An EU AI Act readiness assessment is three things: an inventory of every AI system you build or use, a classification of each one against the Act's risk tiers, and a gap list against the obligations that attach to that tier. It is a product and operations exercise more than a legal one, which is why it usually stalls when it gets handed to legal alone.
The reason to run one this quarter is counterintuitive. The headline deadline just moved, and most teams read that as permission to stop. It is not.
The deadline moved. The rules did not go away
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before the original high-risk deadline. It amends the AI Act itself and pushes two dates back:
- Stand-alone high-risk systems (Annex III): 2 December 2027. A sixteen-month deferral.
- AI embedded in regulated products (Annex I): 2 August 2028. A twelve-month deferral.
One detail matters more than the dates. The Commission's original proposal tied the delay to a conditional trigger, meaning the clock would start when harmonised standards and guidance were actually ready. The final agreement replaced that with fixed dates (Gibson Dunn's analysis of the agreement walks through the change). So there is no further slip built into the text. December 2027 is the date.
What already applies to you today
This is the part that gets lost in the coverage of the delay. Working from the official implementation timeline:
| Obligation | Applies since |
|---|---|
| Prohibited practices (Article 5) | 2 February 2025 |
| AI literacy (Article 4) | 2 February 2025 |
| General-purpose AI model obligations (Articles 51 to 56) | 2 August 2025 |
| Governance, notified bodies, and the penalties framework | 2 August 2025 |
| Transparency for AI interaction and synthetic content (Article 50) | 2 August 2026 |
Two carve-outs worth knowing. Providers of general-purpose models that were already on the market get until 2 August 2027. And the watermarking piece of Article 50 has a four-month grace period for systems already deployed, which closes on 2 December 2026. The new prohibitions on AI that generates non-consensual intimate imagery or CSAM also bite from 2 December 2026.
So if you are waiting for the Act to become real, it became real nineteen months ago. The deferral covers one tier of obligations, not the regime.
What a readiness assessment actually covers
Five steps, in this order. The order matters, because every step depends on the one before it.
1. Inventory what you have. You cannot classify a system you have not written down. This is the step that takes longest and the one teams consistently underestimate, because the inventory is never just the models your engineers shipped. It is the vendor tools with AI features switched on by default, the workflow automation someone in ops bought on a credit card, and the model your data team is fine-tuning in a notebook. Budget real weeks for this.
2. Establish your role for each system. The Act puts different obligations on providers than on deployers, and most organisations are both. You are a deployer of the AI in your CRM and a provider of the AI feature in your own product. Get this wrong and you will build a compliance plan against the wrong list.
3. Classify against the tiers. Prohibited, high-risk, limited-risk with transparency duties, or minimal. Annex III is the list that matters for most software companies, and it is narrower than people fear: employment and worker management, access to essential services, credit scoring, education, biometrics, law enforcement. Plenty of B2B SaaS has nothing in Annex III at all. Finding that out is a legitimate and valuable outcome of the assessment.
4. Build the gap list. For each system, what the tier requires against what you have today. Risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness. Expect the honest answer on most of these to be "partially, and undocumented".
5. Put a name and a date on every gap. A gap list without an owner is a document, not a plan. This is the difference between an assessment that changes something and one that gets filed.
Three things teams get wrong
"We just use ChatGPT, so this does not apply." Deployer obligations are lighter than provider obligations, but they are not zero, and the Article 4 literacy duty applies to deployers regardless of tier. More to the point, the sentence is almost never true. Once you actually run step one, something in the inventory turns out to be a system you built.
Treating it as a legal project. Legal can tell you what the obligations are. They cannot tell you which model is behind which feature, what data trains it, who reviews its output, or whether the logging exists. That is product and engineering knowledge, and an assessment run without those people in the room produces a document that is confidently wrong.
Reading the deferral as a reprieve. The work that takes the longest is the boring work: the inventory, the documentation, the logging you did not build, the human oversight step you have to design into a workflow that currently has none. None of that is a fourth-quarter-2027 exercise. Teams that start in 2027 will be retrofitting oversight into shipped products, which is the expensive way to do it.
What the extra time is actually good for
The generous reading of the deferral is that Brussels bought everyone sixteen months because the standards were not ready. That is true, and it is worth taking at face value.
The useful thing to do with sixteen months is not to wait for the standards. It is to run the inventory now, while it is cheap, and find out which category you are in. If nothing you own touches Annex III, you will know that in a few weeks and can stop worrying about a deadline that does not apply to you. If something does, you have four clear quarters to build documentation and oversight into products while they are still being designed, rather than bolting it on afterwards.
Both outcomes are worth more than the report. The inventory alone tends to surface things nobody knew were running.
Where I can help
I run AI readiness assessments as part of AI adoption consulting, usually as the first two weeks of a longer engagement, and as a standalone piece of a product audit when the question is narrower. The output is the inventory, the classification, and the owned gap list, not a compliance binder.
If you want to talk through where your team actually sits, book a call.
This post explains how to approach a readiness assessment. It is not legal advice, and the classification of any specific system is a judgment you should make with counsel.
Related services
Frameworks for this topic
Read next
BBFantasy is a fantasy draft league for Big Brother, live for the season 28 premiere. I ran the same 16-step product process I run for clients on my own reality-TV habit, and the analytics rerouted the entire strategy.
I built a 16-step product strategy process from skills I use with clients. Then I ran it on k8mak.com. The biggest finding: the site I thought I was building was not the site I needed.
I built k8mak.com the same way I build products for clients: JTBD research, OKR alignment, opportunity solution trees, and a 15-step product strategy process. Here is what I built, what I cut, and why.
Want to work together?
I help teams ship better products. Let's talk about your situation.
Get in touch