Free tool
Classify your system under the EU AI Act in 3 minutes.
A few questions place your system in one of the four risk levels of Regulation (EU) 2024/1689 (prohibited, high, transparency or minimal), with the applicable articles and the date from which obligations apply.
Instant result: risk level, applicable articles and deadline.
Before you start
What is the EU AI Act?
Regulation (EU) 2024/1689, the "EU AI Act", is the first European law to regulate artificial intelligence systems. It sets the obligations that apply to your company depending on what you use AI for, what risks it generates and who it affects.
Not all companies have the same obligations. An internal tool that summarises meeting notes is not treated the same as a system that screens CVs in HR or a medical device with AI. The Regulation sorts systems into four risk levels (prohibited, high risk, transparency and minimal) and, for each one, defines what you have to do and by when.
The Regulation isn't only about banning things. It also wants European AI to be trustworthy without slowing innovation, which is why it keeps the lightest rules for SMEs and startups: if your system is low-risk, your obligations are minimal.
Two more things that shape your obligations
The risk level is not the whole story. Two other questions cut across it and change what you have to do.
Your role
Building the system (provider) is not the same as using it in your company (deployer), reselling it (distributor) or bringing it in from outside the EU (importer). The same high-risk system creates different duties depending on which one you are.
If you build a general-purpose model
Training your own general-purpose model (what people call GPAI: the GPT, Claude, Gemini or Llama family) adds its own block of obligations, and a stricter one if the model reaches a size with systemic impact. Integrating a third-party model via API does not make you its provider.
What this calculator does
It applies the Regulation's decision tree to your answers and returns, in under three minutes: the risk level your system falls under, whether you also build a general-purpose model and the role you fall into, the exact articles that apply to you, the date from which those obligations are enforceable and the list of obligations you will need to map (risk management, technical documentation, human oversight, EU registration, transparency…).
What it does not
It does not replace a legal advisor or a formal audit. It is the first picture you need to decide whether your company has to open a compliance file, bring in a specialist, or move the project to a different phase. A starting point, not a verdict.
What if it doesn't apply to me?
A few cases fall outside the Regulation: systems used only for military, defence or national-security purposes; research and development before the system reaches the market; purely personal, non-professional use; and systems released under a free and open-source licence. Open source comes with a catch: it doesn't save you if the system is high-risk, prohibited (Art. 5) or carries transparency duties (Art. 50). And R&D stops being exempt the moment you test it in real conditions or put it into production. E.g.: while you're still building behind closed doors it probably doesn't apply yet; the day you ship, it does.
How the Regulation classifies
What this calculator classifies
The four system risk levels
Prohibited (Art. 5)
The system falls under one of the Art. 5(1) prohibited practices. It cannot be put into service or placed on the EU market: points (a) to (h) apply from 2 February 2025, and points (ba) and (bb), added by Regulation (EU) 2026/1744, from 2 December 2026.
High risk (Art. 6)
The system falls under the high-risk regime: risk management, data governance, technical documentation and event logging (Art. 12), human oversight, accuracy, robustness and cybersecurity (Art. 15), conformity assessment and registration in the EU database.
Transparency (Art. 50)
The system is not high risk but triggers transparency obligations: inform users they are interacting with AI, mark synthetic content or disclose emotion recognition and biometric categorisation. "Limited risk" is the common name for this Art. 50 regime, not a category in the Regulation, and it applies on top of any other classification.
Minimal risk
Residual level: the system falls into none of the above. The Regulation sets no specific obligations for this category, except one light cross-cutting rule that applies to everyone: give your team basic training in AI use (AI literacy, Art. 4). You may also voluntarily sign up to codes of conduct (Art. 95); Art. 95 does not define this level, it is only the framework for those voluntary codes.
The general-purpose model (GPAI) plane
GPAI · general-purpose AI (Art. 53)
General-purpose AI model (GPAI for short) below the systemic-risk threshold. Requires technical documentation, information for downstream providers, copyright policy and a public summary of training data.
GPAI systemic · general-purpose AI (Art. 51 and 55)
General-purpose AI model (GPAI) with high-impact capabilities. In addition to general GPAI obligations: adversarial evaluation, systemic risk management, serious incident notification and a reinforced level of cybersecurity.
This is about the model, not the specific use. Integrating a third-party model via API does not make you its provider: you stay a deployer, with the Art. 26 block and the duty to receive and retain the model's documentation.
The role plane
The same system creates different duties depending on whether you are a provider, deployer, distributor or importer. Your role cuts across the risk level, it does not replace it.
This tool is informational. A final classification requires a specific analysis of the system and its context. It is not legal advice.
