EU AI Act Readiness Scorecard for Law Firms
Twelve questions. Ten minutes. A defensible readiness score cross-referenced against the ISO/IEC 42001 nine-gap framework — showing exactly which statutory obligations your firm meets today, and which are open enforcement exposure.
Why this matters now. Law firms deploying AI tools are subject to the EU AI Act in layers — and the first obligations are already live. Most firms assume the Act only touches "high-risk AI." It does not. A firm running a client-facing chatbot, publishing AI-drafted content, or using AI in matter work carries obligations today. This scorecard measures readiness against each applicable article, then maps your position to the ISO/IEC 42001 management-system framework — because the two regimes are designed to reinforce each other.
AI Literacy
Transparency & Disclosure
High-Risk Classification
Human Oversight & Operations
AI Supply Chain
The finding most firms miss
Our cross-referenced analysis of the two frameworks shows a firm with a complete ISO/IEC 42001 management system already holds roughly 65–70% of the EU AI Act compliance infrastructure — because both regimes are architected around the same principle: documented human oversight with an evidence trail. The remaining distance is a set of specific statutory artefacts, not a second compliance programme.
Readiness by Domain
Your Priority Actions
Close the gap with systems, not binders
The UNUS London Governance Academy builds the ISO/IEC 42001 nine-gap infrastructure — the documented human oversight, AI system register, and evidence trails that deliver the majority of your EU AI Act position — as deployable systems, not static policy documents. The EU AI Act extension series completes the statutory layer.