gekro
GitHub LinkedIn
AI

EU AI Act Risk Classifier

Find out which risk tier your AI system falls into, what that obliges you to do, and the date it actually applies from

System under assessment

Label for your export only. Never leaves the browser.

Step 1 · Prohibited practices - Article 5

Tick anything the system does. One tick here ends the analysis - these are banned outright, and have been since 2 February 2025.

Step 2 · Regulated products - Annex I

Is the AI a safety component of one of these products, or itself such a product, where third-party conformity assessment is already required?

Step 3 · High-risk use cases - Annex III

The eight standalone high-risk areas. Tick every one that applies to the intended purpose, not just the current deployment.

Step 4 · Derogation - Article 6(3)

An Annex III system escapes high-risk only if it does not pose a significant risk of harm to health, safety or fundamental rights and at least one condition below holds. Both halves are required.

Step 5 · Transparency - Article 50

These stack on whatever tier you land in. A high-risk system that also chats to people owes both sets of duties.

Step 6 · General-purpose models - Articles 51-56

A separate obligation track for whoever places the model itself on the market. Fine-tuning someone else's model can make you a provider of the modified model.

Disclaimer

Provided as is, with no warranty of any kind, express or implied, and no guarantee that any figure, rule or date here is accurate, complete or current. This is a triage aid written by an engineer, not a lawyer. It is not legal advice and creates no professional relationship. Classification under the AI Act turns on your specific intended purpose and deployment context, national implementations differ, and the law demonstrably moves: the Digital Omnibus rewrote the compliance calendar in July 2026. Do not rely on this output for a compliance decision. Check the official text and take qualified legal advice before you act on it. Use entirely at your own risk.

Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Logic last checked 28 August 2026. Nothing you type here is transmitted anywhere.

As-is, no warranty. These apps are free under their listed license and run entirely in your browser. Use at your own risk — don't blame me if your PC catches fire, your dog runs away, or the math turns out wrong. Verify anything that actually matters. None of this is professional financial, medical, legal, or engineering advice.

© 2026 Rohit Burani · MIT · Built at gekro.com · View source ↗

Guide

How this works

The Act is a decision procedure, so this is one too. It asks the questions in the order the regulation applies them, and the first hard stop wins:

  1. Scope. The Act bites when a system is placed on the EU market, put into service in the EU, or its output is used in the EU. That last limb catches a lot of providers who assume they are outside it. Military, defence, national security and purely personal non-professional use are carved out by Article 2.
  2. Article 5. Nine prohibited practices. One tick here ends the analysis, because the practice is banned rather than regulated.
  3. Annex I. AI as a safety component of a product already covered by EU harmonised product-safety law. Conformity assessment runs through the existing sectoral regime.
  4. Annex III. The eight standalone high-risk areas.
  5. Article 6(3). The derogation out of Annex III, which needs a no-significant-risk finding and one of four conditions. Profiling voids it outright.
  6. Article 50. Transparency duties, which stack on top of whatever tier you landed in.
  7. Articles 51 to 56. General-purpose model obligations, a separate track for whoever places the model itself on the market.

What it does differently

The tiers stack. Most classifiers hand you one label and stop. In the Act they are not mutually exclusive: a high-risk recruitment system that also talks to candidates owes Chapter III duties and Article 50 duties, and a general-purpose model provider owes Chapter V regardless of what the downstream system does. This tool reports every track you are on.

The derogation is modelled properly. Article 6(3) is a two-part test, not a menu. You need both the finding that the system poses no significant risk of harm and at least one of the four conditions. And even then, the final paragraph makes profiling of natural persons always high-risk. The tool refuses to grant the derogation if you tick profiling.

A derogation is not an exit. Article 6(4) still requires you to document the assessment before placing the system on the market, register it in the EU database anyway, and hand the documentation over on request. The tool says so.

The dates are the post-Omnibus ones. This is the part most secondary sources still get wrong.

The calendar, after the Digital Omnibus

Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is enacted law, not a proposal, and it moved the high-risk regime:

ObligationApplies from
Article 5 prohibitions, Article 4 AI literacy2 February 2025
General-purpose model obligations2 August 2025
Article 50 transparency2 August 2026
Machine-readable marking, systems already on the market2 December 2026
High-risk via Annex III2 December 2027, deferred from 2 August 2026
High-risk via Annex I2 August 2028, deferred from 2 August 2027

The deferral bought time to build compliance infrastructure. It did not remove the duty to work out your classification, and the analysis is the slow part anyway.

Inputs explained

  • Your role - provider, deployer, importer or product manufacturer. The duty tables change completely. Watch for the Article 25 trap: a deployer who rebrands a high-risk system, substantially modifies it, or repurposes it into a high-risk use becomes the provider and inherits the entire Chapter III burden. Fine-tuning counts.
  • Intended purpose - tick Annex III areas against what the system is for, not only what it currently does. Classification follows intended purpose.
  • Systemic risk - training compute above 10^25 FLOP, or a Commission designation. It pulls in Article 55 on top of Article 53, and it cancels the open-source relief entirely.

Penalties

Article 99 sets three bands: up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, EUR 15,000,000 or 3% for most other breaches, and EUR 7,500,000 or 1% for supplying incorrect or misleading information to authorities. For most undertakings the higher of the two figures applies. For SMEs and start-ups it is the lower one, under Article 99(6).

Sources

Limitations

  • This is triage, not legal advice. Classification turns on the specific intended purpose and the deployment context. A tool that reduces that to checkboxes is useful for orientation and useless as a defence.
  • Annex I is compressed. The real annex lists individual harmonisation instruments; this groups them into three families. If you tick it, go and read the actual annex.
  • National implementation varies. Member States designate their own market surveillance authorities and set their own penalty procedures within the Article 99 ceilings.
  • It cannot tell you whether you pose a significant risk of harm. That judgement under Article 6(3) is yours to make and yours to document, and an authority can disagree with it.
  • The Act moves. The Omnibus proved that. The date on this page is when the classification logic was last checked against the text.

Disclaimer

This tool is provided as is, with no warranty of any kind, express or implied, including no warranty of merchantability, fitness for a particular purpose, accuracy, completeness or currency.

It is a triage aid written by an engineer, not a lawyer. It is not legal advice, it does not create any professional or advisory relationship, and it must not be used as the basis for a compliance decision. Classification under the AI Act depends on your specific intended purpose and deployment context; national implementations differ; and the law moves, as the Digital Omnibus demonstrated in July 2026 by rewriting the compliance calendar with three weeks of notice.

Check the official text and take qualified legal advice before acting on anything here. To the fullest extent permitted by law, no liability is accepted for any loss or damage arising from use of this tool or reliance on its output. Use entirely at your own risk.

For informational purposes only. Not financial, medical, or legal advice. You are solely responsible for how you use these tools.