EU AI Act Risk Classifier
Answer a short questionnaire and get a preliminary risk category for your AI system under Regulation (EU) 2024/1689 — plus your role, obligations and the dates that apply to you.
FreeNo signup to start3–5 minutesRuns in your browser
Loading the classifier…
How it works
- Answer up to 8 short questions about your system, your role and how it is used.
- The tool applies the decision rules of the AI Act entirely in your browser — no data leaves the page.
- You get a preliminary category, the obligations for your role, key dates and penalty exposure.
- Optionally email yourself a PDF classification memo, or talk to a compliance expert.
Frequently asked questions
What are the four risk categories?
The AI Act sorts systems into unacceptable risk (prohibited practices under Art. 5), high risk (Annex I products and the eight Annex III areas), limited risk (transparency duties under Art. 50), and minimal risk (no mandatory obligations). General-purpose AI models are governed separately.
When do high-risk obligations apply?
Following the Digital Omnibus timeline relief, high-risk obligations for Annex III systems apply from 2 December 2027, and for high-risk AI embedded in regulated Annex I products from 2 August 2028. Prohibited-practice bans and AI-literacy duties have applied since 2 February 2025. These dates come from the tool's rules file and are confirmed by counsel before this page goes live.
Does the AI Act apply to companies outside the EU?
It can. The Act applies to providers and deployers established outside the EU if the output produced by the system is used in the EU (Art. 2). Providers established outside the EU generally must appoint an authorised representative in the Union (Art. 22).
Is a chatbot high-risk?
Usually not by itself. A customer-support chatbot is typically limited risk: you must tell users they are interacting with an AI system (Art. 50). It becomes high-risk only if it is used in a high-risk area such as essential services or employment decisions.
What is the Art. 6(3) exception?
A system used in an Annex III area is not high-risk if it performs only a narrow procedural task, improves the result of a completed human activity, detects decision patterns without replacing human judgement, or performs a preparatory task — and does not profile natural persons. You must document this assessment and register the system (Art. 6(4), Art. 49(2)).
What are GPAI obligations?
Providers of general-purpose AI models must keep technical documentation, inform downstream providers, adopt a copyright policy and publish a summary of training data (Art. 53). Models with systemic risk have additional duties: evaluation, adversarial testing, systemic-risk mitigation, cybersecurity and incident reporting (Art. 55).
Is this legal advice?
No. This tool gives a preliminary, automated classification based on your answers to help you scope the work. It is not legal advice and does not create a lawyer–client relationship. For a binding classification, book a readiness assessment with our team.