How to Run an EU AI Act Gap Analysis
A gap analysis is the practical heart of EU AI Act readiness. It answers one question for each AI system: what does the Act require, and where do we currently fall short? Done well, it turns a long legal text into a short, owned list of actions. Here is how to run one.
Step 1: Build the AI inventory
You cannot assess what you have not listed. Record every AI system you build, buy, or access, including models embedded in third-party tools and the AI features inside software you already pay for. For each, note the owner, the purpose, the data it uses, and where its outputs are used. Shadow AI, the tools teams adopt without sign-off, is where most gaps hide.
Step 2: Classify each system
Place each system in the Act's risk tiers: unacceptable, high, limited, or minimal. The classification decides which obligations apply, so it has to be defensible, not a guess. A recruitment screening model and an internal meeting-notes assistant sit in very different tiers and carry very different duties.
Step 3: Map the obligations
For every high-risk system, list the specific requirements: risk management, data governance, the Annex IV technical documentation, record-keeping under Article 12, human oversight, accuracy and robustness, the Article 27 fundamental-rights impact assessment where it applies, registration under Article 49, and the Article 50 transparency position. For limited-risk systems, the main duty is transparency.
Step 4: Assess current practice against each obligation
This is the gap itself. For each obligation, record the current state, the evidence that supports it, and the distance to compliance. Be honest about missing or informal practice. A gap you have written down is a gap you can close. A gap you have hidden becomes a finding later.
Step 5: Turn gaps into a roadmap
Rank the gaps by risk and by deadline. High-risk systems facing the August 2026 obligations come first. Assign each gap an owner, a control, and a target date, so the analysis becomes a plan rather than a report that ages on a shelf.
Common gaps we see
No single inventory, so systems are missed entirely.
Classification done once and never revisited as systems change.
Technical documentation that exists in fragments across teams, not as one coherent Annex IV record.
No fundamental-rights impact assessment where the Act requires one.
Evidence that is claimed but cannot be produced on request.
Making it repeatable
A gap analysis is not a one-time exercise. Systems change, new AI is adopted, and the guidance evolves. AIVARA Core 360 runs the gap as a living view: the AI register feeds classification, obligations map to a control library, and the gap becomes a tracker with owners and dates. The output is the same structured assessment each cycle, built on the last rather than restarted.
Start with our EU AI Act Readiness Assessment, which produces the inventory, classification, gap analysis, and roadmap, or explore how AIVARA Core 360 manages the ongoing control environment.