Your AI governance framework and AI policies, written from your answers. Free.
This free AI readiness assessment is a forty-minute questionnaire about how your organisation uses AI. The moment you send, four governance documents are written for you, with your organisation, owners, tools, functions and jurisdictions in them, ready to download as editable Word files. No cost, no obligation.
What you walk away with
01
Four EU AI Act documents, written for youIncluded free
AI Governance Framework, Acceptable Use Policy, Vendor Due Diligence Checklist, Risk Assessment Template. Your organisation, owners, tools and jurisdictions written in.
02
Your readiness score and maturity level
Ten governance domains scored from your own answers, on screen beside the downloads.
03
Editable Word files, yours to keep
Each ends with a schedule showing which answer shaped which clause. Review, approve, publish.
Regulation (EU) 2024/1689 applies to anyone placing AI on the EU market, wherever they sit.
Risk-tiered obligations, an AI literacy duty for every deployer, and penalties up to €35M or 7% of global turnover. The Digital Omnibus, in force since 27 July 2026, moved the high-risk deadlines: December 2027 for stand-alone Annex III systems, August 2028 for AI embedded in regulated products.
1 Aug 2024
In force
2 Feb 2025
Prohibited practices and AI literacy duty apply
2 Aug 2025
General-purpose AI model obligations; governance and penalties
2 Aug 2026
Transparency duties (Art. 50) and the rest of the Act; fines for general-purpose AI providers
2 Dec 2026
New prohibition (non-consensual intimate images); AI-content marking for existing generative AI
2 Dec 2027
High-risk obligations for Annex III systems (was 2 Aug 2026)
2 Aug 2028
High-risk AI in regulated products, Annex I (was 2 Aug 2027)
ExtraterritorialAI literacyRisk tiersGPAI
GDPR
02 / 02
Every AI system that touches personal data is a GDPR system first.
Lawful basis, purpose limitation, data minimisation, DPIAs for high-risk processing and Article 22 limits on automated decisions all apply to AI exactly as they did before. The AI Act adds to GDPR; it does not replace it, and the four documents are written for both.
Art. 35
DPIA where AI processing is likely high-risk
Art. 22
Rights around solely automated decisions
Art. 5
Minimisation and purpose limitation for training and prompts
DPIAAutomated decisionsData minimisationSpecial category data
General information, not legal advice. Dates move; the documents state the ones that apply to you at the time.
4
EU AI Act documents, written for you
€0
Nothing to pay, no obligation
Instant
Ready the moment you send
Reviewed by Fredrik Karlsson, Group COO & CISO, Opsio·Last reviewed
Who is behind this
The documents are free. Making them work is what we do.
Opsio is a Swedish cloud and AI services company, founded in 2018 in Karlstad, with a delivery centre in Bangalore and 24/7 operations. We build, run and secure cloud and AI systems for companies across Europe and Asia, so the policies in these documents are the same ones we apply in production.
An AI governance framework is the controlling document for how an organisation uses AI. It names who is accountable, sets how a new AI use case is assessed, classified and approved, defines which information may be used and which tools are approved, and is where an EU AI Act deployer shows how it meets its AI literacy and risk duties.
What should an AI acceptable use policy include?
An AI acceptable use policy tells staff which AI tools and accounts they may use, what they must never enter, such as personal data, customer confidential information or credentials, how to check AI output before relying on it, which uses are prohibited, and how to report an AI incident. It is also a practical way to evidence the EU AI Act's Article 4 literacy duty.
What does the EU AI Act require of organisations that use AI today?
Since 2 February 2025 organisations using AI in the EU must not use prohibited AI practices (Article 5) and must take measures to support their staff's AI literacy (Article 4, as amended by the Digital Omnibus). Transparency duties such as telling people they are talking to an AI apply from 2 August 2026 (Article 50). Deployer duties for high-risk Annex III systems apply from 2 December 2027.
What is an AI readiness assessment?
An AI readiness assessment measures how far an organisation's governance of AI has come: ownership, policies, risk process, privacy, security, vendors and agents. Opsio's free assessment scores ten domains on a five-level maturity scale from your answers and writes the four governance documents those answers call for.
