EU AI Act Risk Classification Checker
Find out your EU AI Act risk tier in 5 minutes. Answer the questions about your AI system and get your risk tier — unacceptable, high, limited, or minimal — with a compliance checklist citing the exact articles.
1. How would you describe your AI system?
The AI Act distinguishes AI embedded as a safety component of a regulated product from a standalone AI system. This decides which high-risk annex applies (Annex I vs Annex III).
2. Which sector does the regulated product fall under?
Annex I, section A lists the Union harmonisation legislation. If the product requires third-party conformity assessment, the AI safety component is high-risk (Article 6(1)).
3. Does the system do any of these?
These are the prohibited practices in Article 5. If the answer to any one is yes, the system is banned from the EU market (Unacceptable risk).
If you answered Yes to any of 3a–3d, you can classify now — those practices are banned regardless of other factors.
4. Is the system used in any of these high-risk areas? Annex III
Select every use that applies. Each one makes the system high-risk under Article 6(2). Leave all unchecked if none apply.
5. Does the system produce content a person could mistake for human-made?
This is the transparency trigger for limited-risk (Article 50). It covers chatbots, deepfakes, AI-generated text/audio/images/video, and emotion-recognition or biometric-categorisation systems not already high-risk.
6. Is this a general-purpose AI model?
A GPAI model is trained on broad data at scale and is capable of serving a wide range of downstream tasks (e.g. a large foundation model like a frontier LLM). GPAI models have their own obligations under Articles 51–55.
Compliance checklist
Not legal advice. This is an informational classifier based on the EU AI Act (Regulation (EU) 2024/1689). For binding compliance, consult a qualified lawyer or notified body.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's horizontal framework for regulating artificial intelligence. It entered into force on 1 August 2024 and applies obligations in phases through 2027. Rather than banning AI, it sorts AI systems into four risk tiers and attaches obligations proportionate to the harm each tier can cause. The philosophy is simple: the greater the potential impact on people's safety and fundamental rights, the stricter the rules.
The four tiers are Unacceptable (banned outright), High-risk (permitted subject to strict obligations), Limited-risk (transparency duties), and Minimal-risk (voluntary codes of conduct). The checker above maps your answers to this taxonomy.
Who it applies to — including non-EU companies
The AI Act has extraterritorial reach. Article 2 makes it apply to any provider whose AI system is placed on the Union market or whose output is used in the EU, regardless of where the provider is established. A US, UK, or Chinese company whose model serves EU users — directly or through a downstream deployer — is in scope. It also binds deployers (the organisations that actually use a high-risk system) and importers, distributors, and authorised representatives located in the EU.
The August 2026 high-risk deadline
The most consequential date for most teams is 2 August 2026. On that date, the obligations for high-risk AI systems in Articles 9 to 17 became applicable, along with most Annex III high-risk categories (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice). Transparency duties for limited-risk systems (Article 50) and the rules for GPAI providers also apply from this date.
Three earlier dates are already in force: the prohibited-practices ban (Article 5) applied from 2 February 2025, general-purpose AI model obligations and AI literacy duties applied from 2 August 2025. One later date remains: 2 August 2027, when high-risk status applies to AI safety components embedded in products that themselves require third-party conformity assessment under Annex I, section B.
If your system is high-risk and you are not yet compliant with Articles 9 to 15, you are already exposed to enforcement and to fines of up to EUR 15 million or 3% of global turnover.
How risk classification works (the decision tree)
The checker above follows the Act's own decision logic. First it screens for prohibited practices (Article 5) — subliminal manipulation, exploitation of vulnerabilities, social scoring, untargeted facial-image scraping, emotion inference in workplaces and schools, social scoring, and real-time remote biometric identification in public spaces for law enforcement. If any applies, the system is Unacceptable and cannot be placed on the EU market at all.
If nothing is prohibited, it checks the two routes into High-risk status. The first is Annex I: an AI system that is a safety component of a regulated product — a medical device, machinery, a vehicle, a toy, a lift, or another product under Union harmonisation law — where that product itself requires third-party conformity assessment (Article 6(1)). The second is Annex III (Article 6(2)): standalone uses in eight sensitive areas, from biometric identification and critical infrastructure to employment, credit scoring, law enforcement, migration, and the administration of justice.
If the system is not high-risk, the checker asks about transparency (Article 50). Chatbots, deepfakes, AI-generated text, and emotion-recognition or biometric-categorisation systems trigger a lighter-touch regime: inform users they are interacting with AI and label synthetic content. Finally, for general-purpose AI models, it checks the systemic-risk threshold of 10²⁵ FLOPs (Annex XIII, Article 51), which adds model-evaluation and incident-reporting duties on top of the tier. Anything that clears none of these gates is Minimal-risk.
What high-risk obligations actually require (Articles 9 to 15)
A high-risk classification is not a ban — it is a list of engineering and governance duties you must satisfy before placing the system on the market and maintain throughout its life cycle. The core requirements are concentrated in Articles 9 to 15.
- Article 9 — Risk management system. A continuous, iterative process to identify, analyse, evaluate, and mitigate known and reasonably foreseeable risks. It runs across the lifecycle, not just at launch.
- Article 10 — Data and data governance. Training, validation, and testing datasets must be relevant, sufficiently representative, and free of errors to the extent possible. Special care is required for biases.
