AI Compassby Digital Pharma Lab
Back to the compass
~ 15 min · confidential · internal use

Assess your compliance with the EU AI Act

This free diagnostic, designed specifically for pharmaceutical laboratories, assesses your readiness for the European AI regulation. In 15 minutes: a maturity score, your main non-compliance risks, and priority recommendations.

Critical deadline: from 2 August 2026, member-state surveillance authorities gain their enforcement powers over Article 4 (AI Literacy), with penalties of up to €7.5M or 1% of global turnover. GPAI obligations are already enforceable.
0 / 22 questions answered0 %
0

Profile

A few pieces of context (not counted in the score)

What is your role in the organisation?
Organisation size
Main AI activities (multiple selections allowed)
This helps contextualise your regulatory exposure
Your role under the AI Act (multiple possible)
Model provider: you develop or train a general-purpose AI model (GPAI). System provider: you place an AI system on the market (e.g. an MDR/IVDR device embedding AI, under your brand). Deployer: you use, under your authority, an AI system supplied by a third party.
1

AI Governance

Steering, responsibilities and internal policy

AI governance is the organisation you put in place to steer your use of AI: roles and responsibilities, internal policy, review committees and risk monitoring. It is the foundation that lets you demonstrate control and meet the AI Act's obligations over time.

Is there an identified AI compliance officer in your organisation?
Multiple answers possible
Do you have an AI governance committee or body?
Does an internal AI policy exist (acceptable use, ethical principles)?
Is AI Act compliance covered by an identified budget for 2026?
2

AI Systems Inventory and Classification

Mapping your actual regulatory exposure

The inventory means listing all your AI systems and classifying them by AI Act risk level (unacceptable, high, limited, minimal). It is the mandatory starting point of any compliance effort: you can only govern what you have mapped.

Do you have an inventory of AI systems used or developed?
Have you classified your systems according to AI Act risk levels (unacceptable, high, limited, minimal) and your role (provider, deployer)?
Do you use AI in medical devices or IVDs (MDR/IVDR)?
These systems may be classified as high-risk under the AI Act if they serve a safety function
Do you use AI in pharmacovigilance (signal detection, ICSR processing)?
Multiple answers possible
Do you use generative AI tools (ChatGPT, Copilot, Claude, etc.)?
Multiple answers possible
Have you analysed whether your systems fall within the high-risk use cases listed in Annex III of the AI Act, and specifically whether they are applied to biometric, recruitment, training, risk assessment or health insurance pricing use cases?
Have you implemented systematic controls for the prohibited practices under art. 5 (social scoring, manipulation, emotion recognition in the workplace, etc.)?
3

AI Literacy (Article 4)

Training and awareness for staff

AI literacy means the skills, knowledge and understanding that allow your staff to deploy and use AI systems knowingly, and to be aware of both their opportunities and risks. Since 2 February 2025, Article 4 of the AI Act requires every provider and deployer to ensure a sufficient level of AI literacy among its staff, proportionate to the systems used, the context of use and the people affected.

Have your employees using AI received AI literacy training?
Multiple answers possible
Are training modules proportionate to the risk level of the systems used?
Do you track coverage and effectiveness indicators for training?
4

Data and Quality

Governance of data intended for use in AI systems

Data governance covers the quality, traceability and protection of your proprietary data used in production as input to your generative AI (prompts, RAG corpora, shadow AI).

Do you have data governance defining what your employees may or may not process using the AI systems available to them?
Multiple answers possible
Do you have data lineage mechanisms covering production data, and in particular the use made by your employees of the AI systems available to them?
Multiple answers possible
6

AI Vendors and GPAI

Due diligence on models and systems provided by your vendors

This section covers AI models and systems supplied by third parties, including general-purpose AI (GPAI) models. The AI Act allocates responsibilities along the value chain, so you must carry out due diligence on your suppliers and secure your contracts to inherit their compliance guarantees.

Do you conduct AI Act due diligence on your AI vendors and GPAI models?
Multiple answers possible
Do your vendor contracts include specific AI Act clauses (responsibilities, documentation, audit)?
Multiple answers possible
Are you familiar with the GPAI Code of Practice and have you integrated it into your vendor selection criteria?
Multiple answers possible
When acquiring or modifying an AI system, do you assess the risk of becoming a 'provider' yourself under art. 25 (affixing your own brand, substantial modification, change of intended purpose)?
Multiple answers possible
7

EMA Compliance and Pharma Quality

Alignment with the EMA Reflection Paper and GxP requirements

This section connects the AI Act with the healthcare framework: the EMA Reflection Paper on the use of AI across the medicinal product lifecycle and GxP requirements (validation, quality, pharmacovigilance). The goal is to keep AI compliance consistent with pharmaceutical obligations.

Have you integrated the EMA Reflection Paper (September 2024) into your AI practices?
Have you engaged with the EMA, a national authority or a certification body regarding your MDR/IVDR devices integrated into AI systems?
Talk to a consultant