Himalogic AI PACE Report

Answer the questions one section at a time. At the end you get a private link to your AI PACE Report.

1. About you

Name
Work email
Your role
When your company decides how to handle something like compliance, who makes the call?
How would you describe your relationship to the technical side of your AI?

Why this matters: We use this to write your report at the right level. No wrong answer.

2. About your business

In a sentence, what does your company sell?
Industry

Why this matters: Some industries carry extra AI rules on top of the general ones, especially education, finance, hiring, and health.

Who are your customers?
Company size
Where is your company based?
Where are your customers or users?

Why this matters: AI laws generally follow your users, not your headquarters. A company with no EU office can still be covered by the EU AI Act if its AI is used by people in the EU. If you checked "I don't actually know," that's worth knowing too.

3. How you use AI

Which of these describe your company today?

Why this matters: The rules treat a company that uses AI very differently from one that provides it. Each step down this list moves you closer to provider territory, which carries the heavier obligations.

Does your AI appear to customers under your company's name or brand?

Why this matters: Under the EU AI Act, putting an AI system on the market under your own name is part of what makes you a "provider." Many companies building on top of OpenAI or Anthropic assume the model company carries the compliance load. Often it doesn't.

Have you changed the underlying model in any way, like fine-tuning it on your data or changing what it was designed to do?

Why this matters: Modifying a model, or using an AI system for a purpose its maker didn't intend, can shift you from "deployer" to "provider" in the eyes of the regulation. Most companies find this out late.

4. What your AI touches

Does your AI ever influence a decision about a person?

Why this matters: These are the areas most AI laws treat as "high-risk." In the EU, most high-risk obligations apply from December 2, 2027. Some US states and cities already regulate AI in hiring and lending. If you checked any of these, the classification question is usually one for a lawyer, and it's worth asking early.

Does your AI talk directly with people, like a chatbot, voice agent, or assistant?

Why this matters: In the EU, people generally have to be told when they're interacting with an AI. This transparency rule applies regardless of risk level.

Does your AI generate images, audio, video, or text that ends up in front of the public?

Why this matters: There are disclosure and labeling requirements for AI-generated content, and for content that could pass as real.

Does your AI process any of these?

Why this matters: AI laws stack on top of privacy laws like GDPR. Personal data in an AI system usually means two sets of obligations, not one.

Do you use AI to monitor or evaluate your own employees, or to read people's emotions?

Why this matters: Using AI to infer emotions in the workplace or in schools has been prohibited in the EU since February 2025, with narrow exceptions. Several monitoring tools on the market do this quietly.

5. Visibility and control

If your AI gave a customer a wrong or harmful answer tomorrow, how would you find out?

Why this matters: Most frameworks expect you to monitor AI after it launches, not just test it before. If "a customer would tell us" was your honest answer, you're in good company, and it's one of the most common gaps we see.

If a customer asked why your AI made a specific decision or gave a specific answer, could you show them?

Why this matters: Being able to trace an output back to its inputs, model, and version is a core expectation in ISO 42001 and the EU AI Act. It's also what you'll want when something goes wrong.

Do you know which version of which model is running in your product right now?

Why this matters: Model providers update models, sometimes without much notice. If behavior changes, you'll want to know what changed.

Could you list every AI tool your team uses, including the ones people signed up for on their own?

Why this matters: An inventory of AI systems is the first thing almost every framework asks for. Most companies discover more tools than they expected.

If you needed to switch off an AI feature immediately, who would do it, and how long would it take?

Why this matters: Human oversight, including the ability to stop the system, is a requirement for high-risk AI and good practice for everything else.

6. Where you are now

Has a customer or prospect ever sent you a security or AI questionnaire before signing?

Why this matters: This is often how compliance shows up for the first time. A prospect's procurement team sends a spreadsheet with a hundred questions, and the deal waits until you answer. The first time it happened to us, the reaction was "wait, what?" If it hasn't happened to you yet, it likely will once you start selling to larger companies.

Which of these do you already have?

Why this matters: If you already have SOC 2 or ISO 27001, a good share of the groundwork for AI governance is already in place. ISO 42001 is built on the same structure as ISO 27001.

How have you handled compliance work in the past?

7. What's ahead

What prompted you to look into this?
When do you expect your next AI feature or product to reach customers?
Which best describes where you want your AI to go?
What would you most like to get out of your AI PACE Report?

8. Wrap-up

Would you like a copy sent to anyone else on your team?

Up to 3 people. Leave unused rows blank.

Person 1

Why this matters: AI compliance usually touches more than one person: someone technical, someone on the business side, sometimes legal.

Would a conversation about your specific situation be useful?

[CONTENT NEEDED: privacy notice]