Free tool

EU AI Act Risk Classifier

Answer up to six questions about one AI system and get its likely risk tier under the EU AI Act, the obligations that follow, and what to do next. No email required to see the result.

Question 1 of 1

Is the system placed on the EU market, or is its output used in the EU?

This reaches organizations established anywhere. Being headquartered outside the EU is not by itself an exemption, and output being used by an EU-based team or customer can be enough.

This tool gives a structured first read, not legal advice, and it does not create a professional relationship. Classification under the EU AI Act depends on the specific implementation and context, and the listed categories have precise definitions that plain-language summaries flatten. The phase-in timetable should be confirmed against current official guidance. Take qualified advice before relying on any classification for a compliance decision.

EU AI Act questions

What are the EU AI Act risk tiers?

Four. Prohibited practices, banned outright and not fixable through documentation. High-risk systems in listed areas such as employment, credit, essential services and critical infrastructure, plus AI acting as a safety component of a regulated product, where the substantive obligations concentrate. Limited-risk systems that carry transparency duties because they interact with people or generate content. And minimal risk, which is everything else.

Does the EU AI Act apply to companies outside the EU?

It can. The Act reaches organizations that place AI systems on the EU market or whose system output is used in the EU, regardless of where they are established. Output reaching an EU-based team, customer or subsidiary can create that nexus without anyone deciding to enter the EU market, which is why it is the question most worth re-checking.

What is the difference between a provider and a deployer?

A provider develops the system or places it on the market under their own name. A deployer uses a system someone else provides. The obligations differ substantially, and organizations frequently assume they are only deployers before discovering that substantially modifying a system, or putting their own name on it, can make them a provider.

Is high-risk classification a project or an ongoing cost?

Ongoing. The obligations include lifecycle risk management, post-market monitoring, incident reporting and retained logs, none of which end at go-live. Budget it as a permanent operating cost rather than a one-off compliance exercise.

Does this tool give legal advice?

No. It gives a structured first read to help you scope the work and brief the right people. Classification depends on the specific implementation and context, and the listed categories have precise definitions that plain-language summaries flatten. Take qualified advice before relying on a classification for a compliance decision.

What should we do before using the classifier?

Build an inventory of the AI systems actually in use, including features inside software bought for other reasons. You cannot classify systems you have not enumerated, and the embedded vendor features are the ones most often missed and most likely to be in scope without anyone having decided to adopt them.