AI EU AI Act Compliance Gap Analysis Playbook
A US-headquartered software company sells HR screening and employee performance management software to European enterprise customers. The EU AI Act's high-risk AI requirements for employment applications take effect in August 2026. The legal team needs a compliance gap analysis before the effective date.
When to use this playbook
- Use this playbook when the decision looks like the situation above: A US-headquartered software company sells HR screening and employee performance management software to European enterprise customers.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "EU AI Act Compliance Gap Analysis".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- Product technical documentation for the HR screening and performance management tools
- Current data processing agreements with EU customers
- Training data documentation (sources, demographics, bias testing results)
- Existing GDPR compliance records
- EU AI Act Article 9-15 high-risk AI requirements
Attachments: Documents (Documents)
The Prompt
You are an AI governance counsel conducting an EU AI Act compliance gap analysis for a US software company with EU enterprise customers. I am attaching: Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Confirm whether the HR screening and performance management tools meet the Article 6 definition of high-risk AI systems and what the compliance obligations are. 2. Identify gaps against Article 9 (risk management system), Article 10 (training data governance), Article 13 (transparency), and Article 14 (human oversight) requirements. 3. Assess whether current GDPR documentation can be leveraged to satisfy AI Act documentation requirements or whether separate documentation is needed. 4. Identify the customer contract changes needed to allocate compliance obligations between the US vendor and EU deployer. 5. Build a compliance roadmap with milestones, owners, and estimated costs to be ready before the August 2026 effective date. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- High-risk AI classification confirmation
- Gap analysis by Article (9, 10, 13, 14)
- GDPR documentation reuse assessment
- Customer contract amendment requirements
- Compliance roadmap with milestones and cost estimate
Review before you act
- Validate this output against source files before relying on it: Confirm whether the HR screening and performance management tools meet the Article 6 definition of high-risk AI systems and what the compliance obligations are.
- Validate this output against source files before relying on it: Identify gaps against Article 9 (risk management system), Article 10 (training data governance), Article 13 (transparency), and Article 14 (human oversight) requirements.
- Validate this output against source files before relying on it: Assess whether current GDPR documentation can be leveraged to satisfy AI Act documentation requirements or whether separate documentation is needed.
- Validate this output against source files before relying on it: Identify the customer contract changes needed to allocate compliance obligations between the US vendor and EU deployer.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For EU AI Act Compliance Gap Analysis, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface high-risk ai classification confirmation; gap analysis by article (9, 10, 13, 14); gdpr documentation reuse assessment; customer contract amendment requirements. Those are comparison artifacts — they only exist if more than one model runs. Risk-tier assignments and 'high-risk system' calls vary with how a model reads a use-case description. Comparison exposes those classification fights before they reach an exam.
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

