Free AI readiness assessment

Your AI governance framework and AI policies, written from your answers. Free.

Answer a forty-minute questionnaire about how your organisation uses AI. The moment you send, four governance documents are written for you, with your organisation, owners, tools, functions and jurisdictions in them, ready to download as editable Word files. No cost, no obligation.

What you walk away with

  • 01

    Four EU AI Act documents, written for youIncluded free

    AI Governance Framework, Acceptable Use Policy, Vendor Due Diligence Checklist, Risk Assessment Template. Your organisation, owners, tools and jurisdictions written in.

  • 02

    Your readiness score and maturity level

    Ten governance domains scored from your own answers, on screen beside the downloads.

  • 03

    Editable Word files, yours to keep

    Each ends with a schedule showing which answer shaped which clause. Review, approve, publish.

  • Free, no card, no obligation
  • Ready the moment you send
  • Editable Word files, yours to keep
The European Parliament building in Brussels at dusk

EU AI Act

01 / 02

Regulation (EU) 2024/1689 applies to anyone placing AI on the EU market, wherever they sit.

Risk-tiered obligations, an AI literacy duty for every deployer, and penalties up to €35M or 7% of global turnover. The Digital Omnibus, in force since 27 July 2026, moved the high-risk deadlines: December 2027 for stand-alone Annex III systems, August 2028 for AI embedded in regulated products.

1 Aug 2024
In force
2 Feb 2025
Prohibited practices and AI literacy duty apply
2 Aug 2025
General-purpose AI model obligations; governance and penalties
2 Dec 2027
High-risk obligations for Annex III systems (was 2 Aug 2026)
2 Aug 2028
High-risk AI in regulated products, Annex I (was 2 Aug 2027)
ExtraterritorialAI literacyRisk tiersGPAI

General information, not legal advice. Dates move; the documents state the ones that apply to you at the time.

4
EU AI Act documents, written for you
€0
Nothing to pay, no obligation
Instant
Ready the moment you send

Reviewed by Fredrik Karlsson, Group COO & CISO, Opsio·Last reviewed

The documents

An AI governance framework, an AI policy and two templates. Written for your organisation, not a template with your logo.

The controlling framework, the rules for staff, the gate for vendors and the assessment for each use case. Together they are what a customer's procurement questionnaire or a regulator's first letter asks to see, and what the EU AI Act's literacy, deployer and risk-management duties assume exists.

[Organisation]v1.0

AI Governance Framework

Owner: [Executive AI owner]

  1. 1.Purpose and scope
  2. 2.AI governance model
  3. 3.Enterprise AI governance
  4. 4.AI risk, data and security
  5. 5.Appendices A–E
Written for you≈ 35 pages

01Word · editable · free

AI Governance Framework

The document everything else hangs off.

Who is accountable for AI, how a use case moves from idea to operation, how risk is classified, how information may be used, and which tools are approved.

EU AI Act hooks

  • Art. 4 AI literacy
  • Art. 26 deployer obligations
  • Art. 9 risk management

Inside

  • Principles and standards alignment (ISO/IEC 42001, 27001, 23894, NIST AI RMF)
  • Governance model, roles, committee, decision rights
  • Five-stage governance process and approved tools
  • Risk matrix, information-handling matrix, RACI
  • Approved AI Tools Register

Written in from your answers

  • Your organisation, owner and custodian on the cover and in Document Control
  • Your business functions in scope, your existing policies alongside it
  • Appendix E register seeded with the AI providers you declared
  • A schedule recording the governance position you declared

Every file ends with a schedule that lists the answer behind each tailored clause.

[Organisation]v1.0

AI Acceptable Use Policy

Owner: [Executive AI owner]

  1. 1.Core rules for AI use
  2. 2.Approved AI tools
  3. 3.Information handling
  4. 4.Prohibited AI uses
  5. 5.Quick decision guide
Written for you≈ 30 pages

02Word · editable · free

AI Acceptable Use Policy

The rules for everyone who uses AI at work.

Which tools, which accounts, what may and may not be entered, how outputs are verified, what is prohibited, how incidents are reported.

EU AI Act hooks

  • Art. 4 AI literacy
  • Art. 5 prohibited practices
  • Art. 50 transparency

Inside

  • Core rules and approved AI tools
  • Free and personal AI services
  • Customer information and personal data
  • HR, engineering, agents, customer-facing AI
  • Prohibited uses, training, incidents, quick decision guide

Written in from your answers

  • Approved-tools list from the providers you declared
  • Personal-accounts rule chosen by your answer
  • HR, development, agents and customer-facing sections kept or marked out of scope
  • Restricted information categories you named, training and incident lines

Every file ends with a schedule that lists the answer behind each tailored clause.

