Free Assessment โ†’

How AISight Works

AISight is a free, open-methodology tool for assessing your organization's readiness for the EU AI Act (Regulation 2024/1689). This page explains exactly how the assessment works, what the scores mean, and which regulation articles each question maps to.

Important: AISight is an informational tool. It does not constitute legal advice, and it is not certified or endorsed by any regulatory authority. The assessment is based on the published text of Regulation (EU) 2024/1689. For binding compliance guidance, consult a qualified legal professional.

Source Material

All questions, classification logic, and compliance requirements in AISight are derived from a single source:

We do not use third-party research, market estimates, or proprietary data. Every article reference, risk category, and obligation listed in the tool can be verified against the regulation text at artificialintelligenceact.eu.

Readiness Assessment

How It Works

The assessment consists of 15 questions across 4 sections. Your answers are scored across 4 dimensions, weighted, and combined into an overall readiness score from 0 to 100.

The 4 Dimensions

DimensionWeightWhat It Measures
Exposure30%How much EU AI Act obligation your organization likely faces โ€” based on EU presence, industry, number of AI tools, high-risk use cases, and whether you build AI
Visibility25%How well you know what AI is in use โ€” shadow AI awareness, AI inventory completeness, tool count awareness
Governance25%Organizational readiness โ€” AI usage policy, governance ownership, risk assessment practices
Compliance20%Progress toward specific EU AI Act requirements โ€” awareness of the regulation, risk classification, technical documentation, conformity assessments

Scoring Formula

Each dimension is scored independently from 0 to 100. The Exposure dimension is inverted (higher exposure = lower score) because greater regulatory exposure with less preparation means lower readiness. The overall score is:

Overall = (100 โˆ’ Exposure) ร— 0.30 + Visibility ร— 0.25 + Governance ร— 0.25 + Compliance ร— 0.20

The result is rounded and clamped to 0โ€“100.

Readiness Levels

ScoreLevelMeaning
0โ€“25CriticalSignificant regulatory exposure with minimal preparation
26โ€“50At RiskGaps that need immediate attention before enforcement
51โ€“75In ProgressFoundation in place, but key gaps remain
76โ€“100Well PreparedStrong compliance posture, fine-tuning needed

Question-to-Article Mapping

QuestionDimensionRelevant Articles
Employee countExposureArticle 99 (penalty calculation based on turnover)
EU presenceExposureArticle 2 (territorial scope)
IndustryExposureAnnex III (high-risk use case categories)
AI tool countExposure / VisibilityArticle 49 (registration obligations)
Shadow AIVisibilityArticle 4 (AI literacy), Article 26 (deployer obligations)
Builds own AIExposureArticle 16 (provider obligations)
AI use casesExposureAnnex III Categories 1โ€“8
AI policyGovernanceArticle 4 (AI literacy)
AI inventoryVisibilityArticle 49 (EU database registration)
Governance ownershipGovernanceArticle 17 (quality management system)
Risk assessmentsGovernanceArticle 9 (risk management system)
Regulation awarenessComplianceArticle 4 (AI literacy)
Risk classificationComplianceArticle 6 (classification rules)
Technical documentationComplianceArticle 11, Annex IV
Conformity assessmentsComplianceArticle 43, Annex VI

Penalty Exposure Estimate

The penalty exposure shown in results is calculated using the maximum penalty tier from Article 99(3): 7% of global annual turnover, capped at โ‚ฌ35 million. The turnover is estimated from the employee count range selected. This is an approximation โ€” actual penalties depend on factors outlined in Article 99(7).

Risk Classification Wizard

The classifier follows the decision logic defined in the EU AI Act:

  1. Article 5 check โ€” Is the AI practice prohibited? If yes: Unacceptable Risk.
  2. Article 6(2) + Annex III check โ€” Does the AI system fall into an Annex III high-risk category AND make or influence decisions affecting individuals? If yes: High Risk. Critical infrastructure (Annex III Category 2) is high-risk regardless of whether it directly affects individuals.
  3. Article 6(1) check โ€” Is the AI system a safety component of a product covered by Annex I harmonisation legislation? If yes or unsure: High Risk.
  4. Annex III Category 1 check โ€” Is it a biometric identification or categorisation system? If yes: High Risk.
  5. Article 50 check โ€” Does the system interact with people or generate synthetic content? If yes: Limited Risk (transparency obligations).
  6. Default โ€” Minimal Risk. No mandatory obligations, voluntary codes of conduct encouraged (Article 95).

Annex III Categories Covered

CategoryDomainAnnex III Reference
1BiometricsAnnex III, Category 1
2Critical infrastructureAnnex III, Category 2
3Education and vocational trainingAnnex III, Category 3
4Employment, workers managementAnnex III, Category 4
5(a)Essential public services, healthcareAnnex III, Category 5(a)
5(b)Creditworthiness assessmentAnnex III, Category 5(b)
5(c)Life and health insuranceAnnex III, Category 5(c)
6Law enforcementAnnex III, Category 6
7Migration, asylum, border controlAnnex III, Category 7
8Administration of justiceAnnex III, Category 8

Article 5 Checker

The banned AI checker tests for all prohibited practices listed in Article 5(1) of the EU AI Act:

Penalty Calculator

The penalty calculator implements the three-tier structure from Article 99:

TierViolationMaximum PenaltyArticle
1Prohibited AI practicesโ‚ฌ35M or 7% of global turnoverArticle 99(3)
2High-risk system violationsโ‚ฌ15M or 3% of global turnoverArticle 99(4)
3Incorrect information to authoritiesโ‚ฌ7.5M or 1% of global turnoverArticle 99(5)

For SMEs and startups, the penalty is the lower of the fixed amount or the percentage of turnover (Article 99(6)). For large enterprises, it is the higher of the two.

EU AI Act Timeline

All enforcement dates shown in the timeline are from Article 113 of Regulation (EU) 2024/1689.

Data Privacy

Open Source

The scoring logic, classification rules, and question mappings described on this page are implemented exactly as documented. The assessment tool is built with React and TypeScript, and the complete source code is available for review.

Questions or feedback? If you believe any aspect of the methodology is incorrect or could be improved, we welcome feedback. Accuracy and transparency are our highest priorities.