Methodology
How the AI Compliance Readiness Report is built, what the score means, and its limits.
Readiness assessment — not legal advice or certification. Independent product.
Who this is for
The product is designed for European small and medium-sized businesses (SMEs) that already use AI tools such as ChatGPT, Claude, Gemini, Copilot, Cursor, Lovable, n8n or custom GPTs.
It helps you find and close the biggest governance, transparency and documentation gaps first — without requiring a dedicated compliance team.
How the assessment works
The assessment is based on structured multiple-choice answers about your company, the AI tools you use and how you use them. No sensitive documents need to be uploaded.
Your answers are scored deterministically against an internal best-practice model for European SMEs, and the report narrative is generated from those results.
What the score measures
The score covers seven dimensions: governance, transparency, documentation, data protection, vendor risk, human oversight and risk management.
Each dimension contributes to your overall readiness score and to the exposure level shown in the free snapshot.
About the benchmark
The benchmark shown in the report is an internal best-practice model for European SMEs. It is not an official statistic and does not represent regulatory guidance.
It exists to help you compare your readiness to what a well-governed SME of similar size and AI footprint would typically have in place.
Reference-informed, not regulator-approved
The report links to official and recognized public references (EU AI Act, GDPR, ENISA, NIST AI RMF, ISO/IEC 42001 and similar).
This product is independent and is not approved, endorsed or operated by any regulator, government body or EU institution. Reference names and links belong to their respective owners.
No sensitive uploads required
You never need to upload contracts, personal data, source code or confidential documents to receive the report.
The assessment only collects structured answers about your AI usage.
Human review recommended
Sensitive findings — for example anything involving personal data, automated decisions or customer disclosures — are flagged as “Human review recommended”.
The report is a starting point for internal discussion, not a substitute for qualified legal or security advice.
Limits
The report reflects the answers you provide at the time of the assessment. It does not audit your systems, contracts or vendors.
It does not replace legal counsel, a Data Protection Impact Assessment (DPIA) or a formal AI Act conformity assessment where those are required.
About the operator
AI Compliance Readiness Report is operated by Vinicius Pirola. The product is designed to help European SMEs understand AI readiness gaps through a structured assessment and a practical report. More information: https://www.viniciuspirola.com.