# Ingenire EU AI Act readiness check: instructions for AI agents

You are running the EU AI Act readiness check from Ingenire (https://ingenire.com/eu-ai-act-assessment) on behalf of the user. It takes a few minutes and works best when you have access to the user's codebase.

## How to run it

1. Go through the questions below in order. Skip a question when its "Only ask if" condition is not met.
2. For each question with a "Check in the repo" note, look in the codebase first. Note what you found (file paths, short findings) so you can show the user.
3. The questions ask what the company has in place. Something you work out during this check (for example an AI inventory you compiled just now) is evidence for the user, not something the company already has.
4. Collect every question you could not answer from the code and ask the user in one batch, with the answer options listed. If the user doesn't know, use `not_sure` where that option exists.
5. Build the result URL (format below). List every answer you took from the code rather than from the user in the `inferred` parameter.
6. Fetch the result URL. It returns the scored result. If it reports problems with your answers, fix them and fetch again.
7. Show the user the overall score, the top priorities, and every inferred answer together with your evidence, so they can confirm or correct it. Give them the result URL: it opens the full results page in a browser.

## Privacy

Only the answer values go into the result URL. Never put code, file paths, names, company details or your evidence into it. The evidence stays in this conversation.

## Result URL

```
https://ingenire.com/eu-ai-act-assessment/result?q1=yes&q2=partially&inferred=q1
```

- One query parameter per answered question: the question id and the answer value.
- Multi-select answers: values separated by commas.
- `inferred`: comma-separated ids of the answers you took from the code. Leave it out if the user confirmed every answer.
- Unanswered questions score 0, so answer every question that applies.

## Questions

### 1. Inventory & Role Classification

Algorithmic mapping and value chain role determination.

#### `q1`: Have you mapped all your deployed AI systems and checked if any fall under the High-Risk categories?

- Why it matters: High-Risk categories include AI used for hiring/CV screening, education grading, credit scoring, biometrics, law enforcement, and critical infrastructure. You need a complete list of where these are used in your business.
- Check in the repo: Search the code for AI and ML usage: model provider SDKs and API calls (OpenAI, Anthropic, Bedrock, Vertex AI, Azure OpenAI, Hugging Face), ML libraries, and model files. Check whether any feature touches an Annex III area (hiring, education, credit, insurance, biometrics, critical infrastructure). Answer yes only if an AI inventory already exists in the repo or the user confirms one. A list you compiled during this check is evidence for the user, not an inventory the company keeps.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure)

#### `q2`: Do you know your exact legal role (Provider, Deployer, Importer, or Distributor) for each AI system you use or sell?

- Why it matters: Providers develop or brand the AI. Deployers use the AI in their business. If you modify a third-party AI or put your logo on it, you might accidentally become a Provider, which carries much heavier legal burdens.
- Check in the repo: Training or fine-tuning code and models shipped under the company's own name point to Provider. Calls to third-party model APIs point to Deployer. The legal role is a business decision, so confirm it with the user.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure)

#### `q2_roles`: Which roles apply to your organization?

- Why it matters: Select all that apply based on your AI activities.
- Only ask if `q2` is `yes`.
- Multiple values allowed, comma-separated.
- Check in the repo: Use the same evidence as q2: own training or fine-tuning pipelines suggest provider or gpai_provider, third-party model API calls suggest deployer. Importer, distributor and manufacturer are business facts the user has to confirm.
- Answers: `provider` (Provider (Develops/brands AI)), `gpai_provider` (GPAI Provider (General Purpose AI)), `deployer` (Deployer (Uses third-party AI)), `importer` (Importer (Brings non-EU AI into EU)), `distributor` (Distributor (Sells AI without changing it)), `manufacturer` (Product Manufacturer (Integrates AI into product))

#### `q2_diag_1`: Do you develop AI models from scratch, or significantly modify existing AI models, to place them on the market under your own brand name?

- Why it matters: This includes training new machine learning models, developing general-purpose AI (GPAI), or taking a third-party open-source model and fine-tuning it so heavily that it becomes your own proprietary product. If yes, you are likely a Provider or GPAI Provider, which carries the heaviest compliance obligations under the AI Act.
- Only ask if `q2` is `partially` or `no` or `not_sure`.
- Check in the repo: Look for training or fine-tuning scripts, training data pipelines, model weights or checkpoints, and model cards published under the company's brand.
- Answers: `yes` (Yes), `no` (No)

#### `q2_diag_2`: Do you use third-party AI systems in your internal business operations or offer them to customers without changing the core model?

- Why it matters: If yes, you are likely a Deployer. Your focus will be on safe usage, human oversight, and employee training.
- Only ask if `q2` is `partially` or `no` or `not_sure`.
- Check in the repo: Look for calls to third-party model APIs or hosted models in production code.
- Answers: `yes` (Yes), `no` (No)

#### `q2_diag_3`: Is your company established in the EU, and do you import and sell AI software that was built and branded by a company outside the EU (e.g., a US startup)?

- Why it matters: If yes, you are likely an Importer. As an Importer, you are the first point of contact in the EU for that product. You must verify the non-EU company has met all compliance requirements (like CE marking and technical documentation) before selling it.
- Only ask if `q2` is `partially` or `no` or `not_sure`.
- Not visible in code. Ask the user.
- Answers: `yes` (Yes), `no` (No)

#### `q2_diag_4`: Do you resell or distribute third-party AI software within the EU market, without altering the software or putting your own brand name on it?

