You are the MD. Somewhere in the business, people are using AI — the subscriptions you approved, and the ones you didn't. The EU AI Act doesn't care where you're registered; it cares where your market is, and key obligations have already been in force since February 2025. If a customer, an insurer or a regulator asked tomorrow, could you evidence where you stand?

For most UK and Irish firms the honest answer is no. Not because anyone's negligent — because nobody has asked the questions in order. This checklist does. It's the self-audit layer of our full guide to the EU AI Act for UK and Irish businesses: twelve questions covering inventory, risk, obligations and readiness. Answer them in one sitting, write down the answers, and you'll know your position before year end.

This isn't legal advice — we work alongside your legal counsel, not instead of them. It's the diagnostic a busy MD can actually run.

The 12 questions

Four groups of three. Tick yes or no for each — gut answers count, and a hesitant yes is a no. The groups run in order: you can't classify what you haven't inventoried, and you can't govern what you haven't classified.

A. Know what you run

Inventory — the foundation every other question stands on

Can you list every AI system your business uses, including tools teams signed up for themselves?

Do you know which systems you provide vs deploy under the Act — and what each role requires?

Do you have that list written down somewhere other than someone's head?

B. Know your risk

Classification — which obligations attach, and to what

Has every system on that list been classified against the Act's risk tiers?

Do you know which of your systems touch hiring, credit, education or essential services (the high-stakes list)?

If a customer or regulator asked tomorrow, could you evidence the classification — not just assert it?

C. Know your obligations

Literacy & documentation — the duties already in force

Can you show that staff using AI have had AI literacy training (an obligation since Feb 2025)?

Do you have logging and record-keeping for the AI systems that matter?

Does someone in the business hold named accountability for AI governance?

D. Know your plan

Readiness — turning findings into a sequenced response

Do you know which AI Act deadlines already apply to you — and which land in the next 12 months?

Do you have a prioritised remediation plan rather than a vague intention to "look at it"?

Could you brief your board on your AI Act position in five minutes, with evidence?

Want it on paper?

Get the downloadable version of this checklist — the twelve questions with space for notes, yours to keep and reuse each quarter. Print it, run it with your leadership team, keep it in the compliance file.

One email, no list spamming. The checklist is also available co-branded for partners and advisers — ask us.

How to score yourself

Count your yeses. The bands are blunt on purpose — precision here is false comfort.

10–12 yes — in decent shape

You can evidence most of what the Act asks. Keep the list current, diarise the deadlines that land next, and get back to running the business.

6–9 yes — exposed

The gaps are real but fixable, and now they're written down — which is the first fix. Sequence them: inventory first, classification second, everything else follows.

0–5 yes — you are the typical UK SME

Most firms sit here. It's not a verdict, it's a starting position — and the Act's deadlines don't care how typical you are. The good news: the first three questions fix more than half the exposure.

Dry reassurance where it's earned: nothing here is unfixable, and none of it requires ripping out tools your teams rely on. Not sure of some answers? Take the AI Act quiz (2 min) — it approaches the same ground from the risk side.

Every "no" is a gap with a fix attached. AI Act Readiness closes them in weeks, not quarters — find every system, classify it, govern it.

Close the gaps — AI Act Readiness

What each group actually tests

A — Inventory: you can't comply with what you can't see

Most firms can name two or three AI tools and are running a dozen. The undeclared ones — the browser extensions, the free tiers, the sales team's favourite — are your biggest exposure, because they carry obligations nobody is tracking. Questions 1–3 test whether the business has a written, complete AI inventory: the register every other obligation depends on. If the answer to question 3 is "it's in Dave's head," you've found finding number one.

B — Classification: obligations follow the risk tier

The Act doesn't treat all AI alike — obligations attach by risk class, and by whether you provide the system or deploy it. Questions 4–6 test whether classification has actually happened, and whether it's evidenced: a classification you can't show a regulator is a classification you don't have. The four risk classes in plain English is the companion read — most business SaaS lands lower than people fear, which is exactly why guessing is the wrong move.

C — Obligations: the duties that already apply

This is the group where "we'll deal with it next year" is already late. AI literacy training has been an obligation since February 2025 — not a nice-to-have, a duty, and most SMEs have missed it. Questions 7–9 test AI literacy, logging and record-keeping for the systems that matter, and whether someone owns AI governance by name. "The whole leadership team" is the same as nobody.

D — Readiness: deadlines don't negotiate

Knowing your gaps is table stakes; questions 10–12 test whether there's a plan with an order to it and a named owner, and whether the board could be briefed in five minutes with evidence. A prioritised plan beats a perfect one that doesn't exist.

Why "before year end" is not marketing

Two reasons, both boring and both real. First, the timetable: prohibitions and AI literacy duties have applied since February 2025, further obligations landed through 2026, and the final tranche — including AI embedded in regulated products — arrives in August 2027. Each tranche that passes converts "upcoming" into "in force," and the full deadline timeline is shorter than most boards assume.

Second, the calendar: Q4 is when boards ask. Budget setting, insurer renewals, customer due-diligence questionnaires — all of them increasingly include the same question about AI governance, and "we're looking into it" is not an answer that survives contact with a procurement team. Walking into that season knowing your position — with the checklist to prove it — is simply cheaper than the alternative.

Mostly no's? Here's the fix

The checklist diagnoses; it doesn't treat. Treatment is AI Act Readiness: the Shadow AI Audit finds every system including the ones nobody declared, the Readiness Diagnostic classifies them and produces a prioritised, fixed-price plan in two weeks, and the Literacy Training track closes the February 2025 obligation with attendance records for your compliance file. Weeks, not quarters — and you keep every artefact, whoever you use to act on them.

Run the checklist once, honestly, and you'll know exactly which of those you need. That's the whole point.