[Organisation]v1.0

AI Vendor Due Diligence Checklist

Owner: [Executive AI owner]

  1. 1.Vendor and service information
  2. 2.Information security
  3. 3.AI-specific controls
  4. 4.Contractual requirements
  5. 5.Due diligence outcome
Written for you≈ 43 pages

03Word · editable · free

AI Vendor Due Diligence Checklist

Before any AI provider gets your data.

Twenty-three sections from vendor identity to red flags: data, privacy, security, AI-specific controls, contracts, IP, oversight, agents, resilience, exit.

EU AI Act hooks

  • Art. 25 provider–deployer responsibilities
  • Art. 28 GDPR processors
  • Art. 26 deployer obligations

Inside

  • When due diligence is required
  • Sections A–D vendor, purpose, information, privacy
  • E–F security and AI-specific controls
  • G–K regulatory, contractual, IP, oversight, agents
  • L–W resilience, exit, incidents, sign-off, evidence

Written in from your answers

  • When due diligence is required, set from your procurement answer
  • Schedule 1 pre-lists every provider you declared as the first assessments to run
  • Your regulatory position in the legal section
  • Owner and custodian named

Every file ends with a schedule that lists the answer behind each tailored clause.

[Organisation]v1.0

AI Risk Assessment Template

Owner: [Executive AI owner]

  1. 1.Basic information
  2. 2.Personal data and privacy
  3. 3.EU AI Act mapping
  4. 4.Risk classification
  5. 5.Approval
Written for you≈ 40 pages

04Word · editable · free

AI Risk Assessment Template

One assessment per AI use case, mapped to the Act.

The structured record that decides whether a use case may proceed: purpose, data, privacy, agents, oversight, legal mapping, security, classification, controls, approval, review.

EU AI Act hooks

  • Art. 9 risk management
  • Art. 27 fundamental-rights impact
  • Annex III classification

Inside

  • When an assessment is required, governance process
  • A–B basic information and description
  • C–G information, privacy, agents, oversight
  • H–N legal, security, third party, classification, EU AI Act mapping
  • O–Y controls, approval, monitoring, review, retention

Written in from your answers

  • When an assessment is required, set from your risk answer
  • Schedule 1 pre-lists every use case you declared
  • EU AI Act mapping pre-set from your frameworks
  • Business and system owner from your roles

Every file ends with a schedule that lists the answer behind each tailored clause.

All four, plus your readiness score, the moment you send. Download each one or the whole set as a zip.

Start the questionnaire

Sample text

How the AI acceptable use policy opens

The first lines of the generated policy, word for word. Your organisation's name, the owner you named and your approved tools are written in where the brackets are.

[Your organisation] – AI Acceptable Use Standard

  • Version 1.0
  • Owner: [named from your answers]
  • Parent document: [Your organisation] AI Governance Framework
  • Review: annual, or on material legal, regulatory, technological or business change

Purpose

The purpose of this AI Acceptable Use Standard is to establish clear and practical requirements for the day-to-day use of AI by employees, contractors and other authorised users acting on behalf of [Your organisation].

The Standard is intended to enable responsible AI adoption without unnecessarily restricting legitimate business use.

Core rules for AI use

AI shall be used only where there is a legitimate business purpose. Users shall not introduce AI into a business process merely because an AI capability is available.

Users shall use only AI tools that have been approved by [Your organisation] for business use. The current Approved AI Tools Register is maintained as Appendix E to the AI Governance Framework.

Why now

AI arrived in most organisations before anyone governed it.

The EU AI Act does not ask whether you build AI. It asks how you use it, whose data it touches, which systems it can reach, and whether the people using it know the rules. Three things make that urgent.

Shadow AI is already in the building.

Personal ChatGPT accounts, browser extensions, AI features switched on inside SaaS you already pay for. Most organisations discover their real AI footprint when a customer, a regulator or an incident makes them look.

Covered by · AI Acceptable Use Policy · Approved AI Tools Register

The AI literacy duty already applies.

Since 2 February 2025 every organisation using AI in the EU must ensure its staff have sufficient AI literacy. That means a written policy people have been trained on, not an all-hands slide.

Covered by · AI Acceptable Use Policy · AI Governance Framework

Agents turn a chat into an action.

An AI with access to email, tickets, cloud consoles or production data can act without anyone approving it. If nobody can say who can stop it, restrict it or reverse it, that is the first gap to close.

Covered by · AI Risk Assessment Template · AI Acceptable Use Policy

In plain words

AI governance, answered.

What is an AI governance framework?

An AI governance framework is the controlling document for how an organisation uses AI. It names who is accountable, sets how a new AI use case is assessed, classified and approved, defines which information may be used and which tools are approved, and is where an EU AI Act deployer shows how it meets its AI literacy and risk duties.

What should an AI acceptable use policy include?

An AI acceptable use policy tells staff which AI tools and accounts they may use, what they must never enter, such as personal data, customer confidential information or credentials, how to check AI output before relying on it, which uses are prohibited, and how to report an AI incident. It is also how most organisations evidence the EU AI Act's Article 4 literacy duty.