Is there a free AI policy template?
Yes. The AI Acceptable Use Policy is the AI policy staff follow day to day, and Opsio's assessment writes it for free from your answers instead of handing you a blank template: approved tools, what must never be entered, how to check output, prohibited uses and how to report an incident, with your organisation and owners named.
How does this relate to ISO 42001 (ISO/IEC 42001)?
ISO/IEC 42001 is the international standard for an AI management system. The AI Governance Framework is written having regard to ISO/IEC 42001, alongside ISO/IEC 27001, ISO/IEC 23894 and the NIST AI RMF, so its roles, risk process and approved-tools register are a practical starting point. It is not a certification: an ISO/IEC 42001 certificate needs an audit by an accredited certification body.
The documents
An AI governance framework, an AI policy and two templates. Written for your organisation, not a template with your logo.
The controlling framework, the rules for staff, the gate for vendors and the assessment for each use case. Together they are what a customer's procurement questionnaire or a regulator's first letter asks to see, and what the EU AI Act's literacy, deployer and risk-management duties assume exists.
[Organisation]v1.0
AI Governance Framework
Owner: [Executive AI owner]
1.Purpose and scope
2.AI governance model
3.Enterprise AI governance
4.AI risk, data and security
5.Appendices A–E
Written for you≈ 50 pages
01Word · editable · free
AI Governance Framework
The document everything else hangs off.
Who is accountable for AI, how a use case moves from idea to operation, how risk is classified, how information may be used, and which tools are approved.
When due diligence is required, set from your procurement answer
Schedule 1 pre-lists every provider you declared as the first assessments to run
Your regulatory position in the legal section
Owner and custodian named
Every file ends with a schedule that lists the answer behind each tailored clause.
[Organisation]v1.0
AI Risk Assessment Template
Owner: [Executive AI owner]
1.Basic information
2.Personal data and privacy
3.EU AI Act mapping
4.Risk classification
5.Approval
Written for you≈ 45 pages
04Word · editable · free
AI Risk Assessment Template
One assessment per AI use case, mapped to the Act.
The structured record that decides whether a use case may proceed: purpose, data, privacy, agents, oversight, legal mapping, security, classification, controls, approval, review.
The first lines of the generated policy, word for word. Your organisation's name, the owner you named and your approved tools are written in where the brackets are.
[Your organisation] – AI Acceptable Use Standard
Version 1.0
Owner: [named from your answers]
Parent document: [Your organisation] AI Governance Framework
Review: annual, or on material legal, regulatory, technological or business change
Purpose
The purpose of this AI Acceptable Use Standard is to establish clear and practical requirements for the day-to-day use of AI by employees, contractors and other authorised users acting on behalf of [Your organisation].
The Standard is intended to enable responsible AI adoption without unnecessarily restricting legitimate business use.
Core rules for AI use
AI shall be used only where there is a legitimate business purpose. Users shall not introduce AI into a business process merely because an AI capability is available.
Users shall use only AI tools that have been approved by [Your organisation] for business use. The current Approved AI Tools Register is maintained as Appendix E to the AI Governance Framework.
Why now
AI arrived in most organisations before anyone governed it.
The EU AI Act does not ask whether you build AI. It asks how you use it, whose data it touches, which systems it can reach, and whether the people using it know the rules. Three things make that urgent.
Shadow AI is already in the building.
Personal ChatGPT accounts, browser extensions, AI features switched on inside SaaS you already pay for. Most organisations discover their real AI footprint when a customer, a regulator or an incident makes them look.
Covered by · AI Acceptable Use Policy · Approved AI Tools Register
The AI literacy duty already applies.
Since 2 February 2025 every organisation that provides or uses AI in the EU has had an AI literacy duty. Since the Digital Omnibus it means taking measures to support your staff's AI literacy, and a written policy people are trained on is the clearest way to show you did.
Covered by · AI Acceptable Use Policy · AI Governance Framework
Agents turn a chat into an action.
An AI with access to email, tickets, cloud consoles or production data can act without anyone approving it. If nobody can say who can stop it, restrict it or reverse it, that is the first gap to close.
Covered by · AI Risk Assessment Template · AI Acceptable Use Policy
The EU AI Act
Written for the duties that already apply.
