

Have you classified your AI use cases into the AI Act's risk classes?

The Act regulates use cases, not tools. The same model can be minimal risk in marketing and high risk in hiring. Without the classification, every other duty is unscoped.

Question 2 of 5 · High-risk duties implemented

For your high-risk use cases, are the documentation and oversight duties actually implemented?

High-risk means technical documentation, risk management, human oversight, logging and accuracy monitoring. Identified is not implemented; auditors read evidence, not intentions.

Question 3 of 5 · AI literacy trained

Have the people who operate and oversee AI systems been trained for it?

Article 4 makes AI literacy a duty, not a nice-to-have, and it already applies. Generic e-learning does not cover role-specific oversight duties.

Question 4 of 5 · Provider vs deployer mapped

Do you know, per use case, whether you are the provider or the deployer?

The duties differ sharply by role, and you can be both at once: deployer of a bought tool, provider of what you build on top. Contracts decide who carries what.

Question 5 of 5 · Compliance has an owner

Does AI Act compliance have a named owner with budget and authority?

Deadlines are staged through 2027, but the duties are cumulative and evidence takes quarters to build. A committee without budget is a way of saying no slowly.

For the statistics · one click each

Three questions for the public picture

These do not affect your score. They feed the anonymised, aggregated statistics; groups under 8 respondents are never shown.

What is the highest AI Act risk class in use in your company today?

High risk
Limited risk
Minimal risk
We do not know

Do you know which AI Act deadlines apply to you?

No
Roughly
Yes, precisely
Our advisors track it

Is there a dedicated budget for AI Act compliance?

None
Under 50k EUR
50k to 250k EUR
Over 250k EUR
Not disclosed

Your context

Used to calibrate the report. Company size and sector remain in the anonymized dataset; your email does not.

What the five levels look like

Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.

Use cases classified

  1. 1Not started
  2. 2Know the classes
  3. 3Partially classified
  4. 4Fully classified
  5. 5Classified + process

At the low end: Without classification you cannot know what the law requires of you. A one-day workshop over your AI inventory gets you to a first map. What good looks like: A living classification with a process for new use cases is exactly what the Act assumes. Keep it wired into procurement and deployment reviews.

High-risk duties implemented

  1. 1None
  2. 2Duties identified
  3. 3Implementation planned
  4. 4Partially implemented
  5. 5Fully implemented

At the low end: If a high-risk use case runs live without its duties, you accumulate liability daily. Either implement, or switch the use case off until you can. What good looks like: Full implementation puts you ahead of most of the market. Turn it into an asset: audited AI is a sales argument with enterprise customers.

AI literacy trained

  1. 1No training
  2. 2Ad hoc self-study
  3. 3Training planned
  4. 4Rolled out broadly
  5. 5Role-specific, refreshed

At the low end: The literacy duty already applies. A pragmatic start: one half-day for everyone, one deeper track for people with oversight roles. What good looks like: Role-specific, refreshed training is the standard the Act imagines. Keep records; literacy is the duty auditors can check fastest.

Provider vs deployer mapped

  1. 1Never considered
  2. 2Unsure for most
  3. 3Partially mapped
  4. 4Fully mapped
  5. 5Mapped + contracts

At the low end: Role confusion means you either over-comply at cost or under-comply at risk. Map your top five use cases first; the pattern usually repeats. What good looks like: Mapped roles with adjusted contracts is the mature end state. Revisit on every new AI purchase; vendors love shifting duties downstream.

Compliance has an owner

  1. 1Nobody owns it
  2. 2Legal, ad hoc
  3. 3Named, no budget
  4. 4Named with budget
  5. 5Integrated system

At the low end: Unowned compliance work does not happen; it accumulates. Name one person this quarter, even at 20 percent of their time, with the classification from question 1 as their mandate. What good looks like: Integrated ownership turns the Act from a project into an operating property. Your job now is keeping evidence fresh, not building from zero.