EU AI Act risk check

Which risk class does your AI fall under?

The EU AI Act classifies every AI system by risk – and ties concrete obligations to it. Answer a few questions and get an instant first assessment plus the key obligations.

100% in your browser · no sign-up, no data sent anywhere

Start the AI risk check

4 short steps, about 2 minutes. You pick what applies to your system – we map it to the four risk classes of the EU AI Act.

Your role

AI Act duties depend on whether you supply the system or use it. Without this we would show you duties that are not yours.

4 steps · ~2 min · anonymous

Methodology and sources

The check is a deterministic decision tree. It uses no generative AI, sends nothing to a server, and makes no judgement beyond mapping to the classes the regulation defines. Every option below names the provision it rests on.

The decision rule

  1. If a prohibited practice under Art. 5 applies, the result is "prohibited" — regardless of everything else.
  2. Otherwise: if an Annex III area applies, the check tests the Art. 6(3) derogation. If the system performs profiling it stays high-risk. Otherwise one of the four conditions is enough for it to be likely not high-risk.
  3. The product route under Art. 6(1) with Annex I is assessed separately. The Art. 6(3) derogation does not apply to it.
  4. Art. 50 transparency duties are always reported additionally when a trigger applies — including alongside a high-risk result.
  5. If none of this applies the result is "minimal risk". The Art. 4 AI literacy duty applies anyway.

Source

Regulation (EU) 2024/1689 (AI Act), Official Journal of 12 July 2024. EUR-Lex ↗

As amended by Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), Official Journal of 24 July 2026, in force since 27 July 2026. EUR-Lex ↗

Selection in the checkProvision
Social scoring — evaluating people or groups over a period of time by their social behaviour, leading to detrimental treatmentArt. 5(1)(c)
Subliminal, manipulative or deceptive techniques that materially distort behaviour, by objective or effect, causing significant harmArt. 5(1)(a)
Exploiting vulnerabilities due to age, disability, or a specific social or economic situationArt. 5(1)(b)
Real-time remote biometric identification in publicly accessible spaces for law enforcementArt. 5(1)(h)
Emotion recognition in the workplace or in education — except for medical or safety reasonsArt. 5(1)(f)
Untargeted scraping of facial images from the internet or CCTV footage to build or expand facial recognition databasesArt. 5(1)(e)
Biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientationArt. 5(1)(g)
Predicting a criminal offence solely on profiling or assessment of personality traitsArt. 5(1)(d)
Generating or manipulating realistic images, video or audio showing an identifiable person's intimate parts, or an identifiable person engaged in sexually explicit activities, without their explicit consentArt. 5(1)(ba)
Generating or manipulating material or performances depicting child sexual abuseArt. 5(1)(bb)
Biometrics — remote identification, categorisation by sensitive attributes, or emotion recognition (where permitted)Annex III(1)
Critical infrastructure — safety component in digital infrastructure, road traffic, or the supply of water, gas, heating and electricityAnnex III(2)
Education and vocational training — access and admission, evaluating learning outcomes, assessing the appropriate level of education, or monitoring for prohibited behaviour during testsAnnex III(3)
Employment and workforce management — targeted job advertising, applicant filtering, recruitment, promotion, termination, task allocation based on behaviour or traits, and monitoring and evaluating performanceAnnex III(4)
Essential services — creditworthiness, risk assessment and pricing in life and health insurance, public assistance benefits, and emergency call triage and dispatchAnnex III(5)
Law enforcement (where permitted) — victim risk, polygraphs, reliability of evidence, risk of offending or reoffending, and profiling during investigationsAnnex III(6)
Migration, asylum and border control (where permitted) — polygraphs, risk assessments, examining applications, and detecting and identifying peopleAnnex III(7)
Administration of justice and democratic processes — assisting judicial authorities with facts and law, alternative dispute resolution, and influencing elections or referendumsAnnex III(8)
The AI system is a safety component of a product covered by EU harmonisation law — or is itself such a product — and that product requires third-party conformity assessmentArt. 6(1) with Annex I
The system interacts directly with people (chatbot, voicebot, AI assistant)Art. 50(1)
The system generates synthetic image, audio, video or text contentArt. 50(2)
You publish deep fakes with it, or text on matters of public interestArt. 50(4)
The system recognises emotions or categorises people biometrically (where permitted)Art. 50(3)
The system performs profiling of natural personsArt. 6(3) subpara. 3
It is intended to perform a narrow procedural taskArt. 6(3) subpara. 2(a)
It is intended to improve the result of a previously completed human activityArt. 6(3) subpara. 2(b)
It is intended to detect decision-making patterns or deviations and does not replace a human assessment without proper reviewArt. 6(3) subpara. 2(c)
It performs a preparatory task to an assessmentArt. 6(3) subpara. 2(d)

What the check does not do

  • It does not replace legal advice or a conformity assessment.
  • It does not test whether your system is an AI system within Art. 3(1) — it assumes that.
  • It does not cover duties for general-purpose AI models (Chapter V).
  • It does not test whether the research exemptions in Art. 2(6) and 2(8) apply. The section “Universities and research” explains them.
  • It does not decide individual cases: only the wording of the regulation governs, and an authority can review a self-classification under Art. 80.

