Services / S1 · Locate
EU AI Act Readiness Assessment.
A systematic stocktake: which AI systems do you use or ship, which risk class do they fall into under the EU AI Act, which role do you hold, and which compliance gaps must you close by which deadline? The result is a prioritized roadmap — so you know where you stand and in what order to act.
Who it’s for
You need clarity before you commit budget — or answer a customer.
The Readiness Assessment is the right entry point when the EU AI Act has become real internally — through a board, customers, investors, or your own compliance function — and no one can say with confidence what it means for your live AI initiatives or your European market access.
Company size
Roughly 500–5,000 employees. Enough complexity that several AI systems run in parallel — and lean enough that an assessment in 6–10 weeks is a realistic format.
AI maturity
Between 2 and 15 AI systems in production or advanced development — including generative AI in marketing, HR, or service, and AI products shipped to EU customers. Not a pure “innovation lab” phase.
Decision-makers
General Counsel, compliance and risk leads, AI/Data leads — often on behalf of the executive team. We address the interface where regulation and operational practice meet.
Pain points we address
- Uncertainty over which systems count as “high-risk”
- Unclear whether you’re a provider, deployer, or both
- Fear of fines up to €35M / 7% of global turnover
- No in-house EU AI Act expertise
- EU customers asking AI Act questions in procurement
- No clear view of your own AI portfolio
How it runs
Four phases, transparently planned.
The assessment runs in four distinct phases that build on each other over 6 to 10 weeks. You receive concrete artifacts at the end of each phase — not status updates.
Discovery & system inventory
Structured interviews with stakeholders at three levels: leadership (risk, compliance, AI leads), engineering (data scientists, developers), and the business (system owners). Alongside, a facilitated discovery workshop that makes the whole AI portfolio visible — including the shadow AI in marketing tools and SaaS platforms that’s so often forgotten.
We review existing documentation, data protection impact assessments, and current compliance frameworks. The goal: a complete inventory without blocking your teams with two weeks of workshops.
What you’ll have
- AI system inventory (Excel + Python dashboard)
- Technical architecture overview per system
- Stakeholder and accountability matrix
- Data flow and governance status
Risk classification, role & gap analysis
Each system from the inventory is checked against the Act’s risk categories: prohibited practices (Art. 5), high-risk under Annex III, high-risk under Annex I, GPAI models, and the transparency duties under Art. 50. In parallel we determine your role — provider, deployer, importer, or distributor — per system, since that drives everything downstream.
Then the gap analysis: where does current practice differ from the requirements? Technical documentation, data governance, human oversight, cybersecurity, post-market monitoring — we go through each requirement and flag concrete gaps.
What you’ll have
- Risk classification matrix (interactive dashboard)
- Provider / deployer role determination per system
- Compliance gap analysis per system
- Mapping onto existing GDPR compliance
Strategic roadmap development
In a facilitated prioritization workshop with your leadership team we decide together which gaps get closed when. The order follows regulatory deadlines, business risk, and realistic resourcing — not an abstract ideal world.
The result is a 12- to 24-month implementation roadmap with clear owner assignments, milestones, and budget estimates. Alongside it, a quick-wins guide with measures you can implement in the next 0–3 months.
What you’ll have
- Strategic compliance roadmap (Gantt + narrative)
- Quick-wins implementation guide
- Resource and budget estimates
- Integration strategy with existing systems
Executive handover & toolkit
A 90-minute executive presentation for your board and leadership — concise, decision-oriented, with recommendations clearly highlighted. We prepare the material so your internal compliance function can carry it forward independently.
Alongside, knowledge-transfer sessions with the operational teams: how is the inventory dashboard maintained? Who owns which documentation? What templates exist for future classifications? After Phase D you should be able to keep going on your own — not dependent on us.
What you’ll have
- Executive presentation (slides + live session)
- Implementation toolkit with templates
- Python-based compliance tracking dashboard
- Recommendations for next steps (audit, monitoring)
Investment
Two engagement levels, clearly delineated.
A typical Readiness Assessment runs 6 to 9 weeks. For groups with embedded high-risk AI or in regulated industries, we build the estimate after a structured scoping call.
5–12 AI systems
The typical scope for an organization with mature AI use. Clearly bounded scope, established regulatory requirements, all four phases in 6 to 9 weeks.
from €15,000
Enterprise · custom
Complex engagements
15+ systems, embedded high-risk AI under Annex I, regulated industries (finance, medical, energy), or international group structures. Price and effort after a scoping call.
Custom estimate
Factors
What drives the price.
Four factors scale the effort — they’re the basis of every proposal we build after the scoping call.
AI portfolio size
Number and maturity of AI systems. Each system is classified individually, checked for compliance gaps, and added to the roadmap — effort scales largely linearly with the number of systems.
System complexity
Embedded high-risk AI under Annex I (e.g. in medical devices or machinery) needs much more technical depth than Annex III applications, because product conformity assessment has to be considered alongside.
Industry & sector regulation
Finance, medical, and energy firms must cover sector-specific requirements on top of the AI Act — frameworks like MDR, DORA, or NIS2 quickly multiply the documentation scope.
Reporting & documentation needs
Board updates, CSRD integration, investor documentation, external audit trails: every additional reporting duty meaningfully expands Phase D (the executive handover).
Bundle discounts apply with the Bias Audit (–15%), Workshops (–10%), or a full engagement (–20%). All prices net of VAT. Travel billed as incurred.
To understand the EU AI Act, you first have to understand your own AI portfolio. One doesn’t work without the other.
— Dr. Valentin José Mayr · Founder
Related services
Where it goes after the assessment.
The Readiness Assessment is the foundation. Depending on the result, different next steps make sense — we recommend the next building blocks concretely in the roadmap report.
S2 · Test
AI Ethics Audit
Deep technical review of individual high-risk systems: fairness, explainability, data quality.
from €8,000
S3 · Sustain
Continuous Monitoring
Drift detection and post-market monitoring for production AI systems under Art. 72.
from €6,000 setup
S4 · Understand
Workshops
Build internal capability: Executive Education, Technical Team Training, or Ethics Framework Development.
from €2,000
Let's get specific