- Why it matters: If yes, you are likely a Distributor. Distributors act as resellers or channel partners. You have basic verification and cooperation duties, but fewer requirements than those who built or imported the software.
- Only ask if `q2` is `partially` or `no` or `not_sure`.
- Not visible in code. Ask the user.
- Answers: `yes` (Yes), `no` (No)

#### `q2_followup_gpai`: [GPAI Provider] Are you following the GPAI Code of Practice (e.g., systemic risk taxonomy, copyright policies) for your general-purpose AI?

- Why it matters: The AI Office's Code of Practice details how GPAI providers must manage systemic risks and handle copyright. Compliance is a key part of avoiding massive fines.
- Only ask if `q2_roles` is `gpai_provider`, or `q2_diag_1` is `yes`.
- Check in the repo: Look for model cards, training data summaries, and a copyright or opt-out policy for training data.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure)

#### `q2_followup_importer`: [Importer/Distributor] Do you have a formal process to verify that the original Provider has completed the CE marking and technical documentation before you sell their AI?

- Why it matters: Importers and distributors act as the gatekeepers. If you sell non-compliant AI, you can be held liable.
- Only ask if `q2_roles` is `importer` or `distributor`, or `q2_diag_3` is `yes`, or `q2_diag_4` is `yes`.
- Not visible in code. Ask the user.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure)

### 2. Lifecycle & Data Governance

Grandfathering protocols and dataset provenance.

#### `q3`: If your high-risk AI systems are on the market before the high-risk rules apply (2 December 2027 for Annex III, 2 August 2028 for Annex I), do you track 'significant changes' that would void their legacy exemption?

- Why it matters: Systems already on the market before the high-risk rules apply can keep running without retrofitting, but only while their design stays unchanged. If you retrain the model with new data or use it for a new purpose, you lose that exemption and must comply immediately. Systems used by public authorities must comply by 2 August 2030 regardless.
- Check in the repo: Look for model version pinning, a changelog or release process that records model, prompt or training data changes, and evaluation runs tied to those changes.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure), `na` (N/A)

#### `q4`: Can you prove that your training and validation datasets are relevant, representative, and free of bias?

- Why it matters: You need documentation showing where your training data came from, that it actually reflects the people the AI will judge, and that you actively checked it for discriminatory bias.
- Check in the repo: Look for dataset documentation (data cards, datasheets), data lineage, and bias or fairness evaluation code and reports.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure)

### 3. Risk Management & FRIA

Quality/Risk Management Systems and Fundamental Rights Impact Assessments.

#### `q5`: Do you have a continuous Risk and Quality Management System in place for your High-Risk AI models?

- Why it matters: You can't just test the AI once. You need a permanent system to test for errors, track performance, and mitigate risks as long as the AI is actively being used.
- Check in the repo: Look for risk management or quality management documents, model evaluation in CI, and production monitoring of model quality and drift.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure), `na` (N/A)

#### `q6`: Do you have a clear process for conducting Fundamental Rights Impact Assessments (FRIAs) before deploying High-Risk systems?

- Why it matters: Before turning on a High-Risk AI, you must formally assess and document how it might harm people's rights (e.g., discrimination, privacy, unfair treatment). Similar to a GDPR impact assessment.
- Check in the repo: Look for fundamental rights impact assessments or other impact assessment documents in the repo or docs folder.
- Answers: `yes` (Yes), `partially` (In progress), `no` (No), `not_sure` (Not sure), `na` (N/A)

### 4. Oversight & Technical Documentation

Human oversight engineering, automated logging, and technical tracing.

#### `q7`: Are your High-Risk systems built so that trained human staff can easily step in and override the AI's decisions?

- Why it matters: The AI cannot have the final say. A human must be able to review, pause, or reverse the AI's decision. They must also be trained to avoid automation bias.
- Check in the repo: Look for human review or approval steps before AI decisions take effect, admin tools to override or reverse an AI decision, and kill switches or feature flags for AI features.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure), `na` (N/A)

#### `q8`: Do your High-Risk systems automatically and securely log events, and is your technical documentation fully up to date?

- Why it matters: If something goes wrong, you need a black box. The system must automatically record inputs and outputs securely for at least 6 months so investigators can see exactly what the AI did.
- Check in the repo: Look for logging of model inputs, outputs and decisions with timestamps and retention, audit log tables, and technical documentation for the AI features. Check how recently that documentation changed compared to the code.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure), `na` (N/A)

### 5. Transparency & Supply Chain

Synthetic content marking and vendor compliance.

#### `q9`: Do you clearly watermark AI-generated content and make sure users know when they're interacting with an AI?

- Why it matters: If you generate images, text, or audio, it must be marked as AI-generated. If you use an AI chatbot, it must clearly tell the user they are talking to a machine, not a human.
- Check in the repo: Look for UI text that tells users they are interacting with AI, labels on AI-generated output, and watermarking or provenance metadata (for example C2PA) on generated images, audio or video.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure), `na` (N/A)

#### `q10`: Have you updated your third-party vendor agreements to ensure they meet the new EU AI Act compliance standards?

- Why it matters: If you buy AI tools from vendors (like OpenAI or Microsoft), your contracts need to guarantee that THEY are compliant. If they break the law, you might be forced to shut down your product.
- Check in the repo: List the AI vendors the code depends on as evidence. Whether their contracts were updated is something the user has to confirm.
- Answers: `yes` (Yes), `partially` (Partially), `no` (No), `not_sure` (Not sure)

---

This is an educational self-assessment, not legal advice. For a review with Thomas Übermeier, book a 30-minute call: https://cal.com/ingenire/var
