The EU AI Act classifies every AI system by risk – and ties concrete obligations to it. Answer a few questions and get an instant first assessment plus the key obligations.
100% in your browser · no sign-up, no data sent anywhere
4 short steps, about 2 minutes. You pick what applies to your system – we map it to the four risk classes of the EU AI Act.
AI Act duties depend on whether you supply the system or use it. Without this we would show you duties that are not yours.
4 steps · ~2 min · anonymous
The check is a deterministic decision tree. It uses no generative AI, sends nothing to a server, and makes no judgement beyond mapping to the classes the regulation defines. Every option below names the provision it rests on.
Regulation (EU) 2024/1689 (AI Act), Official Journal of 12 July 2024. EUR-Lex ↗
As amended by Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), Official Journal of 24 July 2026, in force since 27 July 2026. EUR-Lex ↗
| Selection in the check | Provision |
|---|---|
| Social scoring — evaluating people or groups over a period of time by their social behaviour, leading to detrimental treatment | Art. 5(1)(c) |
| Subliminal, manipulative or deceptive techniques that materially distort behaviour, by objective or effect, causing significant harm | Art. 5(1)(a) |
| Exploiting vulnerabilities due to age, disability, or a specific social or economic situation | Art. 5(1)(b) |
| Real-time remote biometric identification in publicly accessible spaces for law enforcement | Art. 5(1)(h) |
| Emotion recognition in the workplace or in education — except for medical or safety reasons | Art. 5(1)(f) |
| Untargeted scraping of facial images from the internet or CCTV footage to build or expand facial recognition databases | Art. 5(1)(e) |
| Biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation | Art. 5(1)(g) |
| Predicting a criminal offence solely on profiling or assessment of personality traits | Art. 5(1)(d) |
| Generating or manipulating realistic images, video or audio showing an identifiable person's intimate parts, or an identifiable person engaged in sexually explicit activities, without their explicit consent | Art. 5(1)(ba) |
| Generating or manipulating material or performances depicting child sexual abuse | Art. 5(1)(bb) |
| Biometrics — remote identification, categorisation by sensitive attributes, or emotion recognition (where permitted) | Annex III(1) |
| Critical infrastructure — safety component in digital infrastructure, road traffic, or the supply of water, gas, heating and electricity | Annex III(2) |
| Education and vocational training — access and admission, evaluating learning outcomes, assessing the appropriate level of education, or monitoring for prohibited behaviour during tests | Annex III(3) |
| Employment and workforce management — targeted job advertising, applicant filtering, recruitment, promotion, termination, task allocation based on behaviour or traits, and monitoring and evaluating performance | Annex III(4) |
| Essential services — creditworthiness, risk assessment and pricing in life and health insurance, public assistance benefits, and emergency call triage and dispatch | Annex III(5) |
| Law enforcement (where permitted) — victim risk, polygraphs, reliability of evidence, risk of offending or reoffending, and profiling during investigations | Annex III(6) |
| Migration, asylum and border control (where permitted) — polygraphs, risk assessments, examining applications, and detecting and identifying people | Annex III(7) |
| Administration of justice and democratic processes — assisting judicial authorities with facts and law, alternative dispute resolution, and influencing elections or referendums | Annex III(8) |
| The AI system is a safety component of a product covered by EU harmonisation law — or is itself such a product — and that product requires third-party conformity assessment | Art. 6(1) with Annex I |
| The system interacts directly with people (chatbot, voicebot, AI assistant) | Art. 50(1) |
| The system generates synthetic image, audio, video or text content | Art. 50(2) |
| You publish deep fakes with it, or text on matters of public interest | Art. 50(4) |
| The system recognises emotions or categorises people biometrically (where permitted) | Art. 50(3) |
| The system performs profiling of natural persons | Art. 6(3) subpara. 3 |
| It is intended to perform a narrow procedural task | Art. 6(3) subpara. 2(a) |
| It is intended to improve the result of a previously completed human activity | Art. 6(3) subpara. 2(b) |
| It is intended to detect decision-making patterns or deviations and does not replace a human assessment without proper review | Art. 6(3) subpara. 2(c) |
| It performs a preparatory task to an assessment | Art. 6(3) subpara. 2(d) |
Every substantive change to the classification logic or to the cited provisions is recorded here with its date.
Legal position: 28 July 2026. Based on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, which entered into force on 27 July 2026. Reflected from it: the new Art. 5 prohibitions, the deferred high-risk dates and the Art. 50(2) transitional period; its other changes only where the change history says so explicitly.
AI practices with unacceptable risk – e.g. social scoring or manipulative systems. Banned in the EU.
AI in sensitive areas such as hiring, lending or medicine. Permitted, but strictly regulated.
Chatbots and AI-generated content. Permitted – with a transparency duty toward users.
The vast majority of AI applications. No specific obligations under the AI Act.
Two exemptions in Article 2 place research outside the scope. They are narrower than they sound, and they concern scope rather than risk class. That is why the check above does not ask about them.
The Regulation does not apply to AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development. The word “sole” carries the whole weight: as soon as the same system is also used outside research, the exemption no longer applies.
Research, testing and development activity regarding AI systems or AI models is exempt as long as it takes place before they are placed on the market or put into service. Testing in real world conditions is expressly not covered by that exclusion. Other Union law, data protection in particular, continues to apply regardless.
If your project falls entirely under Art. 2(6) or 2(8), the result of the check above does not apply to you. If only part of it does, classify the remainder separately.
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law for artificial intelligence. It classifies AI systems by risk and ties graduated obligations to that – from none all the way to a ban.
The AI Act entered into force in August 2024 and applies in stages: the Art. 5 bans and the AI-literacy duty since February 2025, obligations for GPAI models from August 2025, and the transparency obligations from August 2026. The big high-risk obligations were postponed by the “Digital Omnibus” — Annex III to December 2027, Annex I to August 2028. The same Omnibus added two prohibitions to Art. 5 — non-consensual intimate material and depictions of child sexual abuse — which apply from December 2026. And providers of systems generating synthetic content that were placed on the market before August 2026 have until December 2026 to meet Art. 50(2).
Yes. The AI Act applies to anyone developing or deploying AI systems in the EU – regardless of company size. What matters is the risk class of the specific system, not the size of the company.
No. It gives a first orientation based on the AI Act's typical criteria. The binding classification depends on the individual case and should be legally confirmed.
We support you from risk classification through the AI policy to compliant implementation in your organisation.
These tools complement the current result.