AI auditreadinessgap analysis

    How to Run an EU AI Act Readiness Audit in 30 Days

    Ready 4 AI Act ยท April 2, 2026 ยท Last updated July 31, 2026

    Cover image for "How to Run an EU AI Act Readiness Audit in 30 Days"

    What an EU AI Act readiness audit is

    An EU AI Act readiness audit is a structured review that inventories every AI system in use, classifies each one under the Act's risk tiers, and produces a documented gap analysis against the obligations that apply.

    Done properly it takes 30 focused days for a mid-sized organisation.

    Week 1 โ€” Inventory

    Sources: procurement records, SaaS licence lists, shadow-IT surveys, vendor questionnaires. Expect the final count to be 2-3x what leadership initially guesses.

    Week 2 โ€” Classification

    1. Prohibited (Article 5) โ€” if yes, stop use.
    2. High-risk (Annex III or Annex I) โ€” HR, credit, education, critical infrastructure, safety components.
    3. GPAI โ€” provider or deployer?
    4. Limited risk (Article 50) โ€” chatbots, generative content, deepfakes.
    5. Minimal risk โ€” everything else. Article 4 literacy still applies.

    Week 3 โ€” Gap analysis

    For every high-risk system, map current state against Articles 9-17 and 72. Score each obligation red / amber / green with evidence.

    Week 4 โ€” Roadmap

    • Executive summary: risk exposure, headline gaps, remediation cost.
    • Prioritised backlog against the 2 August 2026 and 2 August 2027 deadlines.
    • Named governance owner.

    Common traps

    • Skipping shadow IT.
    • Taking vendor classifications at face value.
    • Producing a 200-page report no-one reads.

    Related: Guided AI Act audits ยท EU AI Act overview ยท Free readiness assessment

    Reviewed by Ready 4 AI Act EU - Editorial team. This article is journalistic information, not legal advice.

    Not sure where you stand?

    Take the free readiness assessment and get a personalised report.

    Start free assessment