- Article 11 — Technical documentation. A complete record (Annex IV) covering the system's intended purpose, the data, the model architecture, training and testing, and post-market monitoring, kept before market placement and maintained current.
- Article 12 — Record-keeping (logging). Automatic event-logging capabilities to ensure traceability of the system's operation over time.
- Article 13 — Transparency to deployers. The system must come with clear instructions for use so deployers can interpret output and exercise oversight.
- Article 14 — Human oversight. The system must allow effective human oversight, appropriate to the autonomy and context, so a person can remain in meaningful control.
- Article 15 — Accuracy, robustness, and cybersecurity. The system must achieve appropriate levels of accuracy and be resilient against errors, faults, and attacks throughout its lifecycle.
Beyond Articles 9 to 15, high-risk providers need a quality-management system (Article 17), undergo the appropriate conformity-assessment procedure (Articles 43 to 47), affix the CE marking, register the system in the EU database (Article 49), and run post-market monitoring (Article 72) with a serious-incident reporting duty (Article 73).
Penalties
Enforcement is handled by national market-surveillance authorities and the EU AI Office, and the fines under Article 99 are deliberately large:
- Up to EUR 35 million or 7% of worldwide annual turnover (whichever is higher) for breaching the prohibited-practices rules in Article 5.
- Up to EUR 15 million or 3% of worldwide annual turnover for breaching the high-risk obligations, transparency duties, or GPAI provider obligations.
- Up to EUR 7.5 million or 1% of worldwide annual turnover for supplying incorrect, incomplete, or misleading information to notified bodies or national authorities.
For small and medium-sized enterprises and start-ups, each fine is capped at the lower of the percentage or the fixed amount.
How this checker works
This tool is a deterministic, rule-based classifier. Your answers are mapped to the same decision logic the AI Act itself uses — prohibited practices first, then Annex I and Annex III high-risk triggers, then Article 50 transparency, then the GPAI systemic-risk threshold. There is no machine-learning model, no API call, and no server. Every question and every result is computed locally in your browser by ordinary JavaScript, and your inputs are discarded the moment you close the tab.
The trade-off is that the checker cannot capture every nuance: borderline cases, deployer-specific duties, exemptions for scientific research and military use, and the interaction between the AI Act and sector-specific law all need human judgement. Use the result as a fast first read; then take it to a qualified lawyer or a notified body for a binding assessment.
Frequently asked questions
Does the EU AI Act apply to US companies?
Yes. The AI Act has extraterritorial scope (Article 2). If an AI system is placed on the Union market, put into service in the Union, or its output is used in the EU, the rules apply — regardless of where the provider is established. US companies whose AI output reaches EU users must comply.
What is the August 2026 deadline?
On 2 August 2026, the core obligations for high-risk AI systems (Articles 9 to 17) and most transparency rules became applicable, along with the bulk of Annex III high-risk categories. A narrower set of high-risk systems — safety components of regulated products that require third-party conformity assessment (Annex I, section B) — apply from 2 August 2027. Prohibited practices applied from 2 February 2025 and general-purpose AI model rules from 2 August 2025.
What are the fines under the EU AI Act?
Under Article 99, non-compliance is tiered: up to EUR 35 million or 7% of total worldwide annual turnover (whichever is higher) for violations of the prohibited-practices rules (Article 5); up to EUR 15 million or 3% for breaches of the obligations on high-risk systems, transparency, or GPAI providers; and up to EUR 7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities. For SMEs and start-ups, the fine is capped at the lower of the percentage or the fixed amount.
Is a chatbot high-risk under the AI Act?
Generally no. A standard customer-service or general-purpose chatbot is treated as limited-risk and only triggers transparency duties: you must inform users they are interacting with an AI system (Article 50(1)). A chatbot becomes high-risk only when used in a high-risk context listed in Annex III — for example screening job applicants (employment), grading students (education), or evaluating creditworthiness (essential services).
What makes a general-purpose AI model "systemic risk"?
A GPAI model is presumed to pose systemic risk when the cumulative compute used for its training exceeded 10^25 FLOPs (Annex XIII, Article 51). Providers of such models face extra obligations under Articles 51 to 55, including model evaluation, adversarial testing, systemic-risk assessment, and incident reporting. The Commission can also designate a model as systemic on a case-by-case basis.
Does this checker give legal advice?
No. The checker is an informational classifier that maps your answers to the AI Act risk tiers and summarises the corresponding obligations. It is a decision-support tool, not legal advice, and it cannot capture every nuance of your situation. For a binding classification and compliance plan, consult a qualified lawyer or a conformity-assessment body.
Is my data stored or sent anywhere?
No. Every question you answer and every result is computed locally in your browser by JavaScript. Nothing is uploaded to a server, there is no backend database, and closing the tab discards your answers. The only network calls are for analytics and ads, which do not include your questionnaire inputs.
What is the difference between Annex I and Annex III high-risk?
Annex I lists AI systems that are safety components of products already covered by EU harmonisation law — medical devices, machinery, motor vehicles, toys, lifts, and similar. These are high-risk when the product itself requires third-party conformity assessment (Article 6(1)). Annex III lists standalone AI uses deemed high-risk regardless of any product: biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration and border control, and justice and democratic processes.