AI Act Risk Checker
Up to 12 questions. Everything runs in your browser — no data leaves your device. You'll get the EU AI Act category your system falls into, the article it's based on, the deadline, and what it concretely means whether you're a provider, a deployer, or both.
Legal text verified against the consolidated text on EUR-Lex as of 27 July 2026. The narrow-exception wording (Article 6(3)) also reflects the European Commission's draft classification guidelines, published 19 May 2026 and non-binding until finalized (expected late 2026). Page last reviewed: August 2026.
What are the EU AI Act risk categories?
The EU AI Act (Regulation (EU) 2024/1689) sorts AI systems into four risk tiers — prohibited, high-risk, limited risk (transparency obligations) and minimal risk — and adds a separate chapter for general-purpose AI models. Which tier applies decides what you must do and by when. Your obligations also depend on your role: a provider develops or places the system on the market, a deployer uses it under its own authority, and many organisations are both, for different systems.
The table below is the reference the questionnaire above applies. Dates reflect Regulation (EU) 2026/1744 (the Digital Omnibus), in force since 27 July 2026.
| Category | Legal basis | Applies from | What it means |
|---|---|---|---|
| Prohibited practice | Article 5 | In force since 2 February 2025 | Banned outright in the EU, whatever your role and however the system is used. Not a paperwork outcome: it is redesign-or-don't-ship for the EU market. |
| High-risk — Annex I (product-embedded) | Article 6(1) | 2 August 2028 (postponed from 2 August 2027) | The system is a safety component of a product already regulated by EU product-safety law. Provider: risk management, data governance, technical documentation, conformity assessment (often via a notified body), CE marking, registration, post-market monitoring. Deployer: use per instructions, human oversight, logs. |
| High-risk — Annex III (standalone) | Article 6(2) | 2 December 2027 (postponed from 2 August 2026) | The system falls in one of the eight Annex III use-case areas and its output materially shapes a decision about a person. Provider: quality management system, logging, conformity assessment, registration in the EU database (Article 49), post-market monitoring. Deployer: human oversight, logs kept at least six months, and in specific cases a fundamental rights impact assessment (Article 27). |
| Narrow-task exception | Article 6(3) and 6(4) | Same deadline as the tier it exempts from | An Annex III system may escape high-risk status if it only performs a narrow procedural task. In practice it rarely applies: profiling always defeats it, and ranking or scoring does not count as procedural. Article 6(4) still requires a documented assessment before market placement, plus registration under Article 49(2). |
| General-purpose AI — baseline | Article 53 | In force since 2 August 2025 | Applies to whoever trains the model, not to those calling it through an API. Keep technical documentation current, inform downstream providers, publish a copyright policy and a public summary of training content. |
| General-purpose AI — systemic risk | Articles 51 and 55 | In force since 2 August 2025 | Presumed at a training compute of 1025 FLOPs or more (a rebuttable presumption). Notify the European Commission within two weeks of foreseeing or reaching the threshold, then model evaluation, adversarial testing, incident tracking and reporting, and cybersecurity obligations. |
| Transparency obligations (limited risk) | Article 50 | In force since 2 August 2026 | Applies on top of any tier above, whenever people interact with the system or see its output: disclose AI interaction, label deepfakes, and mark generated content in a machine-readable way. A targeted grace period runs to 2 December 2026 for the machine-readable marking requirement only. |
| Minimal risk | No tier-specific obligation | — | Most AI systems land here. The general AI-literacy duty (Article 4, in force since 2 February 2025, with no headcount threshold) still applies, and the AI Act being silent does not switch off the GDPR or sectoral law. |
Why we built this
Most AI Act checklists stop at "high-risk or not." The two places people actually get it wrong are upstream of that: whether they're a provider or a deployer (most founders calling an API are both, for different systems), and whether the narrow Article 6(3) exception really applies to their case — in practice it rarely does, because most tools that inform a decision about a person end up shaping that decision, not just organizing the paperwork around it. This tool asks about both, on purpose, before it gives you an answer.
Reading in French? This same questionnaire, same logic, same dates, is at Vérificateur de risque AI Act. If you'd rather have the long-form French write-up, with worked examples and a ready-to-use system register, see the Grille de classification des risques AI Act.
Questions people ask
Is this legally binding or certified in any way?
No. It's a free orientation tool built on public information, meant to help you ask the right questions early. It is not a substitute for the documented assessment the Regulation requires for borderline cases, and not a legal opinion.
Does anything I type get sent to a server?
No. The classification runs entirely in your browser with plain JavaScript — no AI model, no API call, no backend. The only network request on this page is the standard Google Analytics tag used across this site, which does not see your answers.
Why do the high-risk deadlines look so far away?
Because they were pushed back — recently. Regulation (EU) 2026/1744 (the "Digital Omnibus"), published in the Official Journal on 24 July 2026 and in force since 27 July 2026, moved the Annex III standalone high-risk deadline from 2 August 2026 to 2 December 2027, and the Annex I product-safety deadline from 2 August 2027 to 2 August 2028. Prohibited practices (Article 5), AI literacy (Article 4), general-purpose AI obligations, and transparency (Article 50) were not delayed — Article 50 is already in force as of 2 August 2026.
I just call the OpenAI / Anthropic / Google API — does the GPAI chapter apply to me?
Generally no, not directly. Training a foundation model triggers Chapter V (Articles 51–56). Calling one through an API makes you a deployer of that model — the heavy obligations sit with the model's provider — while you remain the provider of whatever you build on top of it, which is judged on its own merits by the rest of this questionnaire. One catch: if what you build turns out high-risk, you're the one who inherits provider obligations for it (Article 25), and the model vendor's terms of service excluding high-risk use don't get you out of that by themselves.
Are you using the European Commission's draft guidelines, or just the Regulation itself?
Both, and we say which is which. The pass/fail logic (prohibited, high-risk, transparency, minimal) comes from the Regulation itself. The detailed examples in the narrow-exception question (Article 6(3), such as what counts as a "narrow procedural task") come from the Commission's draft classification guidelines, published 19 May 2026 and open for consultation until 23 July 2026. Those guidelines are not binding and not final — the Commission expects to adopt a final version by the end of 2026, and it can differ from the draft. We built this tool to match the draft as it stands today, and we'll update it if the final text changes.
Jérôme Denis — Senior AI & Data Governance Consultant, Toulouse, France. Twenty years in digital transformation, AI Act compliance work with SMEs and mid-size companies. This is the questionnaire I use as a first pass in real engagements, published free because a shared starting point beats a locked-up one.
Landed on a High-Risk or Prohibited result and want a second, human opinion?
The first conversation is free, no strings attached.