AI Act readiness audit

The technical side, not the legal one. We establish which AI systems you actually run, what has to be documented and built so compliance can be evidenced — and which of it applies already.

What applies today, and what is still to come

The Digital Omnibus, in force since 27 July 2026, deferred the obligations for high-risk systems. That is the change that made the headlines — and the one most often read as meaning nothing need be done until 2027. The deferral covers only one part of the regulation.

DateWhat it covers
in force2 February 2025Prohibited practices (Article 5) and the AI literacy duty (Article 4).
in force2 August 2025Obligations for general-purpose AI (GPAI) model providers, governance rules and penalties.
in force2 August 2026Transparency obligations (Article 50): telling people they are interacting with AI, and marking generated content. Systems already in service have until 2 December 2026 for machine-readable marking.
from2 December 2027Annex III high-risk systems — moved from 2 August 2026 by the Digital Omnibus. This is the change that got the coverage.
from2 August 2028High-risk systems embedded in regulated products (Annex I) — moved from 2 August 2027.

Verified 19 August 2026. This area moves quickly — two of the dates above were deferred after the regulation came into force. Confirm them with your own lawyer before making decisions on them.

"Deferred" is not the same as "nothing to do"

Three groups of obligations apply regardless of the deferral, and reach a far wider set of companies than high-risk systems do:

  • Transparency (since August 2026). If a person is interacting with an AI system they have to be told, and generated content has to be marked — though systems already in service before August 2026 have until 2 December 2026 for the machine-readable marking. That covers an ordinary website chatbot, not only critical systems.
  • AI literacy (since February 2025). A duty to take measures supporting the development of AI literacy among the people operating these systems on your behalf. It has applied for eighteen months and was not deferred.
  • Prohibited practices (since February 2025). A list of uses that may not be deployed at all — worth checking before a project starts rather than after.

The deferral is worth using, though: retrofitting documentation, logging and oversight onto a system already in production is considerably harder than designing them in. Companies that treat 2027 as the deadline will be doing this under pressure.

Where our role ends and your lawyer's begins

This boundary matters more than usual here, so we state it before describing the work.

  • We do not provide legal advice. We do not opine on whether your system is high-risk, and we do not interpret the regulation. This page is not legal advice either.
  • We do the engineering. We establish which systems you run and what for, and we build the technical documentation, logging, human-oversight mechanisms and monitoring — the material any compliance assessment rests on.
  • We work from your lawyer's conclusions. Once classification is settled, we translate it into concrete requirements. Where there is no classification yet, we prepare the material a lawyer needs in order to make one.

What the audit covers

The audit ends in a document, not a presentation. It contains three things, in order:

  • A register of AI systems. What is in use, by whom, in which process, on what data and who owns it — together with the role you occupy (provider or deployer), since the obligations follow from it. In practice this is often the most revealing part: tools adopted by teams on their own initiative are rarely written down anywhere.
  • A gap assessment. What is missing against the obligations that apply today and those arriving in 2027 — separately, so urgent can be told from important.
  • A list of technical tasks. Ranked by urgency and cost, distinguishing what is a configuration change from what needs work on the system itself.

What we build

The scope follows the audit and the classification, but the same elements recur whatever the sector. They are also the areas the regulation names explicitly for high-risk systems — and worth having before then.

  • Technical documentation — what the system does, what data it runs on, its limitations and known failure modes. Written to be readable a year later, when its author has changed jobs.
  • Logging and reconstructable decisions — inputs, outputs and model versions recorded well enough to reconstruct why the system answered as it did. Bolting this on afterwards is usually the most expensive part.
  • Human oversight — real oversight, with the ability to stop and correct the system, rather than a button nobody has ever pressed. It includes naming who oversees it and how they would know something was wrong.
  • Monitoring and response — watching quality and behaviour after deployment, and a route for reporting problems.
  • Transparency to the user — telling people they are talking to AI and marking generated content. This applies now.

AI literacy — the duty most often forgotten

Article 4 has applied since February 2025 and, after the July 2026 amendment, requires taking measures that support the development of AI literacy, accounting for knowledge, experience and context of use — not guaranteeing a particular level for each individual. It is an obligation of effort rather than of result, but a real one.

In practice it means the people using a system understand what it does, where it is unreliable, and when not to trust it. We run that training as part of AI implementation — and document it, because an undocumented measure is hard to evidence later.

Frequently asked questions

The high-risk deadline moved to 2027 — do we have time?

For the high-risk obligations, yes: 2 December 2027 for Annex III systems. But the deferral covers only that part. Transparency obligations have applied since 2 August 2026, prohibited practices and the AI literacy duty since February 2025, and the general-purpose model rules since August 2025. "Nothing to do until 2027" is the most common wrong conclusion drawn from the coverage of the delay.

How does a readiness audit differ from legal advice?

Legal advice tells you how the regulation applies to your situation and what risk it carries. We tell you what has to be built so that compliance can be evidenced: how systems are documented, what is logged, where a human can genuinely intervene, and what evidence is produced automatically. Legal classification stays with your lawyer — we work from their conclusions rather than in place of them.

We only use off-the-shelf tools like ChatGPT. Does the AI Act apply to us?

Most likely yes, but as a deployer rather than a provider — a different and usually much lighter set of obligations. The AI literacy duty covers people operating a system on your behalf regardless of who built it. If the tool talks to customers or generates content, transparency obligations come into play too.

What do we actually get from the audit?

A register of the AI systems in use with their role and context, an assessment of what is missing against both the obligations that apply now and those arriving in 2027, and a list of technical tasks ranked by urgency and cost. Without that register, a conversation about compliance is a conversation about systems nobody has counted.

Does the AI literacy duty mean mandatory certified training?

No. Since the July 2026 amendment, Article 4 requires taking measures that support the development of AI literacy, accounting for knowledge, experience and context of use — not guaranteeing a particular level for each individual, and not any specific certificate. What matters in practice is that the people operating a system understand what it does, where it gets things wrong, and when to stop it.

Do you help with GDPR as well?

The AI Act and the GDPR overlap but are separate regimes: the GDPR governs personal data, the AI Act governs AI systems, including ones that process no personal data at all. The audit flags where the two meet; a full GDPR assessment is separate work.

Sources

The dates and scopes above rest on the text of the regulation and the changes made by the Digital Omnibus, in force since 27 July 2026. Verified 19 August 2026. Current texts:

Start with the register

A free consultation, after which you know which AI systems you actually run and which of today's obligations reach you.