Free Tools For You

EU AI Act Risk Checker

Describe your AI use case in a few sentences and get its risk category, your concrete obligations, and the deadlines that apply. Takes about 2 minutes.

Your use case

Describe your AI use case, and see where it falls.

No, not everything slipped to 2027 - transparency duties apply from Aug 2, 2026

EU AI Act Risk Checker
0 / 1500 (min. 50)
The analysis is indicative and does not constitute legal advice.
The guide

The EU AI Act explained in plain language.

The AI Act applies to AI systems placed on the market or used in the EU. Your obligations depend on whether you are a provider (you build or supply the system) or a deployer (you use it) - and on which of four risk tiers your use case falls into.

/01

Prohibited

  • Practices banned outright - e.g. workplace emotion recognition, social scoring, untargeted face scraping.
/02

High risk

  • CV screening, credit scoring, exam grading, safety components - heavy obligations for providers and deployers.
/03

Limited risk

  • Chatbots, AI-generated content, deepfakes - transparency duties under Art. 50, live from Aug 2, 2026.
/04

Minimal risk

  • Most internal tools - no mandatory requirements, but the Art. 4 AI-literacy duty still applies.
Deadlines

The deadline timeline, after the Digital Omnibus.

Half the market believes "everything slipped to 2027". It did not - transparency obligations go live in weeks.

  1. Feb 2, 2025in force

    Ban on prohibited practices; AI-literacy duty (Art. 4) for all providers and deployers

  2. Aug 2, 2025in force

    General-purpose AI (GPAI) rules; governance framework; penalty regime

  3. Aug 2, 2026weeks away

    Art. 50 transparency: chatbot disclosure, deepfake labelling, notice of emotion recognition and biometric categorisation

  4. Dec 2, 2026upcoming

    Machine-readable marking (watermarking, Art. 50(2)) for providers of generative systems; new ban: non-consensual intimate images and CSAM

  5. Dec 2, 2027upcoming

    Obligations for standalone high-risk systems (Annex III) - moved from Aug 2026

  6. Aug 2, 2028upcoming

    Obligations for high-risk systems embedded in products (Annex I)

Grandfathering: high-risk systems placed on the market before their deadline are exempt from the full requirement package until substantially modified.

Quick check

Common use cases, classified at a single glance.

Quick check
  • CV screening / candidate ranking AIHIGHAnnex III 4 (employment)
  • Employee performance evaluation / monitoring AIHIGHAnnex III 4
  • Creditworthiness scoringHIGHAnnex III 5(b)
  • Life & health insurance pricing with AIHIGHAnnex III 5(c)
  • Admissions / exam grading AI in educationHIGHAnnex III 3
  • Customer-service chatbotLIMITEDArt. 50 disclosure duty
  • Marketing deepfake / AI avatar videoLIMITEDArt. 50 labelling duty
  • Internal knowledge-base search (RAG)MINIMAL (typically)no Annex III area
  • Predictive maintenance in manufacturingMINIMALunless a safety component (check Annex I)
  • Webshop recommender systemMINIMALno affected area
  • Emotion recognition in the workplacePROHIBITEDArt. 5(1)(f), except medical/safety purposes
  • Real-time facial recognition in public spacesPROHIBITEDArt. 5(1)(h), narrow law-enforcement exceptions
Penalties

What a breach costs: the ceilings of the fines.

  1. EUR 35MMaximum penalty for prohibited practices
  2. EUR 15MOther breaches of obligations
  3. EUR 7.5MMisleading information to authorities. For SMEs the lower of the two applies.
FAQ

Frequently asked questions about the AI Act.

FAQ

Answer

Yes. As a deployer you have your own obligations - lighter than a provider's, but real: transparency, human oversight, and for high-risk systems, monitoring and log retention.

Prefer a human?

Send us your results, and we'll map out your next step.

Write to us by email or through the form, with your tool results or just your questions.

Write to us