EU AI Act Risk Checker
Prohibited, high-risk, transparency or minimal risk: the articles, duties and dates.
Free preview.
- Free preview: the category, the reasons and the dates for your own answers, with the first of your duties (up to 10).
- Locked until you unlock it: download and copy.
- Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Result
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the EU AI Act Risk Checker
The EU AI Act — Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI — sorts AI into four levels: prohibited practices, high-risk systems, systems with transparency duties and minimal risk, with separate rules for the providers of general-purpose AI models. Which level you are in, and what you must do, depends on what the system does and on your role: provider, deployer, importer, distributor, product manufacturer or authorised representative.
Answer the questions — scope, role, the prohibited practices of Article 5, the products of Annex I, the uses of Annex III with the Article 6(3) exceptions, the transparency cases of Article 50 and the model questions — and the checker shows the category with the reasons and articles behind it, your duties one by one with the day each applies, the timeline and the maximum fines. The free preview shows the category, the reasons and the dates with the first duties; the full list, the PDF summary and Copy summary need a Premium pass. Your answers stay in your browser.
How to use it
- Say what you are checking — an AI system, a general-purpose AI model or both — and whether it is placed on the EU market or its output is used in the EU. Tick any exclusion that applies.
- Tick your role. A business that puts its own name on someone else’s high-risk system, modifies it substantially or changes its purpose becomes its provider (Article 25).
- Work through the prohibited practices, the products of Annex I, the uses of Annex III and the transparency cases. For an Annex III use, say whether the system profiles people and whether one of the four Article 6(3) exceptions describes it.
- Read the result: the category, why, your duties with their articles and dates, and the fines.
- With a Premium pass, use Download PDF or Copy summary to keep the result; without one, the page shows the free preview.
Examples
Provider · Annex III point 4(a) recruitment · profiles candidates · chat interface
High-risk (Annex III use): risk management, data governance, technical documentation, logging, instructions, human oversight, accuracy and cybersecurity, a quality management system, conformity assessment, the EU declaration and CE marking, registration, post-market monitoring and incident reporting — from 2 December 2027. The chatbot notice of Article 50(1) applies now.
Provider and deployer · interacts with people · no Annex III use
Transparency duties: tell people they are talking to an AI system unless it is obvious (Article 50(1)), at the latest at the first interaction (Article 50(5)), plus AI literacy for staff (Article 4).
Product manufacturer · machinery (Annex I, Section B, point 21) · safety component · notified body needed
High-risk under a product law: only Articles 6(1), 60a and 102–112 of the AI Act apply, and the AI requirements reach the robot through the Machinery Regulation as it is amended to include them (Article 2(2)).
General-purpose AI model · open-source licence · training compute above 10^25
General-purpose AI model with systemic risk: notify the Commission within two weeks, documentation for the AI Office and downstream providers, a copyright policy, a public training-content summary, model evaluation with adversarial testing, systemic-risk mitigation, incident reporting and cybersecurity. The open-source exemption does not apply with systemic risk.
Common uses
- Product and compliance teams deciding whether an AI feature is high-risk before they build the documentation.
- Buyers of AI tools — HR, banks, insurers, schools and public bodies — checking their duties as deployers.
- Importers and distributors checking what to verify before they sell an AI system in the EU.
- Developers outside the EU whose product or output reaches people in the EU.
The prohibited practices (Article 5)
AI systems may not be placed on the market, put into service or used for:
- (a) subliminal, purposefully manipulative or deceptive techniques that distort behaviour and cause significant harm;
- (b) exploiting vulnerabilities due to age, disability or a social or economic situation, causing significant harm;
- (c) social scoring that leads to detrimental or disproportionate treatment;
- (d) predicting crimes from profiling or personality traits alone;
- (e) untargeted scraping of facial images from the internet or CCTV to build recognition databases;
- (f) emotion recognition in workplaces and education, except for medical or safety reasons;
- (g) biometric categorisation to infer race, political opinions, trade-union membership, religious or philosophical beliefs, sex life or sexual orientation;
- (h) real-time remote biometric identification in publicly accessible spaces for law enforcement, save narrow, authorised exceptions.
