EU AI Act (framework self-assessment) v0.1.0
framework-euaiact · 1 sections
Metadata
Scales, categories & audiences
Scales: maturity5 (5 levels) · Categories: scope transparency highrisk · Audiences: lead owner exec
Edit these in the raw JSON editor below — they change rarely and carry structure (levels, signals, deep-dive wiring) that a form would mangle.
EU AI Act elements core
Everyone answers these. Board or executive sponsor, legal and privacy (GDPR runs in parallel), procurement and contract owners, product or system owners who know where output is used, and the data governance lead.
| Id | Question | Type | Category | Scale | |
|---|---|---|---|---|---|
| euaiact-1 | Walk me through where AI is in use here, including tools your vendors supply. For each one, could anyone in the EU end up using what it produces, and did you build it or just use it? | scored_text · scored | scope | maturity5 | |
| euaiact-2 | Pick three AI systems you run. Which of the Act’s tiers is each in, who decided, and what did they write down? Is any of them used in employment, education, essential services, biometrics or law enforcement? | scored_text · scored | scope | maturity5 | |
| euaiact-3 | Does anything you run read people’s emotions, score them on behaviour, scrape faces from the web or generate images of real people? How would you know if a vendor tool started doing that? | scored_text · scored | scope | maturity5 | |
| euaiact-4 | When a customer chats with your bot or reads a summary your AI wrote, how do they find out it was AI? Who checked that last month, and against what? | scored_text · scored | transparency | maturity5 | |
| euaiact-5 | Which foundation models sit under your AI tools, and who supplies them? What have those providers actually given you in writing, and what does the contract say they must tell you when the model changes? | scored_text · scored | transparency | maturity5 | |
| euaiact-6 | For the system you would call highest risk, show me the risk list. When was it last updated, what changed, and who signed off the residual position? | scored_text · scored | highrisk | maturity5 | |
| euaiact-7 | What data did this system learn from or draw on, who owns it, and how did you satisfy yourself it reflects the people it will be used on? What happens when an error is found in it? | scored_text · scored | highrisk | maturity5 | |
| euaiact-8 | If a regulator asked you next week to explain what this system is and to show what it did on a given day last month, what would you hand over, and how long would it take to find? | scored_text · scored | highrisk | maturity5 | |
| euaiact-9 | For a high-risk system you supply or run, where are the instructions for use? Who wrote them, what do they say it must not be used for, and when did they last change? | scored_text · scored | highrisk | maturity5 | |
| euaiact-10 | When this system gets it wrong, who notices, how fast, and what can they actually do about it? Has anyone ever overridden it, and is that written down? | scored_text · scored | highrisk | maturity5 | |
| euaiact-11 | How accurate is this system, how do you know, and what happens to that number when the inputs get strange or someone tries to game it? When was it last tested? | scored_text · scored | highrisk | maturity5 | |
| euaiact-12 | Which of your systems will need a conformity assessment and CE mark before Dec 2027 or Aug 2028? Who owns that plan, and what would tell you after go-live that something has gone wrong? | scored_text · scored | highrisk | maturity5 |
+ Add question to “EU AI Act elements”
Add section
Advanced — raw JSON
Full pack document, validated on save (schema yarn-pack/2). This is where scales, audiences, structured conditions and adaptive config live.