Services / S1 · Locate

EU AI Act Readiness Assessment.

A systematic stocktake: which AI systems do you use or ship, which risk class do they fall into under the EU AI Act, which role do you hold, and which compliance gaps must you close by which deadline? The result is a prioritized roadmap — so you know where you stand and in what order to act.

Investment

from €15,000

Duration

6–10 weeks

Effort

120–200 hours

Who it’s for

You need clarity before you commit budget — or answer a customer.

The Readiness Assessment is the right entry point when the EU AI Act has become real internally — through a board, customers, investors, or your own compliance function — and no one can say with confidence what it means for your live AI initiatives or your European market access.

01

Company size

Roughly 500–5,000 employees. Enough complexity that several AI systems run in parallel — and lean enough that an assessment in 6–10 weeks is a realistic format.

02

AI maturity

Between 2 and 15 AI systems in production or advanced development — including generative AI in marketing, HR, or service, and AI products shipped to EU customers. Not a pure “innovation lab” phase.

03

Decision-makers

General Counsel, compliance and risk leads, AI/Data leads — often on behalf of the executive team. We address the interface where regulation and operational practice meet.

Pain points we address

  • Uncertainty over which systems count as “high-risk”
  • Unclear whether you’re a provider, deployer, or both
  • Fear of fines up to €35M / 7% of global turnover
  • No in-house EU AI Act expertise
  • EU customers asking AI Act questions in procurement
  • No clear view of your own AI portfolio

How it runs

Four phases, transparently planned.

The assessment runs in four distinct phases that build on each other over 6 to 10 weeks. You receive concrete artifacts at the end of each phase — not status updates.

A

Weeks 1–2 · 40–50 h

Discovery & system inventory

Structured interviews with stakeholders at three levels: leadership (risk, compliance, AI leads), engineering (data scientists, developers), and the business (system owners). Alongside, a facilitated discovery workshop that makes the whole AI portfolio visible — including the shadow AI in marketing tools and SaaS platforms that’s so often forgotten.

We review existing documentation, data protection impact assessments, and current compliance frameworks. The goal: a complete inventory without blocking your teams with two weeks of workshops.

What you’ll have

  • AI system inventory (Excel + Python dashboard)
  • Technical architecture overview per system
  • Stakeholder and accountability matrix
  • Data flow and governance status

B

Weeks 3–5 · 50–70 h

Risk classification, role & gap analysis

Each system from the inventory is checked against the Act’s risk categories: prohibited practices (Art. 5), high-risk under Annex III, high-risk under Annex I, GPAI models, and the transparency duties under Art. 50. In parallel we determine your role — provider, deployer, importer, or distributor — per system, since that drives everything downstream.

Then the gap analysis: where does current practice differ from the requirements? Technical documentation, data governance, human oversight, cybersecurity, post-market monitoring — we go through each requirement and flag concrete gaps.

What you’ll have

  • Risk classification matrix (interactive dashboard)
  • Provider / deployer role determination per system
  • Compliance gap analysis per system
  • Mapping onto existing GDPR compliance

C

Weeks 6–8 · 30–50 h

Strategic roadmap development

In a facilitated prioritization workshop with your leadership team we decide together which gaps get closed when. The order follows regulatory deadlines, business risk, and realistic resourcing — not an abstract ideal world.

The result is a 12- to 24-month implementation roadmap with clear owner assignments, milestones, and budget estimates. Alongside it, a quick-wins guide with measures you can implement in the next 0–3 months.

What you’ll have

  • Strategic compliance roadmap (Gantt + narrative)
  • Quick-wins implementation guide
  • Resource and budget estimates
  • Integration strategy with existing systems

D

Weeks 9–10 · 20–30 h

Executive handover & toolkit

A 90-minute executive presentation for your board and leadership — concise, decision-oriented, with recommendations clearly highlighted. We prepare the material so your internal compliance function can carry it forward independently.

Alongside, knowledge-transfer sessions with the operational teams: how is the inventory dashboard maintained? Who owns which documentation? What templates exist for future classifications? After Phase D you should be able to keep going on your own — not dependent on us.

What you’ll have

  • Executive presentation (slides + live session)
  • Implementation toolkit with templates
  • Python-based compliance tracking dashboard
  • Recommendations for next steps (audit, monitoring)

Investment

Two engagement levels, clearly delineated.

A typical Readiness Assessment runs 6 to 9 weeks. For groups with embedded high-risk AI or in regulated industries, we build the estimate after a structured scoping call.

Enterprise · custom

Complex engagements

15+ systems, embedded high-risk AI under Annex I, regulated industries (finance, medical, energy), or international group structures. Price and effort after a scoping call.

Custom estimate

200+ hours · 10+ weeks

Factors

What drives the price.

Four factors scale the effort — they’re the basis of every proposal we build after the scoping call.

01

AI portfolio size

Number and maturity of AI systems. Each system is classified individually, checked for compliance gaps, and added to the roadmap — effort scales largely linearly with the number of systems.

02

System complexity

Embedded high-risk AI under Annex I (e.g. in medical devices or machinery) needs much more technical depth than Annex III applications, because product conformity assessment has to be considered alongside.

03

Industry & sector regulation

Finance, medical, and energy firms must cover sector-specific requirements on top of the AI Act — frameworks like MDR, DORA, or NIS2 quickly multiply the documentation scope.

04

Reporting & documentation needs

Board updates, CSRD integration, investor documentation, external audit trails: every additional reporting duty meaningfully expands Phase D (the executive handover).

Bundle discounts apply with the Bias Audit (–15%), Workshops (–10%), or a full engagement (–20%). All prices net of VAT. Travel billed as incurred.

To understand the EU AI Act, you first have to understand your own AI portfolio. One doesn’t work without the other.

— Dr. Valentin José Mayr · Founder

Related services

Where it goes after the assessment.

The Readiness Assessment is the foundation. Depending on the result, different next steps make sense — we recommend the next building blocks concretely in the roadmap report.

S2 · Test

AI Ethics Audit

Deep technical review of individual high-risk systems: fairness, explainability, data quality.

from €8,000

Learn more →

S3 · Sustain

Continuous Monitoring

Drift detection and post-market monitoring for production AI systems under Art. 72.

from €6,000 setup

Learn more →

S4 · Understand

Workshops

Build internal capability: Executive Education, Technical Team Training, or Ethics Framework Development.

from €2,000

Learn more →

Let's get specific

In 30 minutes, we’ll determine whether the Readiness Assessment is the right starting point for you.