Free self-assessment · 15 minutes · AI
Your staff already use AI. Do you know what they put into it?
Most companies do not have an AI problem they can name. They have Copilot, ChatGPT, a few API keys, and one internal agent nobody has reviewed. This asks twenty-one questions across five areas about what is actually in use, where company data goes, and whether the EU AI Act already reaches you.
Who it is for
Any organisation that uses AI tools, or builds assistants and agents for its own use. It is not written for companies that sell an AI product: the obligations on a provider are a different set, we have no assessment for them yet, and we would rather say so than take an hour of your time asking about somebody else’s position. Talk to us instead.
What it covers — five areas, twenty-one questions
- What you actually use (4)
- Accountability and people (4)
- Shadow AI and accounts (3)
- Company data and generated content (5)
- Assistants, agents and things you build (5)
The quick check asks about generative AI in a single question. This is the long version of that question — and if you build nothing and run no assistant over company data, the last area is marked not applicable rather than counted against you.
What you get
A PDF of a dozen pages or so, the same shape as the quick check’s: an overall score with a band, a radar chart across the five areas, a table of every area with its score, then a prioritised list of findings — each one with what it is, why it matters and what to do about it, ordered so the first few account for most of the exposure.
Two of those findings are usually about the AI Act, and they are the ones people do not expect: duties that land on you as a user of AI rather than a maker of it. Every question and the answer you gave is listed at the end with its score, so nothing in the report is a number you have to take on trust.
What the report looks like
Three pages from a real report, generated by running the assessment. The example is a company that knows its approved AI tools but not what staff signed up for themselves, and builds agents of its own that have not all been reviewed. It scored 44%.

How you scored 
What to address 
Your answers
The account nobody offboards
One question in here tends to land harder than the rest. When somebody leaves, you disable their mail, their VPN and their laptop. The personal ChatGPT account they opened with a work address — two years of company conversations in the history, and a password you do not hold — is on nobody’s leaver checklist, because nobody ever put it there.
The assessment starts below — you do not need to go anywhere else.
A few details first
We use these to prepare your report and, if you would like, to talk it through afterwards.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
In three places it already does. Anyone who uses AI at work has to be trained to use it competently, in force since February 2025 — as is the ban on inferring employees’ emotions at work, narrow medical and safety exceptions aside. Since August 2026 you also have to tell people when they are dealing with a machine, and mark synthetic content as synthetic. The heavier duties, the ones attached to high-risk uses such as recruitment, credit scoring or access to services, were deferred to 2 December 2027 by the Digital Omnibus on AI. That is more time rather than a reprieve: where an automated decision lands on a person, data protection and employment law already reach it today.
Yes, and it will take you less than fifteen. Nothing here punishes a small estate: if you build no assistants and run nothing over your own documents, that entire area is recorded as not applicable and drops out of the scoring rather than dragging the total down. What is left is the part that does apply to you — who holds accounts, on whose payment card, what gets pasted into the box, and whether anybody has written down what must not.
Whoever runs IT, sitting with whoever owns AI in the organisation. That second person often turns out not to exist, and finding that out during a questionnaire rather than during an incident is most of the value here: four of the twenty-one questions are about who decides, and an honest “nobody” scores lower while telling you something.
Free, and no call is attached to it unless you want one. What you enter produces your PDF and is kept alongside your contact details so a later conversation can start from it instead of from nothing. It is not benchmarked, not passed on, and not seen by anyone outside Spirity — and given what this particular questionnaire asks about, anything else would be a poor way to run it.
Yes. All twenty-one questions, every answer option and the report itself exist in German and Hungarian as well as English — pick your language at the top of the page and the assessment follows it. The scoring is identical in all three, so the same answers produce the same number whichever one you choose; only the words change. One thing worth saying either way: no questionnaire, this one included, makes you compliant with the AI Act. It says where you stand.
Ready to get started?
Partner with Spirity Enterprise to implement the right security and IT solutions for your organization.