Skip to main content

The AI Readiness Check

Twenty-four questions before your first production AI workload, along the six steps of Microsoft's Cloud Adoption Framework. At each step the check asks what the framework asks, then adds the EU AI Act obligation that applies. Answer for the use case you are closest to committing to; a hesitant yes, or a don't-know, counts as a no. The result reads the total across all six steps.

Strategy

The framework asks you to identify use cases. EU law asks you to classify them against Article 5 and Annex III first.

  1. Can you name your top three AI use cases and the business metric each one improves?

  2. For each use case, do you know whether you are buying (Copilot, SaaS), configuring (Copilot Studio, Azure AI Foundry) or building (custom models on Azure)?

  3. Has anyone checked the candidate use cases against Article 5 of the EU AI Act? The prohibited practices have been in force since 2 February 2025.

  4. Have you classified each use case against Annex III, so you know which ones count as high-risk when those obligations apply from 2 December 2027?

Plan

The people who run AI and the accountability around them: training under Article 4, named ownership, pilots with an end date.

  1. Have the employees who operate or oversee AI systems received documented AI training? Article 4 has required this since 2 February 2025, for deployers as well as providers.

  2. Have you assessed which AI skills exist in-house and which you need to buy or borrow?

  3. Does every pilot have written success criteria and a kill date, or do pilots run until someone forgets them?

  4. Is there one named person accountable for responsible AI, with the authority to stop a deployment?

Ready (platform)

Where each model runs and what the platform can capture: network isolation, GDPR Article 44 transfers, Article 12 logging.

  1. Do AI workloads run in their own subscription or landing zone, with network isolation from the rest of the estate?

  2. For every model you use, do you know where it runs and where prompts, outputs and logs are stored? GDPR Article 44 applies to those transfers like any other.

  3. Can your platform capture and retain the automatic logs Article 12 requires for high-risk systems? Article 19 sets the minimum retention at six months.

  4. For any system you build, do training and validation data meet the quality and relevance criteria of Article 10, and can you show how you checked?

Govern

One inventory of every AI system, policies enforced as platform controls, and Annex IV documentation with a named owner.

  1. Do you have a current inventory of every AI system in production or pilot, including Copilot licences and the tools individual teams signed up for on a credit card?

  2. Are your AI policies enforced as platform controls (Azure Policy, network rules, identity), or do they exist only as a PDF?

  3. For high-risk systems, is the Annex IV technical documentation planned as an engineering deliverable with an owner, not as an afterthought?

  4. If you fine-tune or white-label a third-party system, has anyone checked whether Article 25 turns you from deployer into provider, with the full provider obligations of Article 16?

Secure

The three attack paths a standard security review skips: prompt injection, data poisoning, model and prompt theft.

  1. Does your threat model cover AI-specific attacks: prompt injection, data poisoning, model and prompt theft?

  2. Is access to model endpoints, keys and training data controlled and logged like access to any production database?

  3. Are AI resources covered by your security monitoring (for example Defender for Cloud AI posture management), not just by the application team's goodwill?

  4. For high-risk systems, can you demonstrate the accuracy and cybersecurity measures Article 15 requires?

Manage

The running cost once the pilot ends: cost per use case, human oversight under Article 14, post-market monitoring.

  1. Do you know what each AI use case costs per month, and per transaction where that applies?

  2. When a model version changes, do you evaluate before you swap, with documented results?

  3. Is human oversight (Article 14) designed into the workflow and staffed, rather than assumed?

  4. Do you have a post-market monitoring plan (Article 72) and a route to report serious incidents within the deadlines of Article 73?

0 of 24 answered. The result appears with the last answer.

Common questions

We haven't chosen a use case yet. Can we still run this?

Run it against the use case you are closest to committing to, even if it's not signed off. The Cloud Adoption Framework steps and the EU AI Act obligations both classify at the use-case level, so a generic answer for 'AI in general' does not produce a usable score.

Does a good score mean we're ready to go to production?

It means the six Cloud Adoption Framework steps are covered for that specific use case. A strategy step marked done for a use case that turns out to be Annex III high-risk still needs the classification worked through before anyone calls it production-ready.

How is this different from the EU AI Act Quick-Check?

The Quick-Check classifies a use case's risk tier. This readiness check assumes you already know the tier and asks the platform question underneath it: logging, security, human oversight, and cost, the operational work that classification alone doesn't cover.

What happens if we fail the security section?

Prompt injection, data poisoning, and model theft are the three gaps a standard security review misses, and they are usually fixable before launch, not after. The AI Use-Case Build folds the fix into the same engagement rather than treating it as a separate project.