The Alice Labs EU AI Act Readiness Assessment
In short
The Alice Labs EU AI Act Readiness Assessment is a proprietary 25-point checklist that scores an organisation's compliance posture across inventory, classification, documentation, governance, and monitoring — used in 12+ Nordic enterprise engagements in 2025-2026.
We built the Alice Labs EU AI Act Readiness Assessment after seeing the same gaps repeat across enterprise clients. It is a 25-point checklist organised into five domains, each scored on a 0-4 maturity scale.
The five domains map directly to the structure of Regulation (EU) 2024/1689:
- System inventory and classification (5 points). Every AI system identified, classified, and registered with a business owner.
- Technical documentation (5 points). Annex IV completeness, version control, and 10-year retention.
- Risk and rights assessment (5 points). FRIA quality, risk management system, bias testing.
- Governance and literacy (5 points). Article 4 training, governance committee, vendor controls.
- Monitoring and incident response (5 points). Logging, post-market monitoring, incident reporting workflows.
In Alice Labs' EU AI Act engagements with 12+ Nordic enterprises in 2025-2026, the most common gap is missing technical documentation for AI systems already in production. The second most common gap is an incomplete inventory — leadership consistently underestimates how many AI systems exist inside the organisation.
A baseline assessment typically takes 2-3 weeks. Closing the gaps takes 8-16 weeks depending on system count and risk profile.
Risk Classification Framework: Four Tiers Explained
In short
The EU AI Act classifies AI systems into four tiers: unacceptable risk (banned), high-risk (Annex III, full obligations), limited risk (transparency only), and minimal risk (no obligations). Most enterprise AI falls into limited or minimal risk.
Classification is the gate that determines every downstream obligation. Misclassification is the most expensive mistake an organisation can make under the AI Act.
Use the table below as a first-pass mapping. Edge cases — for example, a chatbot that screens job applicants — almost always require legal review before classification is finalised.
| Risk tier | Examples | Core obligations | Article |
|---|---|---|---|
| Unacceptable | Social scoring, manipulative subliminal techniques, real-time public biometric identification (with narrow exceptions) | Banned outright; prohibited from market | Article 5 |
| High-risk | Biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, democratic processes | Annex IV documentation, FRIA, conformity assessment, CE marking, post-market monitoring | Articles 6-49 + Annex III |
| Limited risk | Chatbots, emotion recognition, deepfakes, AI-generated content | Transparency: disclose AI interaction or AI-generated content | Article 50 |
| Minimal risk | Spam filters, AI-enabled video games, inventory optimisation | No mandatory obligations; voluntary codes of conduct encouraged | Article 95 |
Source: Regulation (EU) 2024/1689
High-Risk Requirements Deep-Dive: Annex IV Documentation
In short
Annex IV requires nine documentation categories for every high-risk AI system: general description, system design, monitoring, performance metrics, risk management, lifecycle changes, standards applied, EU declaration of conformity, and post-market monitoring plan.
Annex IV is the heart of high-risk compliance. It is also where most enterprises are weakest. The documentation must be ready before a system is placed on the market and updated continuously for 10 years after the last unit is placed on the market.
The nine required sections are:
- General description. Intended purpose, version, provider name, hardware on which it runs, user interface.
- Detailed design. System architecture, key design choices, training methodology, datasets used, computational resources.
- Monitoring, functioning, and control. Capabilities and limitations, foreseeable outputs, expected accuracy levels.
- Performance metrics. Test datasets, validation results, accuracy, robustness, cybersecurity testing.
- Risk management system. Identified risks, mitigation measures, residual risk acceptance criteria.
- Lifecycle changes. Version control, change log with dates, rationale for each change.
- Harmonised standards applied. CEN-CENELEC, ISO, or IEC standards used to demonstrate conformity.
- EU declaration of conformity. Issued by the provider, signed, retained for 10 years.
- Post-market monitoring plan. Data collection, analysis cadence, escalation procedures.
Treat Annex IV as a living artefact, not a one-time deliverable. Build it into the system's CI/CD pipeline so it never goes stale.
Don't know how many AI systems you actually run?
We start every EU AI Act engagement with a 2-week inventory sprint. Most clients discover 2-3x more AI systems than leadership initially estimated.
Book an AI Act readiness callGPAI Obligations: A Separate Track
In short
General-Purpose AI (GPAI) models — foundation models like GPT-4, Claude, and Gemini — follow a separate obligation track under Articles 51-55: documentation, copyright compliance, training-data summaries, and codes of practice. A 10^25 FLOPs training-compute threshold triggers systemic-risk obligations.
GPAI obligations apply from 2 August 2025 and target the model providers themselves — OpenAI, Anthropic, Google DeepMind, Meta, Mistral, and others. If you build on top of these models, the primary GPAI obligations sit with the provider, not you.
All GPAI providers must:
- Maintain technical documentation covering training, evaluation, and intended use.
- Comply with EU copyright law, including respecting Text and Data Mining (TDM) opt-outs.
- Publish a sufficiently detailed summary of the content used for training the model.
- Cooperate with the AI Office and provide information to downstream providers.
Models trained with more than 10^25 FLOPs of compute are presumed to pose systemic risk and trigger additional obligations: model evaluations, adversarial testing, serious-incident reporting, and cybersecurity protections.
If you are a deployer building on GPAI, your obligations primarily track with the use case — high-risk if Annex III applies, limited risk for chatbots and content generation. The model provider's documentation flows down to support your own.
Penalties and Timeline: What's at Stake and When
In short
EU AI Act penalties scale by violation: up to €35M or 7% of global turnover for prohibited practices, up to €15M or 3% for other infringements, and up to €7.5M or 1% for incorrect information. The timeline runs from 1 August 2024 entry into force to 2 August 2027 full enforcement.
