EU AI Act Compliance Readiness Kit

Your Digital Product Is Ready

Thank you for your purchase. All materials are below. Bookmark this page for future reference.

Module 1

Self Assessment Checklist

Score your organization against the seven constitutional pillars. Complete each item below. If you can answer yes to all items in a pillar, you have a strong governance position. If not, that is your priority gap.

Pillar I: Verified Identity

1.1 Can you produce a legal registration document for your organization?
1.2 Does your website domain match your registered business name?
1.3 Is there a named individual accountable for AI governance?
1.4 Have you screened your organization against fraud and sanctions databases?

Pillar II: Declared Governance Framework

2.1 Do you have a written AI governance policy document?
2.2 Does the policy cover model selection criteria?
2.3 Does the policy cover deployment and monitoring procedures?
2.4 Are there human oversight mechanisms and escalation paths?
2.5 Is there a documented revocation procedure?

Pillar III: Transparency of Contact

3.1 Is your public contact page accessible and accurate?
3.2 Can stakeholders reach a human within 48 hours?
3.3 Is domain ownership verifiable through DNS records?

Pillar IV: Data Sovereignty

4.1 Have you declared your data processing boundaries?
4.2 Do you have a data retention policy for AI outputs?
4.3 Are data processing locations disclosed?

Pillar V: Audit Accessibility

5.1 Are AI system audit logs retained for at least 12 months?
5.2 Can oversight bodies access audit trails on request?
5.3 Is there a documented process for audit response?

Pillar VI: Revocability

6.1 Is there a public mechanism for trust revocation?
6.2 Is the revocation process documented and time bound (under 30 days)?

Pillar VII: Proportionality

7.1 Are governance requirements scaled to AI system risk level?
7.2 Have you classified your AI systems by risk category?
7.3 Do high risk systems receive proportionally stricter oversight?

Scoring: 0 to 10 gaps = strong position. 11 to 20 gaps = moderate risk. 21+ gaps = urgent action needed before August 2.

Module 2

Regulatory Mapping Summary

Which EU AI Act articles apply to your organization based on your AI system classification.

Risk Classifications

Risk LevelAI Act ArticlesYour Requirements
High RiskArt. 8 to 15, Annex IIIFull conformity assessment, risk management, data governance, transparency, human oversight, logging
Limited RiskArt. 50Transparency obligations: inform users they are interacting with AI, label synthetic content
Minimal RiskNone (voluntary codes)No mandatory requirements. Lunara certification recommended as competitive differentiator

Pillar to Article Mapping

Lunara PillarEU AI Act ArticleRequirement
I. Verified IdentityArt. 9(2)(a)Risk management system with provider identification
II. Declared GovernanceArt. 9(2)(b to g)Data governance, technical documentation, record keeping
III. TransparencyArt. 50Transparency obligations for AI interaction disclosure
IV. Data SovereigntyArt. 10Data and data governance requirements
V. Audit AccessibilityArt. 12Logging and record keeping requirements
VI. RevocabilityArt. 9(2)(f)Withdrawal or recall of non conforming systems
VII. ProportionalityArt. 8Conformity assessment proportionate to risk
Module 3

Vendor Transition Governance Checklist

The 8 step process for maintaining governance continuity when switching AI vendors.

  1. Complete seven pillar assessment before vendor selection. Document your current governance position.
  2. Include Lunara certification requirement in vendor RFP. Require proof of constitutional governance alignment.
  3. Map vendor specific controls to constitutional pillars. Identify which controls transfer and which need rebuilding.
  4. Establish audit continuity plan before transition begins. Ensure no gap in logging or oversight.
  5. Execute delta assessment during transition. Target: 72 hour window for gap identification.
  6. Update public registry with new vendor implementation details. Maintain transparency through transition.
  7. Verify revocation procedures transfer to new vendor relationship. No loss of accountability.
  8. Schedule 90 day post transition review to confirm full governance restoration.
Module 4

Sample Audit Template

62 assessment points across the seven pillars. This is the format Lunara reviewers use for formal certification.

