UNUS LONDON Compliance Architecture
UL-TOOL-EUAIA-001 · v1.0
0 / 12 answered
Self-Assessment · Legal Sector

EU AI Act Readiness Scorecard for Law Firms

Twelve questions. Ten minutes. A defensible readiness score cross-referenced against the ISO/IEC 42001 nine-gap framework — showing exactly which statutory obligations your firm meets today, and which are open enforcement exposure.

Art. 4 in force since Feb 2025 Art. 50 applies 2 Aug 2026 High-risk obligations Dec 2027

Why this matters now. Law firms deploying AI tools are subject to the EU AI Act in layers — and the first obligations are already live. Most firms assume the Act only touches "high-risk AI." It does not. A firm running a client-facing chatbot, publishing AI-drafted content, or using AI in matter work carries obligations today. This scorecard measures readiness against each applicable article, then maps your position to the ISO/IEC 42001 management-system framework — because the two regimes are designed to reinforce each other.

Domain 01 · Already in Force

AI Literacy

Article 4 — in force since 2 February 2025 · Maps to ISO 42001 Cl. 5.3 & 7.2
Q1 · ART. 4
Does your firm maintain a documented AI literacy training record for every fee earner and staff member who uses AI tools — showing who was trained, on what, when, and how competency was assessed?
ISO 42001 overlap: Gap 2 (Internal Organisation) + Gap 5 (Lifecycle competency)
Q2 · ART. 4
Is AI literacy training tailored to how AI is actually used in your firm — differentiating, for example, between a partner reviewing AI-drafted advice and support staff using an AI intake tool?
ISO 42001 overlap: Cl. 7.2 competence requirements
Domain 02 · Applies 2 August 2026

Transparency & Disclosure

Article 50 — AI-generated content & interaction disclosure · Maps to ISO 42001 Annex A.2
Q3 · ART. 50
Where your firm publishes AI-generated or AI-assisted text intended to inform the public (articles, briefings, updates), is there a documented human review step with a named person holding editorial responsibility?
ISO 42001 overlap: Gap 8 (Human Oversight — PROC-AIMS-HITL pattern)
Q4 · ART. 50
If clients or the public interact with any AI system operated by your firm (chatbot, intake assistant, client portal AI), does the system clearly identify itself as AI at the point of interaction?
ISO 42001 overlap: Gap 7 (Client Disclosure)
Domain 03 · The Gateway Analysis

High-Risk Classification

Annex III — administration of justice · Maps to ISO 42001 Cl. 6.1 (foundation only)
Q5 · ANNEX III
Does your firm maintain a complete register of every AI system in use — including embedded AI inside practice management tools, legal research platforms, and document automation?
ISO 42001 overlap: Gap 3 (AI System Register)
Q6 · ANNEX III
Has each AI system been formally analysed against the Annex III high-risk categories — with a documented, signed-off classification decision for each (e.g. whether litigation-outcome scoring or justice-administration use applies)?
ISO 42001 overlap: none — this is a distinct legal analysis the ISO framework does not perform
Q7 · ART. 27
If any of your AI systems could fall within Annex III (litigation prospect scoring presented to clients, case-outcome prediction as a decision input), has a Fundamental Rights Impact Assessment been completed before deployment?
ISO 42001 overlap: Gap 4 (Risk Assessment) is a necessary input — but does not satisfy Art. 27
Domain 04 · Deployer Obligations

Human Oversight & Operations

Articles 26 & 12 — oversight, monitoring, logs · Maps to ISO 42001 Cl. 9.1 & Annex A.2
Q8 · ART. 26
Is there a documented human oversight procedure governing AI outputs used in client work — defining who reviews, what they check, and producing an evidence trail of each review?
ISO 42001 overlap: Gap 8 (Human Oversight) — the strongest single overlap in the entire Act
Q9 · ART. 12
Are automated logs from your AI systems retained for a minimum of six months, with a documented retention policy covering AI-generated records?
ISO 42001 overlap: Gap 6 (Data Governance) — needs the 6-month minimum made explicit
Q10 · ART. 26(5)
Does your incident escalation pathway extend beyond internal reporting — with a documented procedure for notifying the relevant market surveillance authority of a serious AI incident within the statutory window?
ISO 42001 overlap: Gap 8 escalation pathway covers the internal leg only
Domain 05 · Vendor Layer

AI Supply Chain

Articles 25 & 53 — provider boundary & GPAI verification · Maps to ISO 42001 Cl. 8.4
Q11 · ART. 53
Has your firm verified — and documented the verification — that each general-purpose AI provider you rely on (e.g. the providers behind your drafting, research, or summarisation tools) meets its transparency and copyright obligations under the Act?
ISO 42001 overlap: Gap 9 (Supply Chain) — needs an EU-specific verification record added
Q12 · ART. 25
Has your firm assessed whether any of its AI use crosses the deployer/provider boundary — for example, substantially modifying a model, white-labelling an AI tool, or deploying AI for decisions affecting individuals' rights?
ISO 42001 overlap: Gap 2 (roles) touches this, but the Art. 25 boundary test is a legal analysis
Answer all 12 questions to unlock your score
0%

The finding most firms miss

Our cross-referenced analysis of the two frameworks shows a firm with a complete ISO/IEC 42001 management system already holds roughly 65–70% of the EU AI Act compliance infrastructure — because both regimes are architected around the same principle: documented human oversight with an evidence trail. The remaining distance is a set of specific statutory artefacts, not a second compliance programme.

Your current EU AI Act readiness0%
Readiness with the ISO 42001 nine-gap framework in place65–70%
Readiness with ISO 42001 + EU AI Act extension artefacts90%+
Your Breakdown

Readiness by Domain

What To Do First

Your Priority Actions

Close the gap with systems, not binders

The UNUS London Governance Academy builds the ISO/IEC 42001 nine-gap infrastructure — the documented human oversight, AI system register, and evidence trails that deliver the majority of your EU AI Act position — as deployable systems, not static policy documents. The EU AI Act extension series completes the statutory layer.

Book a Discovery Call