Change history

Every substantive change to the classification logic or to the cited provisions is recorded here with its date.

  • Added provisions for every option and verified them against the official text. Built in the Art. 6(3) derogation with the profiling counter-exception and the documentation and registration duties. Separated the Annex I product route from the Annex III route. Split the Art. 50 duties between provider and deployer. Added the date of application to every result. Added the Art. 50(2) transitional period from Regulation (EU) 2026/1744 and extended the legal-position note to that amending regulation. The prohibitions it inserts as Art. 5(1)(ba) and (bb) are now included, together with the scoping in Art. 5(1a) and (1b) and with their own date of application: Art. 113(3)(a) as amended sets it at 2 December 2026. Art. 5 therefore carries two dates here, and the result names the one that matches what you actually selected.
  • Added the Digital Omnibus deadlines to the FAQ.

Legal position: 28 July 2026. Based on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, which entered into force on 27 July 2026. Reflected from it: the new Art. 5 prohibitions, the deferred high-risk dates and the Art. 50(2) transitional period; its other changes only where the change history says so explicitly.

The four risk classes of the EU AI Act

Prohibited

AI practices with unacceptable risk – e.g. social scoring or manipulative systems. Banned in the EU.

High risk

AI in sensitive areas such as hiring, lending or medicine. Permitted, but strictly regulated.

Limited risk

Chatbots and AI-generated content. Permitted – with a transparency duty toward users.

Minimal risk

The vast majority of AI applications. No specific obligations under the AI Act.

Universities and research: when the Regulation does not apply at all

Two exemptions in Article 2 place research outside the scope. They are narrower than they sound, and they concern scope rather than risk class. That is why the check above does not ask about them.

Art. 2(6): scientific research as the sole purpose

The Regulation does not apply to AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development. The word “sole” carries the whole weight: as soon as the same system is also used outside research, the exemption no longer applies.

Art. 2(8): research, testing and development before placing on the market

Research, testing and development activity regarding AI systems or AI models is exempt as long as it takes place before they are placed on the market or put into service. Testing in real world conditions is expressly not covered by that exclusion. Other Union law, data protection in particular, continues to apply regardless.

What the exemptions do not cover

  • Teaching and administration are not research. A chatbot for students, AI support in admissions or examinations, and university administrative systems do not fall under Art. 2(6).
  • Once a research result is placed on the market or put into service, whether as a spin-off, as a service to third parties, or as a university-wide tool, the Regulation applies in full from that point.
  • The transparency duties in Art. 50 attach to deployment, not to purpose. Anyone generating synthetic content, or running a system people interact with directly, has to disclose it.
  • For anything not covered by the exemptions, the AI literacy duty in Art. 4 applies regardless of risk class.

If your project falls entirely under Art. 2(6) or 2(8), the result of the check above does not apply to you. If only part of it does, classify the remainder separately.

Frequently asked questions about the EU AI Act

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law for artificial intelligence. It classifies AI systems by risk and ties graduated obligations to that – from none all the way to a ban.

When does the EU AI Act apply?

The AI Act entered into force in August 2024 and applies in stages: the Art. 5 bans and the AI-literacy duty since February 2025, obligations for GPAI models from August 2025, and the transparency obligations from August 2026. The big high-risk obligations were postponed by the “Digital Omnibus” — Annex III to December 2027, Annex I to August 2028. The same Omnibus added two prohibitions to Art. 5 — non-consensual intimate material and depictions of child sexual abuse — which apply from December 2026. And providers of systems generating synthetic content that were placed on the market before August 2026 have until December 2026 to meet Art. 50(2).

Does the AI Act apply to my small business too?

Yes. The AI Act applies to anyone developing or deploying AI systems in the EU – regardless of company size. What matters is the risk class of the specific system, not the size of the company.

Is this check legally binding?

No. It gives a first orientation based on the AI Act's typical criteria. The binding classification depends on the individual case and should be legally confirmed.

Unsure about the classification – or the implementation?

We support you from risk classification through the AI policy to compliant implementation in your organisation.