Ten domains regulators and boards expect you to govern. Answer honestly — takes 2 minutes. EU AI Act transparency obligations begin August 2, 2026.
Do you know what data feeds each AI system, who owns it, and where it came from?
Are models tested against benchmarks and formally approved before deployment?
Do you test AI outputs for unfair, discriminatory, or unbalanced outcomes?
Do high-impact AI decisions require human review, with escalation and override paths?
Have you mapped each AI use case to the laws that govern it (EU AI Act, GDPR, industry rules)?
Are prompts and outputs protected against injection, data leakage, and misuse?
Do you assess third-party AI tools and models, and can you switch providers without rewrites?
If an auditor asked what your AI did last quarter, could you produce the record today?
Do you track model performance drift AND monthly AI spend per workload?
Is there a playbook for when AI fails, leaks data, or behaves unexpectedly?