EU AI Act Impactscan
25 questions across 7 topics. Compliance score, risk level and action list with legal references. Takes around 10 minutes.
ChatGPT, Copilot and other AI tools are already used across daily work. Emails, reports, analysis, HR, sales and support. In many organisations, management has no clear view of which tools are used, what data is shared or who is responsible.
The AI Compliance Quick Scan gives leadership a clear baseline in two weeks.
AI adoption mostly starts with employees trying to save time.
That can create useful gains, but it also creates blind spots.
Without a clear overview, management cannot see where sensitive data goes, which use cases carry risk, or whether teams follow the same rules.
There is no clear list of AI tools and use cases across departments.
Customer data, financial data or internal information may enter AI tools without review.
AI responsibility often sits somewhere between IT, legal, operations and management.
If a client, auditor or regulator asks for evidence, there is no clear baseline.
If you cannot list your AI use cases, you cannot govern them.
Many organisations already have an IT policy, a Copilot rollout or a short AI guideline. That is useful, but it rarely shows what people are actually doing.
If the answer to these checks is unclear, there is no real governance. There is intent.
Do employees know which tools are approved?
Do teams know what data they can enter?
Can management prove where AI is used today?
A two week scan of AI use, data exposure and governance gaps.
The Quick Scan maps current AI use across selected teams and departments. It shows where tools are used, what data risks exist, which use cases need review and what actions should come first.
A practical baseline for leadership. Clear enough to act on. Small enough to start without a long programme.
A clear overview of AI tools and use cases by department.
A view of what types of data may be entered into AI systems.
A practical risk view, including use cases that may need closer review.
A simple view of current maturity across policy, ownership, controls and records.
Concrete next steps for leadership, ordered by urgency and effort.
The process is kept small on purpose. Enough structure to find the facts. No heavy project setup.
Scope the business
Leadership intake, selected departments, known AI tools and main concerns.
Map real use
Short interviews or survey input with team leads and key users.
Assess risk
Review of data exposure, ownership, policy gaps and sensitive use cases.
Report actions
Clear report and leadership briefing with next steps.
Best fit for organisations with roughly 50 to 500 employees where AI is already used across multiple teams, but policy, ownership and control are unclear.
Useful where office teams, operations and planning already use AI in scattered ways.
Useful where AI touches planning, support, reporting or operational decisions.
Useful where knowledge work, client data and AI use meet every day.
Useful where governance, records and risk control matter from the start.
Useful where departments solve problems with AI before policy catches up.
Some organisations need employee training. Others need a policy, approved tool list, use case review or management workshop. The scan shows which follow up makes sense.

25 questions across 7 topics. Compliance score, risk level and action list with legal references. Takes around 10 minutes.

For each AI system: risk level, GPAI detection, and obligations based on your role as a provider or deployer.
No. The Quick Scan gives leadership a clear starting point. It maps current AI use, data exposure and governance gaps so the organisation knows what needs attention first.
Yes, if the policy does not show what people actually do in daily work. A policy is useful, but management also needs proof of real AI use across teams, tools and data types.
The scan can include tools such as ChatGPT, Copilot and other AI systems used in daily work. The focus is on where they are used, what data may enter them and who owns the risk.
Leadership should be involved, together with people from IT, legal, operations and selected departments. The scan works best when it combines management view with input from teams that use AI every day.
The process is kept small. It usually uses a leadership intake, selected department input and a review of known tools, data risks, ownership and policy gaps.
You receive an AI Use Map, Data Exposure View, Risk Assessment, Governance Readiness Score and Priority Action Plan. The result is a clear baseline for the next decision.
The scan shows which next step makes sense. That can be employee training, an AI Act management workshop, an approved tool list, a policy update or a longer governance roadmap.