The Omnibus adds (ba), realistic sexual or intimate images, video or audio of an identifiable person made without their explicit consent, and (bb), child sexual abuse material (applicable from 2 December 2026). A system is caught when that is its intended purpose, or when it can foreseeably produce such material and lacks reasonable safeguards against it (Article 5).
When an AI system is high-risk (Article 6)
- Annex I products. The system is a safety component of a product — or is the product — covered by one of the EU product laws of Annex I, and that product needs a third-party conformity assessment. Section A (toys, lifts, radio equipment, pressure equipment, medical and in vitro diagnostic devices, personal protective equipment and others) brings the AI Act’s requirements in full; for Section B (vehicles, aviation security and drones, marine equipment, rail and, after the Omnibus, machinery) the requirements come through that product law (Article 2(2)). AI that only helps users, saves time, automates or checks quality is not a safety component unless its failure would endanger health and safety (Article 6(1a), (1b)).
- Annex III uses. Remote biometric identification, biometric categorisation and emotion recognition; safety components of critical infrastructure; education (admission, grading, proctoring); employment (recruitment, promotion, task allocation, monitoring); access to essential services (public benefits, creditworthiness, life and health insurance pricing, emergency calls and triage); law enforcement; migration, asylum and border control; and justice and elections.
- The Article 6(3) exception. An Annex III system is not high-risk when it only performs a narrow procedural task, improves a completed human activity, detects decision patterns without replacing human review, or prepares an assessment — and it never applies to a system that profiles people. A provider relying on it documents the assessment (Article 6(4)) and registers the system in the EU database (Article 49(2)).
Who does what
- Providers of high-risk systems run a risk management system, govern their data, write the technical documentation, build in logging, human oversight, accuracy and cybersecurity, operate a quality management system, keep the documentation for 10 years, pass the conformity assessment, sign the EU declaration, affix the CE marking, register, monitor the system after sale and report serious incidents within 15 days at the latest (Articles 9–21, 43, 47–49, 72, 73).
- Deployers use the system as instructed, assign trained people to oversee it, check their input data, monitor it, keep the logs for at least six months, tell workers before using it at work, tell people it decides about, explain decisions on request, and — public bodies, providers of public services, credit scoring and life or health insurance — assess the impact on fundamental rights first (Articles 26, 27, 86).
- Importers and distributors check the CE marking, the declaration and the documentation, add their details and hold back systems that do not conform (Articles 23, 24). Providers outside the EU appoint an authorised representative (Article 22).
- Anyone who rebrands a high-risk system, modifies it substantially or turns a system to a high-risk purpose becomes its provider (Article 25).
Transparency duties (Article 50)
- Providers of chatbots, voice assistants and agents design them so people know they are dealing with AI, unless it is obvious (Article 50(1)).
- Providers of systems that generate images, audio, video or text mark the output in a machine-readable, detectable way (Article 50(2)); generators already on the market before 2 August 2026 have until 2 December 2026 (Article 111).
- Deployers of emotion recognition and biometric categorisation inform the people exposed (Article 50(3)); deployers who make deep fakes, or publish AI-written text on matters of public interest without human review and editorial responsibility, disclose it (Article 50(4)).
- The information comes clearly, at the latest at the first interaction or exposure (Article 50(5)).
General-purpose AI models
Providers keep technical documentation for the AI Office, inform the providers who build on the model, adopt a copyright policy that respects text-and-data-mining reservations, and publish a summary of the training content (Article 53). Providers outside the EU appoint an authorised representative (Article 54). A model whose training used more than 10^25 floating-point operations is presumed to have systemic risk (Article 51(2)): its provider notifies the Commission within two weeks (Article 52) and also evaluates the model with adversarial testing, mitigates systemic risks, reports serious incidents and protects its cybersecurity (Article 55). Models released under an open-source licence with public weights are exempt from the two documentation duties — not with systemic risk. Models placed on the market before 2 August 2025 must comply by 2 August 2027.
