AI-generated assessmentSample data

Sample

What the full report looks like

An anonymized sample of the executive AI Compliance Readiness Report.

Executive sample

AI Compliance Readiness Report — Sample

Illustrative figures based on a typical European SME using AI across marketing, support and HR.

0/100

Moderate exposure

Readiness score

MarketingMedium
SalesMedium
Customer SupportHigh
HRHigh
LegalCritical
FinanceMedium
EngineeringLow
OperationsLow
ProductMedium

Top risks (sample)

  • No AI usage policy in place

    GovernanceEmployees use AI tools without documented rules on acceptable use, prompts and data sharing.

  • Customer-facing chatbot lacks AI disclosure

    TransparencyArticle 50 of the EU AI Act requires informing users when they interact with an AI system.

  • Sensitive data entered into public AI tools

    Data ProtectionCustomer and personal data may be shared with public model providers without a vendor review.

  • Missing AI tools inventory

    DocumentationWithout a central inventory you cannot perform risk reviews or respond to incidents.

  • No human review for AI-supported decisions about people

    Human OversightHR and customer profiling use cases require meaningful human oversight.

Top actions (sample)

  1. 1Publish a one-page internal AI usage policy and share with all employees.
  2. 2Add a clear AI disclosure to your customer-facing chatbot and website.
  3. 3Create a simple inventory of every AI tool used across the company.
  4. 4Assign a single owner accountable for AI governance.
  5. 5Block sensitive data from being entered into public AI tools.

Risk register (sample)

Action plan — 5W2H (sample)

Next 7 days

4 actions

Next 30 days

3 actions

Next 60 days

3 actions

Next 90 days

3 actions

Required documentation checklist (sample)

AI Usage Policy

MissingHigh

Why it matters: Baseline rules so employees use AI consistently and safely.

Suggested first step: Draft a concise one-page AI usage policy and require employee acknowledgement.

AI Tools Inventory

MissingHigh

Why it matters: Foundation for risk reviews, vendor management and incident response.

Suggested first step: List every AI tool, owner, business area and personal-data exposure.

Vendor AI Review Checklist

MissingHigh

Why it matters: Captures DPA, sub-processors, training opt-out and retention before adopting AI vendors.

Suggested first step: Issue a vendor review questionnaire to the top 5 AI providers.

AI Risk Assessment

MissingHigh

Why it matters: Documents exposure per use case and supports recommended controls and priorities.

Suggested first step: Use this readiness report as the v1 risk assessment and refresh quarterly.

Customer AI Disclosure Notice

MissingHigh

Why it matters: Potentially relevant to Article 50 transparency obligations.

Suggested first step: Add a short disclosure to chatbot and product surfaces; update privacy notice.

Employee AI Training Record

MissingMedium

Why it matters: Demonstrates governance maturity and reduces misuse.

Suggested first step: Track completion of the 30-minute AI briefing in HR system.

AI Incident Log

MissingMedium

Why it matters: Supports learning, control tuning and timely notifications.

Suggested first step: Adopt a lightweight incident log and brief Support / Security.

Human Review Procedure

MissingHigh

Why it matters: Defines meaningful human oversight for AI-supported decisions about people.

Suggested first step: Document which decisions require human sign-off and how it is evidenced.

Prompt and Data Sharing Guidelines

MissingMedium

Why it matters: Reduces risk of sensitive data leakage into public AI tools.

Suggested first step: Publish a one-pager: what to share, what to avoid, redaction tips.

Article 50 Transparency Statement

MissingMedium

Why it matters: Captures how the company meets transparency obligations on AI interactions and generated content.

Suggested first step: Compile current disclosures, labelling and policies into a single statement.

DPIA Readiness Note

MissingHigh

Why it matters: Potentially relevant when AI involves personal data or significant decisions about people.

Suggested first step: Use the EDPB DPIA template to draft a readiness note for in-scope tools.

Appendix — Official and Recognized References (sample)

External official and recognized resources to help your company validate obligations, deepen analysis and prepare internal documentation.

EU AI Act

OfficialEuropean Union

EU AI Act Service Desk

Official AI Act information platform and service desk.

Open reference
OfficialEuropean Union

Official EU AI Act Compliance Checker

Official checker to help understand which AI Act rules may apply.

Open reference

Transparency

OfficialEuropean Union

AI Act Article 50 — Transparency Obligations

Official AI Act article covering transparency obligations for certain AI systems.

Open reference
OfficialEuropean Union

Code of Practice on Transparency of AI-Generated Content

European Commission code supporting AI Act transparency obligations related to marking and labelling AI-generated content.

Open reference
OfficialEuropean Union

EU Icons for Labelling AI-generated Content

EU icon set for labelling certain AI-generated or manipulated content.

Open reference

Data Protection

RegulatorEuropean Union

EDPB DPIA Template

European Data Protection Board reference for structuring and evidencing DPIA reporting processes.

Open reference

Automated Decision-making

RegulatorEuropean Union

EDPB Guidelines on Automated Decision-making and Profiling

Guidance on automated individual decision-making and profiling under GDPR.

Open reference

AI and Data Protection

RegulatorFrance / European context

CNIL Self-assessment Guide for AI Systems

Self-assessment guide for evaluating AI systems with regard to GDPR maturity.

Open reference

Risk Management

Recognized frameworkUnited States / International reference

NIST AI Risk Management Framework

Recognized AI risk management framework useful as a supporting reference, not an EU regulatory source.

Open reference

External links are provided as official or recognized reference resources. They do not replace legal advice or a company-specific legal assessment.

Sample data for illustration only. Your actual report is generated from your own assessment answers.

This is a readiness assessment, not formal legal advice. Independent product, not affiliated with any government or EU institution.