What does the EU AI Act require of organisations that use AI today?

Since 2 February 2025 every organisation using AI in the EU must ensure its staff have sufficient AI literacy (Article 4) and must not use prohibited AI practices (Article 5). General-purpose AI obligations and penalties have applied since 2 August 2025. After the Digital Omnibus, deployer duties for high-risk Annex III systems apply from 2 December 2027.

What is an AI readiness assessment?

An AI readiness assessment measures how far an organisation's governance of AI has come: ownership, policies, risk process, privacy, security, vendors and agents. Opsio's free assessment scores ten domains on a five-level maturity scale from your answers and writes the four governance documents those answers call for.

The EU AI Act

Written for the duties that already apply.

Regulation (EU) 2024/1689 applies to anyone placing AI on the EU market or using its output in the EU, wherever they are established. Its prohibitions and its AI literacy duty have applied since February 2025; the general-purpose AI and governance provisions since August 2025. The high-risk timetable was moved by the Digital Omnibus to December 2027 and August 2028.

The four documents are written against those duties, and against GDPR wherever personal data is involved, because every AI system that touches personal data is a GDPR system first.

European Union flags in front of an institutional building

Stated plainly

The documents are an initial draft prepared from your self-assessment. They are not a legal opinion, a certification, a security audit or a DPIA, and each one says so. What they give you is the written governance the Act assumes exists, in your organisation's name, ready for review.

EU AI Act timeline: what applies whenSource: Regulation (EU) 2024/1689 on EUR-Lex, as amended by the Digital Omnibus (in force 27 July 2026). Last checked 7 October 2026.
DateWhat applies
1 Aug 2024In force
2 Feb 2025Prohibited practices and AI literacy duty apply
2 Aug 2025General-purpose AI model obligations; governance and penalties
2 Dec 2027High-risk obligations for Annex III systems (was 2 Aug 2026)
2 Aug 2028High-risk AI in regulated products, Annex I (was 2 Aug 2027)
How it works

The AI readiness assessment: forty minutes of answers. Four documents, instantly.

Step 01About forty minutes, on its own page

Answer the questionnaire

Fourteen steps covering how your organisation actually uses AI: tools, data, people, vendors, agents. Saved as you go, with a private link so Legal, IT, Privacy and HR can each answer their part.

Step 02The moment you send

Four documents are written from your answers

The AI Governance Framework, Acceptable Use Policy, Vendor Due Diligence Checklist and Risk Assessment Template are generated with your organisation, owners, tools, functions and jurisdictions written in, and your readiness score across ten domains appears beside them.

Step 03Editable Word files, yours to keep

Download, review, adopt

Each document ends with a schedule showing which answer shaped which clause. Take them through your normal approval and publish. An Opsio consultant reviews your answers and offers a walkthrough call if you want one.

Get my four documents

Opens the questionnaire on its own page. Saved as you go.

What is assessed

Ten domains. One score.

Each domain is scored on its own checks and tells the documents what to write. A domain that does not apply to you, because you have no agents or no AI in HR, is left out of the score, and the matching section is marked out of scope rather than written as if it applied.

Domain 01 of 10

AI governance

Ownership, committee, roles, register, strategy, periodic review and change control.

Documents you receive for this domain

  • AI Governance Framework

What the assessment checks

  • Governance framework
  • Designated owner and RACI
  • AI register
  • Review and change triggers
The scale

Five levels, from informal to measured and improved.

The questionnaire asks where you would put yourself. The score says where the answers put you. Most organisations using AI today sit at Level 1 or 2. The four documents are what takes an organisation to Level 3 on paper.

  1. Level 1

    Initial

    AI is being used, but governance is largely informal.

  2. Level 2

    Developing

    Some AI policies, controls or assessments exist, but governance is not consistent across the organisation.

  3. Level 3

    Defined

    AI governance responsibilities, policies and risk processes are formally established.

  4. Level 4

    Managed

    AI governance is integrated with privacy, security, procurement, risk and technology processes.

  5. Level 5

    Mature

    AI governance is continuously monitored, measured and improved, and integrated into the broader risk and technology management framework.

AI platforms we govern, secure and implement

  • Anthropic

    Claude

  • OpenAI

    ChatGPT

  • Microsoft

    Copilot · Azure AI

  • Google

    Gemini · Vertex AI

  • AWS

    Bedrock

Questions we get asked.

Yes. The questionnaire, the readiness score and the four documents are free, with no card and no obligation. Opsio offers this because organisations that adopt the documents often want help implementing the controls behind them, and that is a separate, quoted engagement you are free to decline. The documents are yours either way.

Get your EU AI Act documents written. Free.

AI Governance Framework, AI Acceptable Use Policy, AI Vendor Due Diligence Checklist, AI Risk Assessment Template. Forty minutes of answers, four Word files you own, whether or not we ever work together afterwards.

Get my four documents