Sample
What the full report looks like
An anonymized sample of the executive AI Compliance Readiness Report.
Executive sample
AI Compliance Readiness Report — Sample
Illustrative figures based on a typical European SME using AI across marketing, support and HR.
0/100
Moderate exposure
Readiness score
Top risks (sample)
No AI usage policy in place
Governance — Employees use AI tools without documented rules on acceptable use, prompts and data sharing.
Customer-facing chatbot lacks AI disclosure
Transparency — Article 50 of the EU AI Act requires informing users when they interact with an AI system.
Sensitive data entered into public AI tools
Data Protection — Customer and personal data may be shared with public model providers without a vendor review.
Missing AI tools inventory
Documentation — Without a central inventory you cannot perform risk reviews or respond to incidents.
No human review for AI-supported decisions about people
Human Oversight — HR and customer profiling use cases require meaningful human oversight.
Top actions (sample)
- 1Publish a one-page internal AI usage policy and share with all employees.
- 2Add a clear AI disclosure to your customer-facing chatbot and website.
- 3Create a simple inventory of every AI tool used across the company.
- 4Assign a single owner accountable for AI governance.
- 5Block sensitive data from being entered into public AI tools.
Risk register (sample)
Action plan — 5W2H (sample)
Next 7 days
Next 30 days
Next 60 days
Next 90 days
Required documentation checklist (sample)
AI Usage Policy
Why it matters: Baseline rules so employees use AI consistently and safely.
Suggested first step: Draft a concise one-page AI usage policy and require employee acknowledgement.
Recommended reference
AI Tools Inventory
Why it matters: Foundation for risk reviews, vendor management and incident response.
Suggested first step: List every AI tool, owner, business area and personal-data exposure.
Recommended reference
Vendor AI Review Checklist
Why it matters: Captures DPA, sub-processors, training opt-out and retention before adopting AI vendors.
Suggested first step: Issue a vendor review questionnaire to the top 5 AI providers.
AI Risk Assessment
Why it matters: Documents exposure per use case and supports recommended controls and priorities.
Suggested first step: Use this readiness report as the v1 risk assessment and refresh quarterly.
Customer AI Disclosure Notice
Why it matters: Potentially relevant to Article 50 transparency obligations.
Suggested first step: Add a short disclosure to chatbot and product surfaces; update privacy notice.
Recommended reference
Employee AI Training Record
Why it matters: Demonstrates governance maturity and reduces misuse.
Suggested first step: Track completion of the 30-minute AI briefing in HR system.
Recommended reference
AI Incident Log
Why it matters: Supports learning, control tuning and timely notifications.
Suggested first step: Adopt a lightweight incident log and brief Support / Security.
Recommended reference
Human Review Procedure
Why it matters: Defines meaningful human oversight for AI-supported decisions about people.
Suggested first step: Document which decisions require human sign-off and how it is evidenced.
Recommended reference
Prompt and Data Sharing Guidelines
Why it matters: Reduces risk of sensitive data leakage into public AI tools.
Suggested first step: Publish a one-pager: what to share, what to avoid, redaction tips.
Recommended reference
Article 50 Transparency Statement
Why it matters: Captures how the company meets transparency obligations on AI interactions and generated content.
Suggested first step: Compile current disclosures, labelling and policies into a single statement.
DPIA Readiness Note
Why it matters: Potentially relevant when AI involves personal data or significant decisions about people.
Suggested first step: Use the EDPB DPIA template to draft a readiness note for in-scope tools.
Recommended references
Appendix — Official and Recognized References (sample)
External official and recognized resources to help your company validate obligations, deepen analysis and prepare internal documentation.
EU AI Act
EU AI Act Service Desk
Official AI Act information platform and service desk.
Open referenceOfficial EU AI Act Compliance Checker
Official checker to help understand which AI Act rules may apply.
Open referenceTransparency
AI Act Article 50 — Transparency Obligations
Official AI Act article covering transparency obligations for certain AI systems.
Open referenceCode of Practice on Transparency of AI-Generated Content
European Commission code supporting AI Act transparency obligations related to marking and labelling AI-generated content.
Open referenceEU Icons for Labelling AI-generated Content
EU icon set for labelling certain AI-generated or manipulated content.
Open referenceData Protection
EDPB DPIA Template
European Data Protection Board reference for structuring and evidencing DPIA reporting processes.
Open referenceAutomated Decision-making
EDPB Guidelines on Automated Decision-making and Profiling
Guidance on automated individual decision-making and profiling under GDPR.
Open referenceAI and Data Protection
CNIL Self-assessment Guide for AI Systems
Self-assessment guide for evaluating AI systems with regard to GDPR maturity.
Open referenceRisk Management
NIST AI Risk Management Framework
Recognized AI risk management framework useful as a supporting reference, not an EU regulatory source.
Open referenceExternal links are provided as official or recognized reference resources. They do not replace legal advice or a company-specific legal assessment.
This is a readiness assessment, not formal legal advice. Independent product, not affiliated with any government or EU institution.