Regulatory readiness review · EU AI Act
EU AI Act Readiness Assessment
Your counsel decides which obligations and systems are in scope. We test whether the matching evidence, controls, owners, exceptions, and remediation records exist and are current, and the compliance conclusion stays theirs.
Your qualified authority defines which EU AI Act obligations and systems are in scope. We test whether the corresponding organizational evidence, controls, owners, exceptions, and remediation records exist and are current. The legal and compliance conclusion remains theirs.
Nothing in the report says whether you comply. It says which readiness statements survived a check against sampled systems, which exceptions are critical, and who committed to close them.


Some of the 500+ brands we've worked with
See all referencesSteps, gates, and who decides
How we work
The client-supplied interpretation fixes the legal boundary. Within it, we follow each readiness statement to current evidence and test selected systems directly instead of accepting a self-reported status.
Confirm the interpreted scope
Your qualified authority supplies the applicable obligations, systems, roles, and acceptance owner. We translate that supplied boundary into technical assessment points without adding our own legal interpretation.
- AI assist
- The model organizes supplied obligations and systems into a scope summary. It does not interpret them.
- Human gate
- Is the supplied set of obligations, systems, and assessment points specific enough for your authority to confirm the test boundary? Your qualified authority confirms the interpretation and the boundary for the technical review.


Follow every statement to evidence
Policies, role records, technical artifacts, operating controls, incidents, exceptions, and dependencies are linked to the assessment points agreed at the start. Missing or outdated evidence remains visible.
- AI assist
- Approved policies, records, and control evidence are placed beside the agreed assessment points.
- Human gate
- Does every readiness statement have a current source and an owner who can explain it? Your qualified authority decides which readiness statements still lack sufficient current evidence.


Check representative systems directly
We sample selected systems and controls to see whether the operating evidence matches the stated readiness position. Contradictory, missing, or weak proof is recorded as an exception and cannot count as a pass.
- AI assist
- The sampled evidence is compared with the stated controls to flag gaps and contradictions for a specialist.
- Human gate
- Which critical exceptions prevent the sampled evidence from supporting an honest readiness position? Your qualified authority decides which exception blocks acceptance of the readiness record.


Assign remediation ownership
Observed gaps are prioritized and attached to owners, dependencies, and next actions. Work that remains unresolved receives a decision state and a date when your authority will review the position again.
- AI assist
- Tested findings, owners, and dependencies become a draft gap register and remediation sequence for review.
- Human gate
- Does every open critical gap have an owner, next action, dependency state, and review date? Your qualified authority accepts the handoff and confirms who owns every open gap.


Named artifacts you keep
What you get
The final record shows what we observed against your interpreted scope and which evidence was reviewed. It does not contain Zeo's legal or compliance opinion.


Risk register
Readiness gaps and the remediation plan behind them
Observed gaps for the agreed obligations, with their evidence, priority, owner, dependency, and next action.


Test evidence
Source list and open assumptions behind the readiness call
The sources used during review, their limits and versions, open assumptions, and dependencies affecting the readiness position.


Report
Sampled-systems readout and the critical exceptions
The systems sampled, controls checked, contradictory evidence, critical exceptions, and conditions found in the review.


Decision record
Accepted scope, remediation commitments, and next review
The accepted assessment scope, open conditions, remediation commitments, decision owner, and next review date.
Scope and honest limits
When to bring us in
This review helps when a legal interpretation exists but the supporting evidence is scattered across policy files, system records, owners, and open exceptions.
A good fit when
- Your counsel has interpreted which obligations apply, but the evidence that would satisfy them is spread across policy files, system records, and inboxes.
- A control is marked in place against an obligation, and nobody can say which system it covers, who maintains it, or when it was last checked.
- The organization is preparing a broad readiness claim before representative systems and controls have been checked.
- Which obligations apply is settled, but the assessment boundary they imply has never been drawn around named systems and named owners.
- Evidence, controls, owners, dependencies, and exceptions all exist in some form, yet nothing maps them onto the obligations your authority interpreted.
- Readiness has been asserted from documents alone, so nobody has opened a representative system and checked the control actually running in it.
- A gap list would need owners, dates, and a route back to whoever accepts residual exposure, though none of that exists yet.
Better handled as other work when
- You want us to say whether you comply. We report whether the evidence behind your authority's interpretation exists, and the determination stays theirs.
- You are after a certificate or a promise that conformity will hold at some future date. Neither is something a readiness review can issue.
- You want the gaps closed as part of this work. Remediation runs outside the agreed review unless it is commissioned alongside it.
If one of these is closer to your situation, start here instead: View the governance service
Advice from people who build
We've worked with more than 500 brands since Zeo started in 2011. The people helping you decide where AI fits, and where it doesn't yet, are senior engineers and strategists who build and operate production AI systems. The advice stays grounded in work that actually shipped.
Tools we use
Tools behind this work
OneTrustthe EU AI Act evidence register used to organize the readiness review
Airtablethe tracker linking each gap to its evidence status and remediation owner
Credo AIthe EU AI Act policy pack a gap finding traces back to a specific article
Next step
Test the evidence behind the readiness statement


Before you decide


























