§ 01 Readiness · Overview
Readiness is not a score you buy. It is whether your public disclosure, your processor chain, and your compute jurisdiction survive being read carefully by someone who is not on your side.
§ 02 Answer · Direct
The honest version, before the method.
The readiness audit is a free scan of what a European entity has published about its own AI, privacy, and security posture, scored against four instruments. It runs on public sources — website, privacy notice, filings, registry data — and returns an indicative score with the top risks it can see.
It is not a certification and it cannot be. Nobody can certify your compliance by reading your website. What it can do is tell you what a regulator, a customer's procurement team, or a journalist would conclude from the outside, which is frequently a surprise.
We publish the assessments we run, including the unflattering ones and including the method limits, on the same page as the result. That is the whole product: not a badge, a mirror.
§ 03 Method · Instruments
Four instruments, each with a specific public signal. Nothing here is a legal determination.
| Instrument | Reference | What the scan looks for |
|---|---|---|
| EU AI Act | Regulation (EU) 2024/1689 | Whether a public AI or automated-decision surface exists, and whether transparency duties would attach to it. |
| GDPR | Regulation (EU) 2016/679, Art. 13–14, 28, 30 | Whether the privacy notice names processors and transfer mechanisms, and whether an AI processing purpose is disclosed at all. |
| NIS2 | Directive (EU) 2022/2555, Art. 21 | Whether the entity is plausibly in scope by sector, and what its public security posture says about supply-chain measures. |
| DORA | Regulation (EU) 2022/2554 | For financial entities, whether ICT third-party risk and register-of-information language appears anywhere public. |
Method limits
It reads public sources only. No access to your systems, contracts, or DPAs.
The score is indicative and comparative. It is not a certification, an audit opinion, or a legal determination.
A low score often means thin public disclosure rather than weak practice — and we say so on every report.
We publish the method and the limits on the same page as the result, so a reader can discount it appropriately.
§ 04 Published · 8 named
Written up as research, with the entity named and the method limits on the page. No entity paid for placement.
§ 05 Sample · 19 indicative
Scores across the sample run 52–71. These reports are excluded from Search on purpose — they are a comparative sample, not a verdict on any single entity.
| Sector | Entities assessed |
|---|---|
| Hospitality | 3 |
| Professional Services | 3 |
| Technology | 3 |
| Telecom | 3 |
| Insurance | 2 |
| Legal | 2 |
| Maritime | 2 |
| Banking | 1 |
Where an entity is a Greek or Cypriot registered company, the assessment can be cross-read against registry filings. That desk is separate and its own method limits apply.
§ 06 Then what · Compute
Most findings are disclosure problems. Some are architecture problems, and those are where we have something to sell.
The majority of what the scan surfaces is fixable with a better privacy notice, a named processor list, and an honest statement of what your AI features actually do. None of that requires buying compute from anyone, and we would rather say so than manufacture a funnel.
The findings that are architectural are narrower: a model processing regulated data through a provider that can be compelled by a third-country authority, or a workload whose logging you cannot produce on audit. Those are jurisdiction problems, and the honest options are Copperway today or reserved EU-sited capacity for later. The Cyprus campus is pre-construction, so nobody is migrating onto AGICY silicon this quarter.
| Finding type | What actually fixes it |
|---|---|
| Thin public disclosure | Your own privacy notice and AI transparency statement. No vendor required. |
| Unnamed processor chain | Publish the sub-processor list. We publish ours in the Trust Center. |
| Third-country compulsion exposure | A jurisdiction change — masked inference now, reserved EU capacity later. |
| Unproducible audit trail | An inference path where you own the logs and can export weights and traces. |
§ 07 Questions · FAQ
What the audit is, what it is not, and what we do with the result.
§ 08 Start · Free scan
The scan is free and takes a domain. You will get an indicative score, the top risks visible from public sources, and the method limits that qualify both.