Himalogic AI PACE Report

Answer the questions one section at a time. At the end you get a private link to your AI PACE Report.

1. About you

Name
Work email
Your role
When your company decides how to handle something like compliance, who makes the call?
How would you describe your relationship to the technical side of your AI?

Why this matters: We use this to write your report at the right level. No wrong answer.

2. About your business

In a sentence, what does your company sell?
Industry

Why this matters: Some industries carry extra AI rules on top of the general ones, especially education, finance, hiring, and health.

Who are your customers?
Company size
Where is your company based?
Where are your customers or users?
Help / Not sure?

Check every region where people actually use your product. If you sell into the US and are not sure about individual states, leave the states checked (the default).

Why this matters: AI laws generally follow your users, not your headquarters. A company with no EU office can still be covered by the EU AI Act if its AI is used by people in the EU. If you checked "I don't actually know," that's worth knowing too.

3. How you use AI

Which of these describe your company today?
Help / Not sure?

You can check more than one. Pick every line that is true today, not only the most advanced one.

Our product includes AI features built on someone else's model (OpenAI, Anthropic, Google, etc.)

Check this if customers see AI in your product even when the model is from OpenAI, Anthropic, Google, or similar.

We've fine-tuned or retrained a model on our own data

Fine-tuning means training an existing model (from OpenAI, Anthropic, or an open-source model) further on your own data so it behaves differently. Writing detailed prompts, or letting the model search your documents for answers, is not fine-tuning.

We have AI agents that take actions on their own (sending emails, updating records, making purchases)

Check this if the AI can take an action in the world (send, update, buy) without a person approving every step.

None of these yet, but we're planning to

Choose this if AI isn't in your product or work yet but you expect it to be. Answer the rest of the questions based on what you're planning, and your report will reflect that.

Why this matters: The rules treat a company that uses AI very differently from one that provides it. Each step down this list moves you closer to provider territory, which carries the heavier obligations.

Does your AI appear to customers under your company's name or brand?

Why this matters: Under the EU AI Act, putting an AI system on the market under your own name is part of what makes you a "provider." Many companies building on top of OpenAI or Anthropic assume the model company carries the compliance load. Often it doesn't.

Have you changed the underlying model in any way, like fine-tuning it on your data or changing what it was designed to do?

Why this matters: Modifying a model, or using an AI system for a purpose its maker didn't intend, can shift you from "deployer" to "provider" in the eyes of the regulation. Most companies find this out late.

4. What your AI touches

Does your AI ever influence a decision about a person?
Help / Not sure?

Check an option if your AI ranks, scores, flags, or recommends an outcome that affects a person — even if a human still makes the final call.

Whether someone gets hired, promoted, or let go

Include screening, ranking, or scoring of candidates or employees, not only a fully automated hire-or-fire decision.

Whether someone gets a loan, credit, or insurance, or at what price

Count it if your AI scores, ranks, recommends, or flags people in these decisions, even when a person signs off at the end.

Whether a student is admitted, graded, or flagged

This includes admissions, grading or scoring student work, placing students into levels or courses, adjusting what a student learns next based on how they performed, and monitoring students during tests. General study help may not count, but if the AI's judgment of a student affects what happens to them, check this.

Whether someone gets access to housing, benefits, or essential services

This includes screening tenants, setting eligibility for public benefits, and decisions about access to essential services. Count it if your AI ranks, scores, or recommends, even if a person makes the final decision.

Medical or health-related decisions

This includes AI that suggests diagnoses, treatments, or triage, or that analyzes medical images or patient data to inform care. General wellness features may fall outside this, but count it if you're unsure.

Identifying people from their face, voice, or other biometrics

Check this if the AI matches or identifies a person from face, voice, or similar body data.

None of these

Choose this only if your AI doesn't score, rank, recommend, or decide anything about individual people in these areas. If it helps a person make one of these decisions, it still counts.

Why this matters: These are the areas most AI laws treat as "high-risk." In the EU, most high-risk obligations apply from December 2, 2027. Some US states and cities already regulate AI in hiring and lending. If you checked any of these, the classification question is usually one for a lawyer, and it's worth asking early.

Does your AI talk directly with people, like a chatbot, voice agent, or assistant?

Why this matters: In the EU, people generally have to be told when they're interacting with an AI. This transparency rule applies regardless of risk level.

Does your AI generate images, audio, video, or text that ends up in front of the public?

Why this matters: There are disclosure and labeling requirements for AI-generated content, and for content that could pass as real.

Does your AI process any of these?
Help / Not sure?

When you are unsure whether something counts, prefer checking the option. You can refine later with a lawyer or privacy specialist. The tips below are orientation only.

