AI Act assessment and compliance plan
How to run the assessment for high-risk systems and build the action plan for compliance.
Assessment for high-risk systems
AI systems classified as high-risk require complete technical documentation and a quality management system. Privacta guides the team through a structured assessment that covers all the requirements of Title III of the AI Act.
The assessment includes:
- Training data — origin, quality, potential bias, mitigation measures
- Technical documentation — system architecture, capabilities and limitations
- Human oversight — measures to ensure human control over the system’s output
- Accuracy and robustness — performance metrics, tests carried out, acceptable thresholds
- Cybersecurity — measures against adversarial attacks and data manipulation
The AI Act assessment is separate from the GDPR DPIA but can share some information. Privacta lets you automatically import the data already entered in the linked DPIA record.
Action plan and gap remediation
At the end of the assessment, Privacta generates a list of gaps against the AI Act requirements. For each gap:
- Assess the criticality (blocking / important / recommended)
- Assign an owner and a deadline
- The actions are automatically added to the Tasks & Deadlines section
- Progress is tracked in the AI Act Readiness dashboard
Technical documentation for the dossier
For high-risk systems, the AI Act requires an always-up-to-date technical dossier. Privacta centralizes in one place:
- The system record with classification and assessment
- The model’s version log
- Accuracy and robustness test results
- Documentation of human oversight measures
- Evidence of compliance with transparency requirements
Continuous monitoring
AI Act compliance is not a static goal: every significant update to a system requires a review of the assessment. Privacta monitors changes to registered systems and alerts the owner when a new assessment is needed.
📄 Add an example of a completed assessment for an HR analytics system