FAQ
Frequently asked questions
What is the EU AI Act and who does it apply to?
The EU AI Act, Regulation (EU) 2024/1689, is the first European law to regulate artificial intelligence systems. It applies to anyone placing an AI system on the Union market, or whose system outputs are used in the Union, regardless of where the company is established: providers that develop and market the system, importers that bring it into the EU from a third country, distributors that resell it, and "deployers" that use it in the course of a professional activity. If your company falls into any of those four roles, it applies to you.
When does the EU AI Act enter into force and which obligations apply already in 2026?
The Regulation entered into force on 1 August 2024 with a phased timeline (Art. 113). The prohibited practices in Art. 5 are enforceable from 2 February 2025 and general-purpose AI model obligations (GPAI, Chapter V) from 2 August 2025. From 2 August 2026 the Art. 50 transparency obligations, the Chapter IX market-surveillance regime and the Art. 101 fines apply. Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since 27 July 2026) postponed the high-risk regime: Chapter III, Sections 1, 2 and 3 apply from 2 December 2027 for systems under Art. 6(2) and Annex III, and from 2 August 2028 for those under Art. 6(1) and Annex I. The postponement does not change the substance of the obligations.
My company only uses ChatGPT, Copilot or Gemini for internal tasks. Do I have to comply with the EU AI Act?
Most likely yes, in the role of "deployer" (Art. 26). If you use a third-party AI system in the course of a professional activity, the Art. 26 obligations apply depending on the specific use: human oversight, training of staff who operate it, logging of serious incidents and, if the system is used for one of the Annex III high-risk cases (HR, credit scoring, education, etc.), the rest of the high-risk deployer duties. The fundamental rights impact assessment (Art. 27) is stricter and only reaches public bodies, providers of a public service and those using the system for credit or for life and health insurance: a private CV screen does not need one. The model obligations (Art. 53/55) belong to the LLM provider, not to you as integrator.
I want to add a chatbot to my website. What do I need to know about the EU AI Act?
Three minimum points. One, transparency (Art. 50): you have to inform the user that they are interacting with AI, unless it is obvious. Two, if the chatbot makes decisions that affect the user's rights (access to a service, pricing, hiring), it can fall under Annex III high risk and trigger the entire Chapter III regime (risk management, data governance, technical documentation, human oversight). Three, if you integrate a third-party GPAI (OpenAI, Anthropic, Google), you have to receive and retain the provider's technical documentation (Art. 53(1)(b)) and apply the deployer obligations (Art. 26).
What is the difference between provider and deployer of an AI system?
The provider (Art. 3(3)) is the one who develops an AI system or has it developed and markets it under their name or trademark: they carry the bulk of the obligations on design, documentation, conformity assessment and EU registration. The deployer (Art. 3(4), the former "user") is the one who uses the system under their authority in a professional, non-domestic activity: they have lighter obligations on oversight, training and incident logging; and, only if they are a public body, provide a public service or use the system for credit or life and health insurance, the Annex III fundamental rights impact assessment (Art. 27). The same company can be a provider for one system and a deployer for another.
How do I know if my system is high risk? What happens if it is?
It is high risk if it falls into one of two cases. One, Annex I: a safety component of a product regulated by EU harmonisation legislation (machinery, toys, lifts, medical devices, etc.). Two, Annex III: any of the eight Annex III domains (biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, justice). If it does, you must comply with Chapter III: risk management system, data governance, technical documentation, human oversight, conformity assessment, registration in the EU database, CE marking and post-market monitoring.
What are the fines for non-compliance with the EU AI Act?
Art. 99 sets three tiers, and each takes whichever is higher of the fixed amount and the percentage of total worldwide annual turnover for the preceding financial year. Up to €35M or 7% for using the Art. 5 prohibited practices. Up to €15M or 3% for breaching the rest of the Regulation's obligations (provider, importer, distributor, deployer, transparency and high-risk systems). Up to €7.5M or 1% for giving authorities incorrect information. If you train or develop a general-purpose AI (GPAI) model, that sits under a separate regime: the fine comes from the European Commission, not your national authority, with its own cap of up to €15M or 3% of worldwide turnover (whichever is higher), applying from 2 August 2026 (Art. 101). For SMEs and start-ups the cap is the lower of the two figures, not the higher one (e.g.: if 3% of your turnover exceeds €15M, the cap is €15M); Regulation (EU) 2026/1744 extended that treatment to small mid-caps. And you can only be fined for an obligation that is already applicable: the high-risk regime does not apply until December 2027 (Annex III) or August 2028 (Annex I).
We're an SME or a start-up. Does the Regulation go easier on us?
