Krasper Technologies

AI Gap Analysis: EU AI Act, ISO 42001 and UAE AI Rules

Krasper Technologies runs a structured gap analysis of your AI use against the EU AI Act, ISO/IEC 42001 and the relevant UAE AI rules. The result is a register of gaps, mapped to evidence, with a roadmap you can prioritise and cost. It does not certify compliance; it tells you where you stand and what to do next.

Last reviewed
Reviewed by
Hannes Krauss, Founder

Who this is for

This assessment suits organisations that deploy or build AI systems in the UAE, serve customers in the EU, or both. It fits a company relying entirely on third party AI tools as much as one training or fine tuning its own models. If you cannot currently list every AI system in use, that is itself a common starting point, not a disqualifier.

It also suits organisations preparing for a client questionnaire, a procurement requirement or an internal audit that asks about AI governance, and want a factual answer before they commit to a programme.

What we assess

We build an inventory of the AI systems in scope: the models, the vendors, the data they process and the purpose each system serves. For each system we classify its likely risk tier and establish whether your organisation acts as a provider, a deployer, or both, since the EU AI Act attaches different obligations to each role.

We also look at the data and model supply chain behind each system: where training and input data comes from, what contractual terms govern a third party model, and where a vendor's own claims about its system need independent verification rather than acceptance at face value.

The frameworks

The EU AI Act sets obligations by risk tier, including the deployer duties in Article 26 for organisations that use a high-risk AI system without being its provider, and a fuller set of requirements for providers of high-risk systems themselves. We assess exposure against the tiers and obligations that apply to your systems, without assuming a tier or a duty that has not been established for your case.

ISO/IEC 42001 specifies the controls of an AI management system: policy, roles, risk management, resourcing, monitoring and continual improvement. We assess which of those controls already exist in some form, which are documented but not operated, and which are missing.

In the UAE, we assess against the UAE Charter for the Development and Use of Artificial Intelligence, Dubai's AI policy and ethics guidance where it applies to your operations, and, where personal data is processed through autonomous or semi-autonomous systems, DIFC Data Protection Regulation 10. Applicability depends on your sector, emirate and free zone, and we establish that scope with you rather than assuming it.

Ready to secure your
enterprise infrastructure?

Schedule a technical briefing. No sales pitch, just architects and your team.

What you get

A gap register that lists each requirement against your current state, with a plain description of what is missing or unverified. A roadmap that prioritises those gaps by risk and groups them into phases you can plan and cost, rather than a single undifferentiated list. And a mapping from each control back to the evidence that would demonstrate it, so your team knows what to produce and keep.

How an engagement runs

We scope the engagement around the AI systems you want assessed. Work then moves through evidence review of your existing documentation and configurations, structured interviews with the people who own and operate each system, and a findings workshop where we walk through the draft gap register with you before the report is finalised.

Duration and cost are scoped to the number of AI systems in scope and the depth of evidence available; we do not quote a fixed timeline in advance of that scoping conversation.

Where this leads

The gap analysis is the starting point. Once you have a prioritised, costed roadmap, implementation continues in our AI governance consulting programme, which turns the roadmap into operating policies, control implementation and ongoing review. You are free to take the gap register to another provider, or to your own team, instead.

AI gap analysis: common questions

Do we need a gap analysis if we only use third-party AI tools?

Yes. Using a vendor's model does not remove your own obligations as a deployer under the EU AI Act, and it does not remove the need to understand what that vendor does with your data. The assessment covers third-party tools as thoroughly as systems you build yourselves.

Does the EU AI Act apply to a UAE company?

It can, depending on whether your AI system's output is used within the EU or affects people located there, regardless of where your organisation is established. We assess that applicability as part of the engagement rather than assuming it either way.

How does this relate to ISO 42001 certification?

The gap analysis assesses your position against ISO/IEC 42001's control set and produces evidence you can use toward certification readiness. It does not itself certify anything: certification is issued by an accredited certification body following its own audit, and this engagement does not guarantee that outcome.

Can you assess against UAE rules only?

Yes. If the EU AI Act does not apply to your organisation, we scope the assessment to the UAE Charter for the Development and Use of Artificial Intelligence, applicable Dubai AI policy, and DIFC Data Protection Regulation 10 where relevant, together with ISO/IEC 42001 if you want that reference included.

What happens after the report?

You receive the gap register, the roadmap and the evidence mapping to keep and act on. Many clients continue into our AI governance consulting programme to implement the roadmap; others take the report to their own team or another provider.

Connect the gap analysis with delivery