Most AI Act gaps are classification gaps. Whether you are a provider or a deployer, and whether a system is high-risk, decides which of these obligations you owe — and both are answered wrongly far more often than any control is failed.
This assessment scores 65 questions across scope, the prohibitions and transparency duties already in force, the GPAI obligations, and the high-risk provider and deployer requirements now landing in 2027 and 2028. It is free, it saves as you go, and you can stop and come back to it.
What this is
The AI Act applies in stages, and the stage you are in decides what you are answerable for today. Prohibitions and AI literacy have applied since 2 February 2025, GPAI model and governance obligations since 2 August 2025, and general application including the Article 50 transparency duties since 2 August 2026. The Annex III high-risk regime was postponed by Regulation (EU) 2026/1744 and now applies from 2 December 2027, with Annex I product-embedded systems from 2 August 2028. This assessment keeps those apart, so an obligation that has not landed yet does not read as a failure today. We have the background elsewhere — the Act explained, provider versus deployer, the risk categories, the current timeline and the documentation checklist. Come here when you want a score.
What it covers
| Area | Questions |
|---|---|
| Scope, roles and inventory | 7 |
| AI literacy — Article 4, in force | 2 |
| Prohibited practices — Article 5, in force | 9 |
| Risk classification — Article 6 and Annexes I and III | 6 |
| Transparency obligations — Article 50, in force | 5 |
| General-purpose AI models — Articles 51–55, in force | 7 |
| High-risk: provider requirements — Articles 9–17 | 10 |
| High-risk: conformity and post-market — Articles 43–73 | 6 |
| Deployer obligations — Articles 26–27 | 8 |
| Governance and enforcement | 5 |
Classify before you score
Almost every wrong answer in an AI Act assessment traces back to a classification nobody made. Two questions decide most of it. Which role do you hold for each system — provider, deployer, importer, distributor — and does anything you have done turn you into a provider? Putting your name on a system, substantially modifying one, or changing the intended purpose of a general-purpose system all do exactly that, and bring the full provider obligations with them.
The second is whether a system is high-risk, which is not a judgement call about how important it feels. It is Annex I product safety legislation, or one of the eight Annex III use cases, with a narrow Article 6(3) derogation that has to be documented and registered to be relied on.
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
Because so much of this framework is dated, read a low score in the high-risk sections as a plan rather than a breach. The sections marked in force are the ones where a low score is a live exposure today.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by obligation area, a prioritised gap list, and the documents from the EU AI Act Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 35 minutes, and longer if you do not yet have an inventory of the AI systems in use. That inventory is the single most useful artefact to come out of this.
What to do with your score
Below 40% — build the inventory and assign roles. Everything else in the Act keys off which systems you have and what you are to each of them.
40–70% — close the obligations already in force before touching the 2027 and 2028 ones. Prohibitions, AI literacy, Article 50 transparency and the GPAI duties are live now.
Above 70% — if you hold high-risk systems, start the quality management system and technical documentation. The delay to December 2027 is time to build conformity, not a reason to stop: it takes many months to produce and evidence.
Frequently asked questions
Is this assessment really free?
Yes. All 65 questions, the breakdown by obligation area and your overall score cost nothing. The $39 report is optional.
Did the high-risk deadline really move?
Yes. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. A lot of commentary online still describes that as a proposal, so check the date on anything you read.
We are outside the EU. Does it apply?
Possibly. The Act reaches providers placing systems on the EU market wherever established, and providers or deployers outside the EU where the output is used in the EU. The scope questions cover this.
Is this the same as ISO 42001?
No. ISO 42001 is a certifiable management system you choose; the AI Act is law you do not. They overlap usefully — a working AI management system carries a lot of the Article 17 quality management requirement — but neither substitutes for the other. There is a separate ISO 42001 assessment if you want both.
Does it cover the GPAI Code of Practice?
It scores the Article 53 and 55 obligations themselves. Signing the Code of Practice is one way to demonstrate compliance with them, not a separate requirement.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.