Regulation (EU) 2024/1689 applies to anyone placing AI on the EU market or using its output in the EU, wherever they are established. Its prohibitions and its AI literacy duty have applied since February 2025; the general-purpose AI and governance provisions since August 2025. The high-risk timetable was moved by the Digital Omnibus to December 2027 and August 2028.
The four documents are written against those duties, and against GDPR wherever personal data is involved, because every AI system that touches personal data is a GDPR system first.
The documents are an initial draft prepared from your self-assessment. They are not a legal opinion, a certification, a security audit or a DPIA, and each one says so. What they give you is the written governance the Act assumes exists, in your organisation's name, ready for review.
EU AI Act timeline: what applies whenSource: Regulation (EU) 2024/1689 on EUR-Lex, as amended by the Digital Omnibus (in force 27 July 2026). Last checked 7 October 2026.
Date
What applies
1 Aug 2024
In force
2 Feb 2025
Prohibited practices and AI literacy duty apply
2 Aug 2025
General-purpose AI model obligations; governance and penalties
2 Aug 2026
Transparency duties (Art. 50) and the rest of the Act; fines for general-purpose AI providers
2 Dec 2026
New prohibition (non-consensual intimate images); AI-content marking for existing generative AI
2 Dec 2027
High-risk obligations for Annex III systems (was 2 Aug 2026)
2 Aug 2028
High-risk AI in regulated products, Annex I (was 2 Aug 2027)
How it works
The AI readiness assessment: forty minutes of answers. Four documents, instantly.
Step 01About forty minutes, on its own page
Answer the questionnaire
Fourteen steps covering how your organisation actually uses AI: tools, data, people, vendors, agents. Saved as you go, with a private link so Legal, IT, Privacy and HR can each answer their part.
Step 02The moment you send
Four documents are written from your answers
The AI Governance Framework, Acceptable Use Policy, Vendor Due Diligence Checklist and Risk Assessment Template are generated with your organisation, owners, tools, functions and jurisdictions written in, and your readiness score across ten domains appears beside them.
Step 03Editable Word files, yours to keep
Download, review, adopt
Each document ends with a schedule showing which answer shaped which clause. Take them through your normal approval and publish. An Opsio consultant reviews your answers and offers a walkthrough call if you want one.
Opens the questionnaire on its own page. Saved as you go.
What is assessed
Ten domains. One score.
Each domain is scored on its own checks and tells the documents what to write. A domain that does not apply to you, because you have no agents or no AI in HR, is left out of the score, and the matching section is marked out of scope rather than written as if it applied.
Domain 01 of 10
AI governance
Ownership, committee, roles, register, strategy, periodic review and change control.
Documents you receive for this domain
AI Governance Framework
What the assessment checks
Governance framework
Designated owner and RACI
AI register
Review and change triggers
Domain 02 of 10
Acceptable use
What employees may put into which tools, personal accounts, output verification and shadow AI.
Documents you receive for this domain
AI Acceptable Use Policy
AI Governance Framework
What the assessment checks
Acceptable use policy
Approved tools
Personal account rules
Output verification
Domain 03 of 10
Risk management
Whether AI is assessed and classified before it is switched on, and who approves it.
Documents you receive for this domain
AI Risk Assessment Template
AI Governance Framework
What the assessment checks
Risk methodology
Risk classification
Approval process
Monitoring and continuity
Domain 04 of 10
Privacy
Personal and special-category data in AI, DPIAs, automated decisions and transparency.
Documents you receive for this domain
AI Risk Assessment Template
AI Acceptable Use Policy
What the assessment checks
DPIA process
Automated decision-making
Minimisation controls
Privacy notices
Domain 05 of 10
Information security
The controls between AI systems and your data, and whether AI-specific threats are on the list.
Documents you receive for this domain
AI Governance Framework
AI Acceptable Use Policy
What the assessment checks
Security baseline
AI threat assessment
Access and logging
Data-loss prevention
Domain 06 of 10
Third-party AI
Vendor due diligence, contracts, inventories, training-on-your-data clauses and exit.
