EDIH, EEN, Interreg: the platform for European programmes.Find out more

AI Act Maturity · Compliance with the European AI Regulation (AI use in business)

Your AI uses classified, your AI Act maturity measured, your action plan costed.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

AI Act Maturity · Compliance with the European AI Regulation (AI use in business)

AI governance and rolesN1 → N5
AI systems inventoryN1 → N5
Risk level classificationN1 → N5
Risk management and data qualityN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

AI governance and roles6484
AI systems inventory5379
Risk level classification6182
Risk management and data quality3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • ANITI
  • CNRS
  • LIRMM
  • CNES
  • Docaposte
  • KPMG

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism, a level, a level above, and the action linking the two, is what turns a finding into a trajectory.

Are the AI systems used in the organisation mapped and qualified according to their risk level?

  1. N1

    No mapping. AI uses are known case by case, depending on who set them up.

  2. N2

    A list exists, built during a one off collection exercise. It covers IT led projects and does not mention a risk level.

  3. N3

    The inventory covers all entities, each system carries a risk qualification and an identified owner. Updates are regular.

  4. N4

    The inventory is fed by a mandatory declaration process at go live. Qualifications are validated by the governance body and logged.

  5. N5

    The inventory is periodically reviewed alongside functional and regulatory changes, with a history of reclassifications and their reasons.

Action to move from L2 to L3

Extend the collection exercise to tools introduced by business teams and AI features embedded in existing software, add an owner and a risk qualification to each line, and put the inventory review on the agenda of the quarterly data committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon AI ACT.

What this framework covers

Regulation (EU) 2024/1689, published in July 2024 and in force since 1 August 2024, classifies AI systems according to the risk they present: prohibited practices, high risk systems subject to a full set of requirements, systems with transparency obligations, and general purpose AI models with their own rules. It also distinguishes roles: provider, deployer, importer, distributor. For a company that buys and deploys AI rather than developing it, most obligations fall under the deployer status, with a possible shift to provider status in case of substantial modification or rebranding under its own name.

The difficulty is not reading the text, it is mapping it to real uses, often introduced by business teams without going through IT. How many AI systems are actually in production across your entities, and who keeps the inventory? Which ones fall under Annex III, particularly in HR, credit access or worker management? Who approves the rollout of a new use, and on what criteria? The answers are rarely centralised, and the scope shifts faster than the documentation.

One point of context is worth setting out. The timeline is staggered: prohibitions and AI literacy obligations applicable since February 2025, rules on general purpose models since August 2025, most requirements on high risk systems from August 2026, with a deferral for certain systems embedded in regulated products. Another common confusion: the AI Act does not replace or supersede the GDPR. The two texts apply together, and a fundamental rights impact assessment does not remove the need for a data protection impact assessment.

A compliance audit is binary: the obligation is met or it is not. The maturity assessment answers a different question. What level of control exists over the systems inventory, risk classification, human oversight, documentation or team training, and what specific action moves you up to the next level. This is the lens that lets you sequence a transformation programme across several entities, rather than tackling every gap at once.

In Datamensio, the framework is ready to use. You can also adapt it: the AI adjusts themes, questions and levels to your sector and your status under the regulation, or builds a variant from your internal policies and existing inventory of uses.

Reference standard: Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)

The themes assessed

  • AI governance and roles

    Decision making body, reporting line, roles and responsibilities, qualification of provider or deployer status for each system, internal AI use policy.

  • AI systems inventory

    Mapping of uses in production and in the pipeline, scope covered, information kept up to date, coverage of tools introduced by business teams and AI features embedded in off the shelf software.

  • Risk level classification

    Qualification method, identification of prohibited practices, review of Annex III cases, systems subject to transparency obligations, traceability and review of classification decisions.

  • Risk management and data quality

    Risk analysis per system, training and test datasets, representativeness, identified biases and corrective measures, expected robustness and accuracy.

  • Technical documentation and traceability

    Documentation required by role, provider instructions for use, event logging, retention period for records, elements available in case of a request from an authority.

  • Human oversight

    Effective human checkpoints, authority of the person in charge of oversight, ability to stop the system, actual competence and availability of overseers.

  • Transparency and information for individuals

    Information for people exposed to an AI system, labelling of generated content, information for workers and their representatives, explainability of individual decisions.

  • Supply chain and suppliers

    Contractual clauses with providers of systems and general purpose models, compliance elements obtained, technical dependencies, reversibility conditions.

  • Literacy and skills

    User awareness, training suited to the uses, internal skills in model evaluation, support arrangements for business teams.

  • Post deployment monitoring and incidents

    Monitoring of system behaviour in operation, drift detection, procedure for reporting and handling serious incidents, feedback loop to the provider and to governance.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Does this assessment make my organisation AI Act compliant?

No. It measures the maturity of your set up and identifies the gaps to address. Compliance is established against the regulation, system by system, and the demonstration relies on your own work and, where relevant, a conformity assessment. The assessment prepares and structures that path.

What is the difference between this maturity assessment and a compliance audit?

An audit concludes with a gap or a compliance finding on a given requirement. The assessment places your practices on a progressive scale and points to the action that moves you up a level. The two are complementary: the assessment sequences, the audit validates.

Is the framework meant for providers or users of AI systems?

It is built for organisations that deploy AI in their operations, deployer status under the regulation. The themes also cover situations where the status shifts to provider, common in cases of substantial modification or rebranding under one’s own name.

How long does the assessment take?

The short version takes 20 to 30 minutes to complete. The full version, run collaboratively, generally spans one to two weeks: most of the time goes into gathering input from business teams, legal and IT.

Can the framework be adapted to our context?

Yes. You can edit the questions, levels and themes, or start from a blank slate. The AI can also produce a sector specific variant from your internal policies. You keep full control of the framework.

How does this assessment fit with ISO/IEC 42001 and the GDPR?

ISO/IEC 42001 provides the management system that keeps obligations on track over time, the GDPR applies as soon as personal data is involved. A cross cutting roadmap consolidates all three assessments and avoids duplicating shared actions, particularly on governance and documentation.

Can several entities be compared with each other?

Yes. Assessments can be rolled out at scale across several business units, with benchmarking between entities and against previous rounds. The AI groups recurring gaps into a prioritised roadmap at group level.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurementon AI ACT.