When the rules apply
- Already applying: the prohibitions of Article 5(1)(a)–(h) and the AI-literacy duty of Article 4; the duties of general-purpose AI model providers; the transparency duties of Article 50 and the general rules; the fines.
- 2 December 2026: the two new prohibitions of Article 5(1)(ba) and (bb), and machine-readable marking for generators already on the market.
- 2 December 2027: the high-risk rules for Annex III uses.
- 2 August 2028: the high-risk rules for Annex I products.
- 2 August 2030: high-risk systems already used by public authorities are brought into line (Article 111(2)).
The checker compares each date with today’s and shows “applies now” or the day it starts (Article 113).
Fines (Articles 99 and 101)
- Prohibited practices: up to €35 million or 7 % of worldwide annual turnover, whichever is higher.
- The duties of providers, representatives, importers, distributors and deployers, and Article 50: up to €15 million or 3 %.
- Incorrect or misleading information to notified bodies or authorities: up to €7.5 million or 1 %.
- SMEs and start-ups: the lower of the two amounts; small mid-caps: the lower amount for the last two tiers.
- Providers of general-purpose AI models: up to 3 % or €15 million, whichever is higher, imposed by the Commission.
Limitations
- A guided self-assessment, not legal advice. The category depends on the system’s intended purpose and real use, and on guidelines, harmonised standards and codes of practice that refine the Act; have a lawyer confirm it.
- It covers the AI Act only. The GDPR, product safety laws, sector rules and national laws apply alongside it.
- One system or model at a time, on the answers given. Change an answer and the result changes.
- It does not run the conformity assessment, write the technical documentation or register anything; it lists what each duty asks for and where it is in the Act.
Privacy
Your answers are checked in your browser and never uploaded. If you tick Keep my answers in this browser, they are saved in this browser’s local storage until you untick it.
Frequently asked questions
What do I get without a pass?
Without a pass, EU AI Act Risk Checker shows the category, the reasons and the dates for your own answers, with the first of your duties (up to 10). Until you unlock it, the result can’t be downloaded or copied. A Premium or Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
Is my chatbot high-risk under the AI Act?
Usually not. A chatbot carries the transparency duty of Article 50(1): people must know they are talking to AI unless it is obvious. It becomes high-risk when it is used for an Annex III purpose — screening job applicants, scoring credit, deciding on public benefits, grading students — or as a safety component of an Annex I product.
When do the high-risk rules apply?
For the uses listed in Annex III, from 2 December 2027; for AI in the products of Annex I, from 2 August 2028. The Digital Omnibus on AI moved both dates. The prohibitions, AI literacy, the duties of general-purpose AI model providers and the transparency duties of Article 50 already apply.
We only use an AI tool someone else made. Do we have duties?
Yes, as a deployer: AI literacy for your staff, and for a high-risk system the duties of Article 26 — use it as instructed, human oversight, relevant input data, monitoring, logs for at least six months, telling workers and the people it decides about — plus a fundamental rights impact assessment for public bodies, providers of public services, credit scoring and life or health insurance. Put your own name on it or change its purpose, and you become its provider.
Does the AI Act apply to companies outside the EU?
Yes, when they place an AI system or model on the EU market, or when the output of their system is used in the EU (Article 2(1)). Providers outside the EU appoint an authorised representative in the EU for high-risk systems and for general-purpose models.
What did the Digital Omnibus on AI change?
Among other things: two new prohibitions (non-consensual sexual or intimate deep fakes and child sexual abuse material), later dates for the high-risk rules, machinery moved to Annex I, Section B, a reworded AI-literacy duty, extra time for marking the output of generators already on the market, simplified documentation and lower fines extended to small mid-caps, and an EU-level regulatory sandbox.
Do I need a pass?
To download the PDF summary or copy the whole summary, yes: a Premium pass unlocks every Premium tool. Without a pass you see a free preview of your own result: the category, the reasons and the dates, with the first of your duties.
Are my answers sent anywhere?
No. The check runs in your browser; nothing you answer is uploaded or stored by MySmartCoPilot.