Documents you receive for this domain
AI Vendor Due Diligence Checklist
What the assessment checks
Vendor due diligence
Procurement gate
Contract clauses
Vendor inventory
Domain 07 of 10
Engineering & development
AI-assisted coding, internal model development, testing, deployment and drift.
Documents you receive for this domain
AI Acceptable Use Policy
AI Risk Assessment Template
What the assessment checks
Development standard
Coding policy
Testing and validation
Deployment controls
Domain 08 of 10
HR
AI in recruitment, performance, monitoring and employment decisions, with human review.
Documents you receive for this domain
AI Acceptable Use Policy
AI Risk Assessment Template
What the assessment checks
Employee AI policy
Recruitment rules
Monitoring requirements
Human review
Domain 09 of 10
Customer & product AI
AI in what you sell: terms, disclosure, approval, contractual clauses and product governance.
Documents you receive for this domain
AI Vendor Due Diligence Checklist
AI Acceptable Use Policy
What the assessment checks
Customer AI terms
Disclosure
Contract clauses
Product governance
Domain 10 of 10
AI agents & automation
Agents with system access: permissions, human approval, logging, production limits, kill-switch.
Documents you receive for this domain
AI Acceptable Use Policy
AI Risk Assessment Template
What the assessment checks
Agent standard
Access controls
Human approval
Emergency shutdown
The scale
Five levels, from informal to measured and improved.
The questionnaire asks where you would put yourself. The score says where the answers put you. The four documents are what takes an organisation to Level 3 on paper.
Level 1
Initial
AI is being used, but governance is largely informal.
Level 2
Developing
Some AI policies, controls or assessments exist, but governance is not consistent across the organisation.
Level 3
Defined
AI governance responsibilities, policies and risk processes are formally established.
Level 4
Managed
AI governance is integrated with privacy, security, procurement, risk and technology processes.
Level 5
Mature
AI governance is continuously monitored, measured and improved, and integrated into the broader risk and technology management framework.
Yes. The questionnaire, the readiness score and the four documents are free, with no card and no obligation. Opsio offers this because organisations that adopt the documents often want help implementing the controls behind them, and that is a separate, quoted engagement you are free to decline. The documents are yours either way.
Each document is written from your answers the moment you send: your organisation's name throughout, the executive owner and governance lead you named, your jurisdictions and the frameworks that apply, your business functions, the AI providers and use cases you declared, the personal-accounts rule you chose, and sections kept or marked out of scope depending on whether you use AI in HR, in development, in customer-facing services or as agents. A schedule at the end of each file lists every answer that shaped a clause, so nothing is hidden.
Editable Word documents, individually or as one zip. Change any clause, rebrand them, put them through your own approval. Nothing to license.
The four documents are written for the EU AI Act: the AI literacy duty, prohibited practices, deployer and provider responsibilities, risk management and the Annex III classification. Because every AI system that touches personal data is a GDPR system first, the privacy sections are written for GDPR too.
The Framework and the Acceptable Use Policy are written to be adopted with light edits, and the two templates can be used as they stand. Owner and custodian are already named from your answers. Where a clause depends on an answer you marked 'unknown', the schedule says so; fix that before approval.
No. The documents are an initial draft prepared from a self-assessment. They do not constitute a legal opinion, a regulatory compliance certification, a security audit or a privacy impact assessment, and each one says so. Review them with your legal, privacy and information-security functions before adoption.
About forty minutes if one person has the answers, spread across fourteen steps. It usually takes longer in calendar time because several functions contribute. That is what the save-and-share link is for.
The Opsio consultants who review assessments. No AI model reads your answers: the score and documents come from Opsio's own rules and templates. Your answers are processed in Frankfurt and stored in Frankfurt and Stockholm; only your name, contact details, company size and location and your score go to our CRM and email provider so we can follow up. We never sell your answers or use them for advertising, and you can ask us to delete them at any time at info@opsio.se. Documents you attach can be provided under NDA instead.
Get your EU AI Act documents written. Free.
AI Governance Framework, AI Acceptable Use Policy, AI Vendor Due Diligence Checklist, AI Risk Assessment Template. Forty minutes of answers, four Word files you own, whether or not we ever work together afterwards.