Regulation (EU) 2024/1689
EU AI Act readiness assessment
Turn EU AI Act obligations into evidence you can show a regulator.
An obligation library (33) addressing EU AI Act requirements for high-risk and GPAI obligations.
33 obligation entries · versioned & change-controlled
Who it’s for
Providers and deployers of AI systems in scope for the EU AI Act — especially high-risk and general-purpose AI obligations.
What readiness means for EU AI Act
For the EU AI Act, readiness means each applicable obligation is evidenced — risk-management system, data governance, human oversight, technical documentation and post-market monitoring.
How Netallion handles it
Your EU AI Act readiness journey
- 1
Determine role & applicability
Establish your role — provider or deployer — and whether a system is high-risk or a general-purpose AI model, so only the obligations that actually apply are scoped.
- 2
Map evidence to obligations
Attach the risk-management system, data-governance records, technical documentation and oversight measures to the obligations they support, with ownership and review dates.
- 3
Assess evidence
Each obligation is assessed for whether the evidence demonstrates it in operation — human oversight actually implemented, post-market monitoring actually running — not merely described in a document.
- 4
Surface blockers
Obligations with missing or stale evidence — a described risk-management system with no post-market monitoring, technical docs missing required elements — become explicit, ranked blockers.
- 5
Review & finalise
An authorised assessor reviews the determinations and pins a readiness conclusion; conformity is established through conformity assessment, not issued by Netallion.
The control library
What the EU AI Act library gives you
An obligation library (33) addressing EU AI Act requirements for high-risk and GPAI obligations.
A curated, versioned catalogue of this framework’s 33 obligation entries — with provenance — to collect, own, organise and track the currency of your evidence against.
From the field
Common EU AI Act blockers we find
Where evidence most often falls short — surfaced explicitly, not averaged away.
- A risk-management system is described but post-market monitoring is unevidenced, so the lifecycle obligation stops at deployment.
- Technical documentation exists but omits required elements such as the data-governance description, so the package is incomplete.
- Human oversight is designed on paper but there is no evidence operators are trained or that oversight actually intervenes.
- The organisation acts as a deployer but has scoped obligations as a provider, leaving deployer-specific duties unaddressed.
Evidence
The evidence you'll bring
You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:
Risk management
- risk-management system across the lifecycle
- risk identification & mitigation records
- residual-risk decisions
- testing against intended purpose
Data & documentation
- data-governance & dataset-quality records
- technical documentation package
- instructions for use
- logging/record-keeping capability evidence
Human oversight
- human-oversight design & measures
- operator competence & training
- accuracy/robustness/cybersecurity evidence
- transparency information to deployers
Monitoring
- post-market monitoring plan & records
- serious-incident reporting procedure
- GPAI model documentation (where applicable)
- conformity-assessment & registration records
Start now — free
Prepare your EU AI Act evidence
Assess your EU AI Act evidence with Netallion
There’s no self-serve kit for EU AI Act yet. On an assessed engagement, Netallion scopes the requirements, organises your evidence, and determines readiness with explicit blockers.
From evidence to a conclusion
How readiness is reached
The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.
- 1Scope
The applicable requirement set for your framework and scope.
- 2Applicable requirements
A fixed denominator — every in-scope requirement counts.
- 3Evidence
You attach and own evidence; ownership and expiry are tracked.
- 4Evidence assessment
The evidence is read against each requirement for sufficiency.
- 5Determination
A requirement-level verdict with byte-verified citations.
- 6Blocker
Negative findings surface as explicit blockers, not averages.
- 7Remediation
Track the fix; reassessment — not a checkbox — resolves it.
- 8Review (R0–R3)
Controlled human review with recorded provenance.
- 9Finalisation
A signed, scope-pinned readiness conclusion.
- 10Report / export
Readiness report, evidence index, SoA, audit ZIP + SHA-256.
- 11Lifecycle & reassessment
Evidence expires/changes → affected requirements reopen.
Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.
What you get out
- Requirement-level readiness across the 33 EU AI Act obligations scoped to your role
- provider/deployer and high-risk/GPAI applicability view
- explicit blocker list with reasons
- evidence index + audit ZIP with SHA-256 manifest
FAQ
EU AI Act readiness — common questions
Does Netallion provide EU AI Act conformity?
No. EU AI Act conformity is established through conformity assessment, with notified-body involvement where the Act requires it. Netallion assesses your readiness against the Act's obligations (33 criteria).
Which obligations does Netallion cover?
The obligation library addresses high-risk and general-purpose-AI requirements — risk management, data governance, human oversight, documentation and monitoring.
How does it relate to GDPR and the NIST AI RMF?
AI systems processing personal data also carry GDPR obligations, and the NIST AI RMF covers overlapping governance ground; all three are supported and linked.
Related
Cross-framework leverage
Evidence you assemble for one framework often supports another. Commonly paired with:
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. EU AI Act conformity is established through conformity assessment (with notified-body involvement where the Act requires it), overseen by the competent authorities. Where the boundary sits.
See what your EU AI Act evidence proves
See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.