The penalty structure is more aggressive than GDPR's 4% cap. For prohibited AI practices, the AI Act allows up to 7% of global annual turnover — and supervisory authorities have signalled they will use it.
The three penalty tiers are:
- €35M or 7% of global turnover for violating prohibited AI practices under Article 5 (whichever is higher).
- €15M or 3% of global turnover for other violations of obligations on providers and deployers.
- €7.5M or 1% of global turnover for supplying incorrect, incomplete, or misleading information to authorities.
The applicability timeline is staggered:
- 1 August 2024. Regulation enters into force.
- 2 February 2025. Prohibited practices ban and Article 4 AI literacy obligations apply.
- 2 August 2025. GPAI obligations and governance provisions apply.
- 2 August 2026. High-risk system obligations (Annex III) apply — the main enforcement milestone.
- 2 August 2027. Full enforcement, including high-risk systems under Annex I (product safety).
If your roadmap doesn't have a delivery line for 2 August 2026, now is the time to add one.
About the Authors & Reviewers

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.
- AI automation & agent systems lead
- Workflow design across 100+ deployments
- Specialist in RAG, integrations & APIs

Co-Founder, Alice Labs
Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.
- 8+ years in AI strategy & implementation
- Top-5 AI Speaker, Sweden (Mindley 2025)
- 100+ enterprise AI engagements
Frequently Asked Questions
When does the EU AI Act apply to my organisation?
The EU AI Act entered into force on 1 August 2024. Prohibited practices and AI literacy (Article 4) applied from 2 February 2025. GPAI obligations apply from 2 August 2025. High-risk system obligations apply from 2 August 2026. Full enforcement is reached on 2 August 2027.
What counts as a high-risk AI system?
High-risk systems are listed in Annex III and cover eight domains: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice and democratic processes. AI used as a safety component of a regulated product (Annex I) is also high-risk.
What is the difference between a Provider and a Deployer?
A Provider develops or commissions an AI system and places it on the EU market or puts it into service under its own name or trademark. A Deployer uses an AI system under its authority, except when use is in the course of a personal non-professional activity. Providers carry the full Annex IV documentation burden; deployers focus on FRIA, monitoring, and human oversight.
What are the penalties for non-compliance with the EU AI Act?
Penalties reach up to €35 million or 7% of global annual turnover (whichever is higher) for violations of prohibited practices in Article 5. Other violations of provider and deployer obligations carry fines up to €15 million or 3% of global turnover. Supplying incorrect or misleading information to authorities is fined up to €7.5 million or 1% of global turnover.
Do I need a Fundamental Rights Impact Assessment (FRIA)?
Article 27 requires deployers of high-risk AI systems that are bodies governed by public law, private operators providing public services, or deployers using systems for credit scoring or insurance pricing to conduct a FRIA before deployment. The FRIA covers affected individuals, frequency of use, harm categories, mitigation measures, and human oversight, and must be notified to the relevant national authority.
What is the 10^25 FLOPs threshold for GPAI models?
Article 51 of the EU AI Act presumes that a General-Purpose AI model has high-impact capabilities — and therefore systemic risk — when the cumulative compute used for training is greater than 10^25 floating-point operations. Models above this threshold trigger additional obligations including model evaluations, adversarial testing, serious-incident reporting, and cybersecurity protections.
Does the AI Act apply if my company is outside the EU?
Yes. The EU AI Act applies extraterritorially. It covers providers placing AI systems on the EU market regardless of where they are established, and deployers established in the EU. It also covers providers and deployers outside the EU when the system's output is used in the EU. Non-EU providers must appoint an authorised representative established in the EU.
How does AI Act compliance overlap with GDPR?
There is significant overlap. Records of AI systems can extend records of processing under GDPR Article 30. Data Protection Impact Assessments (DPIAs) align with FRIAs for high-risk systems. Transparency obligations under Article 50 reinforce GDPR Articles 13-15. Most enterprises run AI Act compliance as an extension of their existing GDPR programme rather than a parallel workstream.
Shadow AI Policy Template: Stop Unauthorized AI Use at Work
Further reading
- Regulation (EU) 2024/1689 — official consolidated text· eur-lex.europa.eu
- European Commission — AI Act overview· digital-strategy.ec.europa.eu
- European AI Office — GPAI codes of practice· digital-strategy.ec.europa.eu
- EU AI Act Explorer (artificialintelligenceact.eu)· artificialintelligenceact.eu
Related services
Related reading
Enterprise AI Strategy: 6-Step Framework
Strategic framework that places AI Act compliance inside the wider enterprise AI lifecycle.
16 min deepdiveWhy AI Projects Fail: 7 Patterns We See in 2026
Common failure modes including governance, compliance, and AI Act readiness gaps.
10 min comparisonBuild vs Buy AI: How to Decide for Enterprise
How build/buy decisions affect provider vs deployer obligations under the EU AI Act.
9 minSources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)(accessed 2026-04-28)
- European Commission — Regulatory framework on AI (digital-strategy.ec.europa.eu)(accessed 2026-04-28)
- European AI Office — General-Purpose AI codes of practice(accessed 2026-04-28)
- EU AI Act Explorer — Annex III high-risk categories(accessed 2026-04-28)
- EU AI Act — Annex IV technical documentation requirements(accessed 2026-04-28)
- EU AI Act — Article 99 penalties for providers and deployers(accessed 2026-04-28)
- EU AI Act — Article 51 GPAI systemic-risk threshold (10^25 FLOPs)(accessed 2026-04-28)
Next scheduled review: