European Union - Trustworthy AI Assessment

Assessment List for Trustworthy Artificial Intelligence (ALTAI) — self-assessment tool

European Union

RAI-EU-NA-ALTAIXX-2020
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

ALTAI is a voluntary self-assessment checklist published by the EU High-Level Expert Group on AI to operationalise the Ethics Guidelines for Trustworthy AI. Released on 17 July 2020, it offers developers, deployers and procurers an actionable tool to evaluate AI systems against seven key requirements for trustworthy AI.

Summary

The Assessment List for Trustworthy Artificial Intelligence (ALTAI) is a practical, voluntary self-assessment framework produced by the EU High-Level Expert Group on Artificial Intelligence (AI HLEG) and published on 17 July 2020. ALTAI translates the High-Level Expert Group’s earlier "Ethics Guidelines for Trustworthy AI" (published 8 April 2019) into an operational checklist and prototype web tool to assist AI developers, deployers and procurers in evaluating and documenting how an AI system meets the seven key requirements of Trustworthy AI: human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; societal and environmental well-being; and accountability. The tool resulted from an extended piloting phase (June–December 2019) involving hundreds of stakeholders and was published by the European Commission as a downloadable PDF and as an interactive web prototype maintained by partners. ALTAI is not a binding regulation; rather, it is intended as guidance and a practical instrument to promote responsible design, risk identification and mitigation, documentation and internal governance. It encourages organisations to conduct structured self-assessments, document outcomes, adopt risk mitigation measures, and keep records that support internal accountability and potential external scrutiny. While ALTAI itself does not create enforcement powers or statutory penalties, its use can support compliance with binding EU instruments such as the GDPR and — where applicable — the future EU AI Act (and sectoral rules). The list and web tool emphasise cross-cutting measures including governance and oversight roles, privacy and data governance arrangements, robustness and safety testing, explainability and transparency measures, bias mitigation and fairness testing, lifecycle monitoring and update practices, and accountability documentation. The framework is intentionally technology- and sector-neutral and has been positioned as useful across domains including healthcare and finance, among others. Official sources and the prototype web tool are published and linked by the European Commission and partner organisations, and the EU continues to reference ALTAI as a building block in broader AI governance and standardisation activities.

Full article

Read full text ↗

Overview

The Assessment List for Trustworthy Artificial Intelligence (ALTAI) is a voluntary self-assessment checklist and prototype web tool developed under the auspices of the EU High-Level Expert Group on AI and published on 17 July 2020 to operationalise the Ethics Guidelines for Trustworthy AI. ALTAI guides AI developers, deployers and procurers through a structured set of questions and recommended practices aligned to the seven key requirements for trustworthy AI. The instrument was produced after a piloting phase that engaged hundreds of stakeholders and exists in both PDF and interactive web forms, including a prototype maintained by a partner research centre. ALTAI aims to make ethical and legal requirements actionable, help teams identify risks and gaps in processes or documentation, and provide a baseline for internal governance and documentation that can support future conformity assessments or regulatory reviews. ALTAI is not a binding legal instrument but rather a practical tool to translate ethical principles into concrete engineering, governance and documentation tasks; it is referenced by the European Commission as a resource for organisations seeking to embed trustworthiness in AI systems (ALTAI publication).

Definitions

For purposes of ALTAI, key terms are defined consistent with the Ethics Guidelines and Commission communications. "Trustworthy AI" denotes AI that is lawful, ethical and robust (technical and social) and that meets seven requirements: human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; societal and environmental well-being; and accountability. "Developer" means the natural or legal persons who create, design or train an AI system; "deployer" refers to those who integrate or put an AI system into operation; "self-assessment" refers to an internal, documented review against the ALTAI checklist designed to surface gaps, risks and mitigation strategies. The list treats 'system lifecycle' as the end-to-end phases of design, development, testing, deployment, monitoring and decommissioning. ALTAI intentionally uses practical operational language (questions, evidence requests, and suggested actions) to facilitate cross-disciplinary teams in providing concrete evidence of trustworthiness steps.

Governance and Institutional Framework

ALTAI situates governance responsibilities within organisations by recommending clear assignments of roles and oversight mechanisms. It encourages the appointment of accountable persons or committees (e.g., AI ethics officers, data protection officers, governance boards) to oversee the self-assessment process, require documented sign-off on findings, and integrate remediation actions into project management and procurement workflows. The European Commission hosts the official ALTAI publication and references the tool in its wider AI policy work; the prototype web tool is available via partner-hosted platforms such as the ALTAI prototype site and is linked from the Commission’s digital strategy pages (ALTAI entry). At institutional level, use of ALTAI supports compliance with existing EU governance obligations such as documentation under GDPR and can create auditable artefacts for internal audit, procurement, or future conformity assessment steps aligned with forthcoming EU legislation. The governance section of ALTAI emphasises continuous governance (not one-off checks), cross-functional participation (legal, technical, domain specialists), and escalation paths when high risks are identified.

Key Focus Areas

ALTAI operationalises the seven key requirements through concrete focus areas and question sets. Human agency and oversight: ensures human-in-the-loop, appropriate decision thresholds, and mechanisms for human review and override. Technical robustness and safety: requires risk analyses, resilience testing, adversarial testing, validation across edge cases and secure operation. Privacy and data governance: asks for data minimisation, provenance tracking, consent and lawful bases, data quality and bias assessment, and secure storage and access controls. Transparency: focuses on documentation (model cards, data statements), explainability measures appropriate to the use case and audience, and communication to end-users about AI involvement. Diversity, non-discrimination and fairness: includes demographic testing, fairness metrics, and mitigation strategies. Societal and environmental well‑being: examines expected social impact, environmental footprint, and safeguards against misuse. Accountability: calls for record-keeping, logging of decisions, impact assessments and escalation procedures. The checklist presents these areas as a combination of diagnostic questions and practical resources so that teams can link responses to evidence such as design documents, test reports, source-control logs, or privacy impact assessments. ALTAI’s structure encourages lifecycle thinking—requirements are considered at design, training, deployment and monitoring stages so that organisations plan remediation and monitoring from the outset.

Implementation Framework

ALTAI is designed for pragmatic organisational adoption. Typical implementation steps include: (1) identify the system(s) and stakeholders for assessment (scope and boundary setting); (2) run the ALTAI checklist collaboratively across legal, technical, product and domain teams; (3) collect and link evidence (documents, tests, datasets, controls); (4) classify identified risks and prioritise mitigations; (5) produce an assessment report and remediation plan; and (6) integrate monitoring metrics and repeat assessments on a defined cadence. The web prototype facilitates stepwise completion and stores responses for internal records, while the PDF version provides a printable checklist. The framework supports tailoring questions to sectoral guidance (for example, healthcare or financial services), and encourages using ALTAI outputs to inform contracts, procurement tenders, and third-party due diligence. The Commission’s pages present ALTAI as complementary to other EU instruments and an input into standardisation and sectoral policy development (ALTAI library entry).

Monitoring and Evaluation

ALTAI encourages organisations to adopt ongoing monitoring and evaluation practices rather than one-off reviews. Recommended monitoring includes automated logging of model performance and fairness metrics, drift detection, periodic re-running of tests against updated datasets, incident tracking and post‑deployment audits. ALTAI also suggests periodic re-assessment triggered by material changes: major retraining events, new data sources, design changes, or new use-case deployments. The tool’s outputs can feed governance dashboards and internal audit cycles. Although ALTAI does not itself prescribe standard metrics, it points teams to established testing methodologies and encourages documentation of the chosen metrics, rationales and thresholds. Where available, organisations are advised to reference sectoral standards and accreditation processes to ensure monitoring practices meet external expectations.

Penalties, Liability, and Appeals

ALTAI is a voluntary self-assessment instrument and does not by itself establish statutory penalties, liability rules or formal appeal mechanisms. The checklist is intended to generate evidence and maturity in organisations’ risk management and documentation. However, documented ALTAI assessments — or the absence thereof — may inform regulatory or judicial determinations under binding laws (for example, GDPR obligations on data protection or national liability laws) and may influence enforcement or civil liability outcomes if systems cause harm. The European Commission positions ALTAI as complementary to legal instruments; organisations should therefore treat ALTAI outputs as part of a broader compliance strategy. In practice, failure to adopt recommended safeguards identified through ALTAI could increase exposure to regulatory sanctions or litigation arising under applicable EU or national rules, while good documentation may mitigate enforcement exposure by demonstrating due diligence.

Relationship to Other Instruments

ALTAI explicitly implements and operationalises the High-Level Expert Group’s Ethics Guidelines for Trustworthy AI (April 2019). It is published and linked by the European Commission’s digital strategy and Futurium platforms (ALTAI publication, Futurium notice). ALTAI is complementary to the GDPR (Regulation (EU) 2016/679) in data governance areas and is intended to feed into future conformity assessment and standardisation work under EU AI policy such as the proposed EU AI Act and sectoral rules. The framework also aligns with OECD and UNESCO recommendations and can be used alongside domain-specific impact assessment tools, model documentation practices (e.g., model cards), and technical evaluation suites for robustness, fairness and privacy-preserving methods.

International Alignment

While produced for EU audiences, ALTAI is technology- and sector-neutral and has been used internationally as a voluntary good-practice instrument. The checklist design and the underlying seven requirements reflect principles similar to those in international frameworks (e.g., OECD Principles on AI, UNESCO recommendations). The European Commission and stakeholders encourage alignment between ALTAI outputs and global standards work; the prototype and guidance are referenced in dialogues with international partners and standardisation bodies. ALTAI’s adaptability allows non-EU organisations to adopt its processes to meet local legal requirements while benefiting from EU best-practice guidance. The web-based prototype and public dissemination facilitate international uptake and cross-jurisdictional learning.

Implementation Timeline

EventDateNotes
Pilot launch (open consultation & pilot testing)2019-06-26Piloting of assessment list commenced, open to stakeholders.
Pilot phase close2019-12-01Pilot feedback collected from ~350+ stakeholders across sectors.
Ethics Guidelines published (AI HLEG)2019-04-08Foundational document setting seven requirements for Trustworthy AI.
ALTAI final publication (PDF & web prototype)2020-07-17Final Assessment List released by AI HLEG and published by European Commission.
Prototype web tool launch (partner-hosted)2020-07-17Interactive prototype available via partner site (insight-centre).
Commission library entry last updated2025-11-11European Commission 'Shaping Europe’s digital future' library page shows recent update.

Sources and References

SourceType
Assessment List for Trustworthy Artificial Intelligence (ALTAI) — European Commission (Shaping Europe’s digital future)Primary Source
AI HLEG - Assessment List for Trustworthy Artificial Intelligence (ALTAI) — FuturiumPrimary Source
ALTAI prototype web tool — Insight Centre (prototype host)Primary Source
Ethics Guidelines for Trustworthy AI — European Commission (AI HLEG)Primary Source

Requirements for a company

What an organisation has to do under European Union - Trustworthy AI Assessment, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

12
  • Appoint accountable persons or committees to oversee the self-assessment process.Organisations developing, deploying, or procuring AI systems.
  • Integrate identified remediation actions into project management and procurement workflows.Organisations developing, deploying, or procuring AI systems.
  • Produce an assessment report and remediation plan after running the ALTAI checklist.Organisations conducting ALTAI self-assessments.
  • Document the AI system's scope, boundaries, and intended uses.Developers, deployers, and procurers of AI systems.
  • Implement and document human oversight measures for AI systems.Developers, deployers, and procurers of AI systems.
  • Establish and document robust data governance practices, including provenance and quality checks.Developers, deployers, and procurers of AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under European Union - Trustworthy AI Assessment, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organisations developing, deploying, or procuring AI systems.Appoint accountable persons or committees to oversee the self-assessment process.
It encourages the appointment of accountable persons or committees... to oversee the self-assessment process.
Governance and Institutional FrameworkImportant
2Organisations developing, deploying, or procuring AI systems.Integrate identified remediation actions into project management and procurement workflows.
...integrate remediation actions into project management and procurement workflows.
Governance and Institutional FrameworkImportant
3Organisations conducting ALTAI self-assessments.Produce an assessment report and remediation plan after running the ALTAI checklist.
(5) produce an assessment report and remediation plan;
Implementation FrameworkImportant
4Developers, deployers, and procurers of AI systems.Document the AI system's scope, boundaries, and intended uses.
Scope and system description: Design documents, system boundary, intended uses and data flows.
Before placing on marketCompliance ChecklistImportant
5Developers, deployers, and procurers of AI systems.Implement and document human oversight measures for AI systems.
Human agency and oversight: ensures human-in-the-loop, appropriate decision thresholds, and mechanisms for human review and override.
Before placing on marketKey Focus AreasImportant
6Developers, deployers, and procurers of AI systems.Establish and document robust data governance practices, including provenance and quality checks.
Privacy and data governance: asks for data minimisation, provenance tracking, consent and lawful bases, data quality and bias assessment.
Before placing on marketKey Focus AreasImportant
7Developers, deployers, and procurers of AI systems.Conduct and document technical robustness and safety testing, including adversarial tests.
Technical robustness and safety: requires risk analyses, resilience testing, adversarial testing, validation across edge cases and secure operation.
Before placing on marketKey Focus AreasImportant
8Developers, deployers, and procurers of AI systems.Address diversity, non-discrimination, and fairness through testing and mitigation strategies.
Diversity, non-discrimination and fairness: includes demographic testing, fairness metrics, and mitigation strategies.
Before placing on marketKey Focus AreasImportant
9Developers, deployers, and procurers of AI systems.Ensure transparency through comprehensive documentation, explanations, and user communication.
Transparency: focuses on documentation (model cards, data statements), explainability measures appropriate to the use case and audience.
Before placing on marketKey Focus AreasImportant
10Developers, deployers, and procurers of AI systems.Maintain accountability records, including logging decisions and impact assessments.
Accountability: calls for record-keeping, logging of decisions, impact assessments and escalation procedures.
Key Focus AreasImportant
11Deployers of AI systems.Adopt ongoing monitoring and evaluation practices for AI system performance and risks.
ALTAI encourages organisations to adopt ongoing monitoring and evaluation practices rather than one-off reviews.
Monitoring and EvaluationImportant
12Deployers of AI systems.Conduct periodic re-assessments of AI systems, especially after material changes.
ALTAI also suggests periodic re-assessment triggered by material changes: major retraining events, new data sources, design changes.
Monitoring and EvaluationImportant

© Regulations.AI · updated on 13-Jun-2026