How to Run an EU AI Act Readiness Audit in 30 Days
Ready 4 AI Act ยท April 2, 2026 ยท Last updated July 31, 2026

What an EU AI Act readiness audit is
An EU AI Act readiness audit is a structured review that inventories every AI system in use, classifies each one under the Act's risk tiers, and produces a documented gap analysis against the obligations that apply.
Done properly it takes 30 focused days for a mid-sized organisation.
Week 1 โ Inventory
Sources: procurement records, SaaS licence lists, shadow-IT surveys, vendor questionnaires. Expect the final count to be 2-3x what leadership initially guesses.
Week 2 โ Classification
- Prohibited (Article 5) โ if yes, stop use.
- High-risk (Annex III or Annex I) โ HR, credit, education, critical infrastructure, safety components.
- GPAI โ provider or deployer?
- Limited risk (Article 50) โ chatbots, generative content, deepfakes.
- Minimal risk โ everything else. Article 4 literacy still applies.
Week 3 โ Gap analysis
For every high-risk system, map current state against Articles 9-17 and 72. Score each obligation red / amber / green with evidence.
Week 4 โ Roadmap
- Executive summary: risk exposure, headline gaps, remediation cost.
- Prioritised backlog against the 2 August 2026 and 2 August 2027 deadlines.
- Named governance owner.
Common traps
- Skipping shadow IT.
- Taking vendor classifications at face value.
- Producing a 200-page report no-one reads.
Related: Guided AI Act audits ยท EU AI Act overview ยท Free readiness assessment
Reviewed by Ready 4 AI Act EU - Editorial team. This article is journalistic information, not legal advice.
Not sure where you stand?
Take the free readiness assessment and get a personalised report.
Start free assessment