Personal information about customers or users

Check this if your AI sees names, emails, account details, messages, or other information that identifies a person — even if that is not the main point of the feature.

Information about children

If your users are mostly children themselves (for example a school or edtech product), it is very likely they will give your AI some information that could be considered about them. Check this even when you cannot be precise yet. This is orientation only, not a legal conclusion.

Health information

Check this if your AI handles medical records, diagnoses, symptoms, prescriptions, or wellness data tied to a person.

Financial information

Check this if your AI handles bank details, payment history, credit scores, income, or similar money-related data about a person.

Biometric data (faces, voices, fingerprints)

Check this if your AI uses face, voice, fingerprint, or similar body-based identifiers to recognize or verify people.

None of these

Choose this only if your AI never receives information that could identify a person, including names, email addresses, messages from users, or uploaded documents. If users type into your AI, it almost certainly processes personal information.

Why this matters: AI laws stack on top of privacy laws like GDPR. Personal data in an AI system usually means two sets of obligations, not one.

Do you use AI to monitor or evaluate your own employees, or to read people's emotions?

Why this matters: Using AI to infer emotions in the workplace or in schools has been prohibited in the EU since February 2025, with narrow exceptions. Several monitoring tools on the market do this quietly.

5. Visibility and control

If your AI gave a customer a wrong or harmful answer tomorrow, how would you find out?

Why this matters: Most frameworks expect you to monitor AI after it launches, not just test it before. If "a customer would tell us" was your honest answer, you're in good company, and it's one of the most common gaps we see.

If a customer asked why your AI made a specific decision or gave a specific answer, could you show them?

Why this matters: Being able to trace an output back to its inputs, model, and version is a core expectation in ISO 42001 and the EU AI Act. It's also what you'll want when something goes wrong.

Do you know which version of which model is running in your product right now?

Why this matters: Model providers update models, sometimes without much notice. If behavior changes, you'll want to know what changed.

Could you list every AI tool your team uses, including the ones people signed up for on their own?

Why this matters: An inventory of AI systems is the first thing almost every framework asks for. Most companies discover more tools than they expected.

If you needed to switch off an AI feature immediately, who would do it, and how long would it take?

Why this matters: Human oversight, including the ability to stop the system, is a requirement for high-risk AI and good practice for everything else.

6. Where you are now

Has a customer or prospect ever sent you a security or AI questionnaire before signing?

Why this matters: This is often how compliance shows up for the first time. A prospect's procurement team sends a spreadsheet with a hundred questions, and the deal waits until you answer. The first time it happened to us, the reaction was "wait, what?" If it hasn't happened to you yet, it likely will once you start selling to larger companies.

Where are you with each of these?
Help / Not sure?

Pick one answer on each row. "Aligned but not certified" means your policies follow the standard but no outside auditor has checked them. "Certified" means an independent auditor has issued the report or certificate (for SOC 2, an attestation report).

SOC 2

ISO 27001

ISO 42001

A written AI use policy

Why this matters: If you already have SOC 2 or ISO 27001, a good share of the groundwork for AI governance is already in place. ISO 42001 is built on the same structure as ISO 27001.

How have you handled compliance work in the past?

7. What's ahead

What prompted you to look into this?
When does (or did) your AI feature or product reach customers?
Which best describes where you want your AI to go?
What would you most like to get out of your AI PACE Report?

8. Wrap-up

Would you like a copy sent to anyone else on your team?

Up to 3 people. Leave unused rows blank.

Person 1

Why this matters: AI compliance usually touches more than one person: someone technical, someone on the business side, sometimes legal.

Would a conversation about your specific situation be useful?
click here to read our privacy notice before you agree

We collect the answers you give in this questionnaire, including your name, work email, and any teammate contacts you choose to add. We use that information to generate Your AI PACE Report, email you (and any teammates you list) a link to that report, and to understand who may need a follow-up from Himalogic Software.

Himalogic Software (Justin Philip Flores) can see your submission and the private fit signals we compute from it. We do not sell your answers. We do not use tracking or analytics scripts on this form.

While you fill out this form, unfinished answers and which section you are on are saved temporarily in your browser (session storage) so that Next, Back, and a page refresh keep your progress. That draft stays on your device only. It is not sent to Himalogic until you submit. We clear the draft when you successfully submit and reach your report. If you leave without submitting, the draft is discarded when the browser session ends. You can also remove it anytime by clearing this site's data in your browser.

We keep submissions for as long as we need them to provide the report and follow up, then delete them on request or when they are no longer needed. Report links are long random addresses and are not meant to be guessable; anyone with the link can open that report.

To ask questions or request deletion, email security@himalogic.com.

This questionnaire and report are an orientation based on your answers. They are not legal advice and not a gap assessment.