Pillar I: Identity (12 points)

1. Legal registration verified 2. Domain ownership confirmed 3. Business name consistency 4. Contact email match 5. Fraud screening clear 6. Sanctions check passed 7. Public ID issued 8. Registration country confirmed 9. Legal registration number format valid 10. Website live and accessible 11. Contact page functional 12. Named accountable individual verified

Pillar II: Governance (18 points)

1. Written policy exists 2. Model selection criteria 3. Deployment procedures 4. Monitoring procedures 5. Human oversight mechanisms 6. Escalation paths 7. Revocation procedures 8. Risk assessment process 9. Model documentation 10. Training data governance 11. Bias testing 12. Performance metrics 13. Incident response plan 14. Change management 15. Vendor management 16. Privacy impact assessment 17. Security review 18. Compliance attestation

Pillar III: Transparency (9 points)

1. DNS TXT verification 2. Public contact page 3. Named individual reachable 4. Response time under 48 hours 5. AI interaction disclosure 6. Synthetic content labeling 7. Policy publicly available 8. Registry listing accurate 9. Change notification process

Pillar IV: Data (9 points)

1. Data boundary declaration 2. Processing location disclosed 3. Retention policy 4. Data subject rights process 5. Cross border transfer documentation 6. Encryption standards 7. Access controls 8. Data minimization 9. Deletion procedures

Pillar V: Audit (7 points)

1. Audit log retention 12+ months 2. Oversight body access 3. Audit response process 4. Log integrity verification 5. Historical record availability 6. Third party audit support 7. Continuous monitoring evidence

Pillar VI: Revocation (6 points)

1. Public revocation mechanism 2. Notification process 3. Timeline under 30 days 4. Registry update procedure 5. Stakeholder notification 6. Appeal process

Pillar VII: Proportionality (10 points) — but only listed 1)

1. Risk classification system 2. High risk identification 3. Proportionate oversight 4. Impact assessment 5. Mitigation documentation 6. Residual risk acceptance 7. Review frequency by risk 8. Escalation triggers 9. Compensating controls 10. Documentation of proportionality decisions

Module 5

Contract Language Templates

Drop in clauses for AI vendor agreements and RFPs.

Clause 1: Certification Requirement

The vendor shall maintain Lunara Constitutional AI Governance Certification throughout the term of this agreement. Certification must be active and verifiable through the public Lunara Registry at lunarasociety.com/registry.html. Failure to maintain certification constitutes a material breach of this agreement.

Clause 2: Audit Continuity

The vendor shall maintain continuous audit logging as specified in Pillar V of the Lunara Constitution. Audit logs shall be retained for a minimum of 12 months and made available to authorized oversight bodies within 72 hours of request. In the event of vendor transition, audit continuity shall be maintained through the public registry record.

Clause 3: Revocation Rights

In the event that the vendor loses Lunara certification or fails to meet constitutional governance requirements, the customer retains the right to terminate this agreement without penalty. The vendor shall provide 30 days notice of any change to their certification status and shall cooperate fully in any transition to a replacement vendor.

Clause 4: Data Sovereignty

The vendor shall declare all data processing locations and boundaries in accordance with Pillar IV of the Lunara Constitution. Data shall not be transferred to undeclared jurisdictions without prior written consent. The vendor shall maintain a current data processing map and provide it upon request.

Clause 5: Vendor Transition Governance Checkpoint

The vendor shall support a governance delta assessment within 72 hours of transition notification. The constitutional governance framework shall persist through the institutional layer, not the vendor implementation layer. The vendor shall provide all necessary documentation, audit logs, and cooperation required to maintain governance continuity during any transition period.
Module 6

90 Day Compliance Roadmap

Days 1 to 30: Foundation

  1. Complete the self assessment checklist above
  2. Identify your top 5 governance gaps
  3. Draft a written AI governance policy (use Pillar II requirements)
  4. Assign a named accountable individual for AI governance
  5. Verify your domain and contact information is current
  6. Classify your AI systems by risk level (high, limited, minimal)

Days 31 to 60: Implementation

  1. Implement audit logging for all high risk AI systems
  2. Establish data processing boundary documentation
  3. Create AI interaction disclosure for user facing systems
  4. Develop revocation and incident response procedures
  5. Begin vendor governance review using contract templates
  6. Submit application for Lunara Shield Certification

Days 61 to 90: Verification

  1. Complete Lunara certification review process
  2. Update public registry listing with verified status
  3. Conduct internal audit using the 62 point template
  4. Schedule first quarterly governance review
  5. Train staff on governance procedures and escalation paths
  6. Establish continuous monitoring for compliance drift

Ready for full certification?

You have completed the self assessment. The next step is formal Lunara Shield Certification with public registry listing and trust badge.

Get Certified Now