of global annual revenue — or €35,000,000, whichever is higher.
The EU AI Act’s maximum administrative fine for prohibited-practice breaches.
Can you produce the records that keep that number theoretical?
Twelve questions mapped to the Act’s core obligations. Answer honestly to see your readiness gaps. This is an orientation tool, not legal advice.
We keep records of high-risk AI system operation (logs retained over the system’s lifecycle).
Art. 12 — Record-keeping
Our high-risk AI systems are designed for effective human oversight.
Art. 14 — Human oversight
We provide clear information to users on an AI system’s capabilities and limitations.
Art. 13 — Transparency
We can demonstrate the accuracy, robustness, and cybersecurity of our AI systems.
Art. 15 — Accuracy & robustness
We maintain technical documentation sufficient to assess conformity.
Art. 11 — Technical documentation
We have a risk-management system covering the AI lifecycle.
Art. 9 — Risk management
Our training/validation data is governed for relevance and bias.
Art. 10 — Data governance
We can reconstruct a specific automated decision after the fact.
Art. 12 — Record-keeping
A named human can intervene in or override AI decisions.
Art. 14 — Human oversight
We disclose to people when they are interacting with an AI system.
Art. 50 — Transparency obligations
We log AI outputs that affect finances or customers, with pass/fail verification.
Art. 12/15
We could produce all of the above to a regulator on request.
Enforcement readiness

