Regulatory readiness review · EU AI Act
EU AI Act Readiness Assessment
Your counsel decides which obligations and systems are in scope. We test whether the matching evidence, controls, owners, exceptions, and remediation records exist and are current, and the compliance conclusion stays theirs.
Your qualified authority defines which EU AI Act obligations and systems are in scope. We test whether the corresponding organizational evidence, controls, owners, exceptions, and remediation records exist and are current. The legal and compliance conclusion remains theirs. Nothing in the report says whether you comply. It says which readiness statements survived a check against sampled systems, which exceptions are critical, and who committed to close them.


Some of the 500+ brands we've worked with
See all referencesThe run order, and who signs each step off
How we work
The client-supplied interpretation fixes the legal boundary. Within it, we follow each readiness statement to current evidence and test selected systems directly instead of accepting a self-reported status.
Confirm the interpreted scope
Your qualified authority supplies the applicable obligations, systems, roles, and acceptance owner. We translate that supplied boundary into technical assessment points without adding our own legal interpretation. Your qualified authority confirms the interpretation and the boundary for the technical review.


Follow every statement to evidence
Policies, role records, technical artifacts, operating controls, incidents, exceptions, and dependencies are linked to the assessment points agreed at the start. Missing or outdated evidence remains visible. Your qualified authority decides which readiness statements still lack sufficient current evidence.


Check representative systems directly
We sample selected systems and controls to see whether the operating evidence matches the stated readiness position. Contradictory, missing, or weak proof is recorded as an exception and cannot count as a pass. Your qualified authority decides which exception blocks acceptance of the readiness record.


Assign remediation ownership
Observed gaps are prioritized and attached to owners, dependencies, and next actions. Work that remains unresolved receives a decision state and a date when your authority will review the position again. Your qualified authority accepts the handoff and confirms who owns every open gap.


Named artifacts you keep
What you get
The final record shows what we observed against your interpreted scope and which evidence was reviewed. It does not contain Zeo's legal or compliance opinion.


Risk register
Readiness gaps and the remediation plan behind them
Observed gaps for the agreed obligations, with their evidence, priority, owner, dependency, and next action.


Test evidence
Source list and open assumptions behind the readiness call
The sources used during review, their limits and versions, open assumptions, and dependencies affecting the readiness position.


Report
Sampled-systems readout and the critical exceptions
The systems sampled, controls checked, contradictory evidence, critical exceptions, and conditions found in the review.


Decision record
Accepted scope, remediation commitments, and next review
The accepted assessment scope, open conditions, remediation commitments, decision owner, and next review date.
Scope and honest limits
When to bring us in
This review helps when a legal interpretation exists but the supporting evidence is scattered across policy files, system records, owners, and open exceptions.
A good fit when
- Your counsel has interpreted which obligations apply, but the evidence that would satisfy them is spread across policy files, system records, and inboxes.
- A control is marked in place against an obligation, and nobody can say which system it covers, who maintains it, or when it was last checked.
- The organization is preparing a broad readiness claim before representative systems and controls have been checked.
- Which obligations apply is settled, but the assessment boundary they imply has never been drawn around named systems and named owners.
- Evidence, controls, owners, dependencies, and exceptions all exist in some form, yet nothing maps them onto the obligations your authority interpreted.
- Readiness has been asserted from documents alone, so nobody has opened a representative system and checked the control actually running in it.
- A gap list would need owners, dates, and a route back to whoever accepts residual exposure, though none of that exists yet.


Better handled as other work when
- You want us to say whether you comply. We report whether the evidence behind your authority's interpretation exists, and the determination stays theirs.
- You are after a certificate or a promise that conformity will hold at some future date. Neither is something a readiness review can issue.
- You want the gaps closed as part of this work. Remediation runs outside the agreed review unless it is commissioned alongside it.
If one of these is closer to your situation, start here instead: View the governance service
Advice from people who build
We've worked with more than 500 brands since Zeo started in 2011. The people helping you decide where AI fits, and where it doesn't yet, are senior engineers and strategists who build and operate production AI systems. The advice stays grounded in work that actually shipped.
Tools we use
Tools behind this work
OneTrustthe EU AI Act evidence register used to organize the readiness review
Airtablethe tracker linking each gap to its evidence status and remediation owner
Credo AIthe EU AI Act policy pack a gap finding traces back to a specific article
Next step
Test the evidence behind the readiness statement


Before you decide




























