A little, but it does not exempt you. Several of its support measures are aimed squarely at this calculator's audience. Every country must run at least one regulatory sandbox: a supervised environment where you can validate an innovative system before launch, with free, priority access for SMEs and start-ups (Art. 57 and 58). Conformity-assessment fees are reduced in proportion to your size (Art. 62). You can file the Annex IV technical documentation using the simplified form the Commission publishes, and assessment bodies must accept it (Art. 11). The quality-management system can scale to your organisation's size (Art. 17), and a microenterprise with no associated or linked companies can keep that paperwork lighter still (Art. 63). E.g.: a start-up shipping a high-risk system requests a priority sandbox slot and documents with reduced templates. What changes is the support and the cost of the process, not the substantive obligations.
Is the list of high-risk systems and prohibited practices final?
No. Every year the Commission reviews whether to add or remove high-risk Annex III uses and prohibited practices, and it can do so by delegated act (Art. 7 and 112). A "you're not in Annex III" today can be out of date tomorrow. E.g.: your system is outside the high-risk regime now, but a new delegated act could bring its domain in. It is worth re-classifying whenever your use case changes or the Regulation is updated.
Why don't the high-risk obligations apply until 2027 or 2028?
Because the technical standards you would demonstrate conformity against are not published yet. Regulation (EU) 2026/1744 pushed the timeline back until those harmonised standards and common specifications appear (Art. 40 and 41): December 2027 for Annex III and August 2028 for Annex I. E.g.: you can't "CE-mark" your HR system today because the harmonised standard to audit it against doesn't exist yet. The obligation still stands; only the date moved, not the substance.
What does registering my system in the EU database involve?
Two things worth knowing up front. One, the database is public: anyone can look up that your system exists and who offers it (Art. 49 and 71). E.g.: a CV-screening system will appear in the register under its provider's name. Two, registering is more than signing up: it will ask you to identify the system, describe its purpose and the data it uses, and attach the EU declaration of conformity and the certificate if a notified body was involved (Annex VIII). E.g.: have the purpose summary ready before you open the file.
Who enforces this, and what happens if I don't comply?
It doesn't take an inspection for this to matter. From 2 August 2026, anyone who believes an AI system breaches the Regulation can lodge a complaint with the market surveillance authority (Art. 85): a customer, a competitor or a former employee. And if you make decisions about people with a high-risk system, those people can ask you for a clear explanation of the AI's role (Art. 86). Keeping your documentation in order is your best defence.
Is this a calculator, a simulator or AI Act compliance software?
It is a screening tool. You answer a few questions about your system and it returns the risk level under Regulation (EU) 2024/1689, the articles that apply to you and the date they become enforceable, already on the Digital Omnibus timeline. That covers the first step, classification, which is where most teams get stuck. It is not compliance software: it does not build the Art. 9 risk management system, the Annex IV technical documentation or the EU database registration. That takes a project, not a form. If the result comes back high risk, the tool tells you which obligations open up and from when.
Is the classification the calculator returns final?
No. The calculator applies the decision tree of Regulation (EU) 2024/1689 to your answers and returns the corresponding risk level and planes. A final classification requires a specific analysis of the system and a legal reviewer. Treat it as a starting point, not a substitute for advice.
What sources does the calculator use?
The decision tree is built on top of the consolidated text of Regulation (EU) 2024/1689 published on EUR-Lex. Each article cited in the result links directly to EUR-Lex in the page's language. For practical interpretation, the official reference is the guidance the European Commission publishes on how to apply the Regulation (Art. 96).
How many categories does the Regulation use?
The Regulation sorts AI systems into four risk levels: prohibited (Art. 5), high risk (Art. 6 with Annexes I and III), transparency (Art. 50) and minimal. On top of that sit two planes that are not risk levels but change your obligations: whether you build a general-purpose model (GPAI, Chapter V), which can also carry systemic risk (Art. 51 and 55); and your role (provider, deployer, distributor or importer). That is why the result gives you all three at once: risk level, whether a GPAI model is involved and the role you fall into.
Do I have any obligations even if my system is low-risk?
Yes, one light and cross-cutting: AI literacy (Art. 4). If you are a provider or you use AI in your professional activity (deployer), you have to take measures so your team and anyone operating the system on your behalf understand the AI they handle, adapted to their training and the context of use. It does not require a certificate or a specific level: it is an obligation of means, applicable from 2 February 2025. E.g. a short internal briefing on what the tool does, its limits and when to distrust its output is usually enough for low-risk use.
Can I download the classification as a PDF?
Yes. After classifying there is a Download as PDF button that generates an A4 document with the classification, the cited articles, the applicable deadline, the obligations to map and the next actions.