A scored self-assessment for a system you have already built — an LLM feature, a RAG pipeline, an agent with tools. Three passes, about half an hour if you know the system well.
First it works out what you are: provider, deployer or importer; whether the EU AI Act reaches you through your market, your users, or output used in the EU; whether the model is general-purpose, and whether it carries systemic risk; and which risk tier you fall into — prohibited, high-risk, limited or minimal. That decides which later questions you are asked. A minimal-risk internal tool is never shown the Article 9–15 high-risk stack, and sections that do not apply are not counted against your score.
All ten categories, no sampling: prompt injection (LLM01), sensitive information disclosure (LLM02), supply chain (LLM03), data and model poisoning (LLM04), improper output handling (LLM05), excessive agency (LLM06), system prompt leakage (LLM07), vector and embedding weaknesses (LLM08), misinformation (LLM09) and unbounded consumption (LLM10). Each one is four or five specific control statements — not “do you handle injection?” but whether you test for payloads hidden in the content the model ingests. You score each 0–3: not in place, ad hoc, documented, robust. The gap between the last two is whether anyone has tested the control, which is usually where the honest answer hurts.
This pass establishes which obligations apply and how far you are from meeting them — not whether you comply. Article 50 transparency and Article 4 AI literacy for anyone in scope; the Article 9–15 stack plus a quality management system (Art. 17) and post-market monitoring (Art. 72–73) if you classified as high-risk; Articles 53 and 55 if you provide a general-purpose model; Article 26 if you deploy someone else’s high-risk system. It also counts down the deadlines still ahead.
Two scores, never averaged — security and compliance have different owners and different clocks. Under them: a per-control scorecard, a gap register listing every statement you scored 0 or 1, marked Critical or High and mapped back to the OWASP ID or the article it came from, and a remediation roadmap split by horizon: live security exposure first, dated obligations after. It prints, so you can hand it to an engineer, an executive or an auditor.
No account, no upload, no server. Your answers live in the page and are gone when you close the tab — there is no save and no resume, so set the time aside before you start. Our analytics records that an audit was started, completed or printed; it never sees an answer.
The person who has to answer “are we exposed?” about an LLM feature already in production, without the budget or the mandate for a formal assessment. It is a readiness signal and a gap list, not legal advice, a certification or a conformity assessment. What the AI Audit is for covers who should run it and the three things it deliberately does not do; the lethal trifecta explains the exposure pattern behind several Part 2 controls.