Free Tool · EU AI Act

EU AI Act Self-Assessment: What Risk Level Is Your AI?

Answer 10 questions about your AI system and get an indicative classification under the EU AI Act (Regulation (EU) 2024/1689): prohibited practices, high risk, limited risk or minimal risk, plus the GPAI branch. You get the concrete obligations of your level, the dates that affect you and the recommended next step.

  • 10 questions
  • ~3 minutes
  • No sign-up

Indicative result: this is not legal advice.

The Assessment, Question by Question

Ten questions about what your AI system does, where it is used and what your role is. At the end: your risk level, your obligations and your deadlines.

Do you offer or operate AI systems in the EU market?

The regulation applies to any organisation that provides or uses AI in the EU, whether or not it is based in Europe.

What is your role with respect to the AI system?

Obligations differ depending on whether you are a provider (you develop or market the system) or a deployer (you use it in your operations).

Do you develop or market a general-purpose AI model (GPAI)?

A GPAI is a model trained at scale that serves many different tasks, like GPT, Claude or Gemini. Integrating one via API does not make you a GPAI provider.

Does your system do any of the following?

These practices have been banned by the regulation since 2 February 2025.

Is your AI used in any of these areas (Annex III)?

If your AI influences decisions that affect people's rights, it is probably high risk.

Is your AI a safety component of a regulated product (machinery, medical devices, toys)?

This is the Annex I high-risk branch: its obligations arrive on 2 August 2027.

Does your system interact with people or generate content?

Chatbots and AI-generated content carry transparency obligations (limited risk).

Has your team received documented AI training (AI literacy, Article 4)?

Mandatory since 2 February 2025 for anyone using or overseeing AI systems: role-specific and documented.

Do you have an inventory and documentation of your AI systems (own and third-party)?

The inventory is the starting point of any compliance plan.

Is your organisation an SME or a startup?

The regulation provides proportionate fines for SMEs and startups (Article 99(6)).

The Four Risk Levels of the EU AI Act (and the GPAI Branch)

The EU AI Act regulates by risk level: the greater the potential impact on people, the heavier the obligations.

Prohibited

Unacceptable risk

Practices banned by the regulation: they cannot be documented or authorised, they must be withdrawn.

Subliminal manipulation, social scoring, mass biometric surveillance.

Stop the practice or redesign the system to exit the prohibited category.

Key deadline
Banned since 2 February 2025
Maximum penalty
Up to €35M or 7% of global turnover
High risk

High risk (Annex III and Annex I)

Systems that affect people's safety or fundamental rights.

AI in HR (CV screening, evaluation), credit scoring and insurance, education, healthcare (diagnosis, triage), justice and borders, critical infrastructure.

Risk management, data quality, technical documentation (Annex IV), traceability, human oversight and robustness. Registration in the EU database for providers.

Key deadline
Annex III: 2 August 2026 · Annex I (regulated products): 2 August 2027
Maximum penalty
Up to €15M or 3% of global turnover
Transparency

Limited risk

Systems that interact with people or generate content: the key is that the user knows.

Chatbots, virtual assistants, AI-generated content, deepfakes.

Disclose the AI interaction, label generated content (including deepfakes) and offer a human intervention mechanism.

Key deadline
With the regulation's general regime: 2 August 2026
Maximum penalty
General regime: up to €15M or 3%
No specific obligations

Minimal risk

Most AI in use: no level-specific obligations.

Spam filters, recommenders, internal process optimisation.

None specific to the level. AI literacy (Article 4) applies across the board.

Key deadline
Article 4 in force since 2 February 2025
Maximum penalty
No level-specific penalties
Separate branch

GPAI models

General-purpose models (like GPT, Claude or Gemini): provider obligations of their own, in parallel to the risk levels.

Models trained at scale that serve many different tasks. Whoever integrates them via API is a deployer, not a GPAI provider.

Technical documentation (model cards), transparency and copyright compliance.

Key deadline
Obligations since 2 August 2025 · Fines applicable from 2 August 2026
Maximum penalty
Up to €15M or 3% of global turnover

Obligations and Deadlines by Risk Level

A summary of Regulation (EU) 2024/1689 per level: what it demands, since when and with what maximum penalty.

LevelKey obligationsApplicable fromMaximum penalty
Prohibited practices Stop the practice or redesign the system; no documentation or commercial exception is possible. 2 February 2025 €35M or 7%
High risk (Annex III) Risk management, data quality, technical documentation (Annex IV), traceability, human oversight, robustness; registration in the EU database for providers. 2 August 2026 €15M or 3%
High risk (Annex I) The same requirements, for AI embedded as a safety component in regulated products (machinery, medical devices, toys). 2 August 2027 €15M or 3%
Limited risk Disclose the AI interaction, label generated content and deepfakes, human intervention mechanism. 2 August 2026 (general regime) General regime: €15M or 3%
Minimal risk No specific obligations; AI literacy (Article 4) applies across the board. Article 4: 2 February 2025 None specific
GPAI models Technical documentation, transparency and copyright compliance for model providers. 2 August 2025 (fines: 2 August 2026) €15M or 3%

Key Dates of the EU AI Act

Staggered application since its entry into force on 1 August 2024.

  1. In force 2 Feb 2025

    Prohibited practices and AI literacy

    Unacceptable AI practices are banned and staff AI literacy becomes mandatory (Article 4).

  2. In force 2 Aug 2025

    GPAI obligations and governance

    Obligations for general-purpose AI models, the governance framework and the general penalty regime.

  3. Next deadline 2 Aug 2026

    High risk (Annex III) and GPAI fines

    Full requirements for high-risk systems under Annex III; fines for GPAI providers become applicable.

  4. Upcoming 2 Aug 2027

    Embedded high risk (Annex I)

    Obligations for high-risk AI embedded in regulated products and for GPAI models placed on the market before 2 August 2025.

Frequently Asked Questions About the Self-Assessment

How the assessment works and what the regulation says about each level.

What does the EU AI Act self-assessment measure?

It classifies your AI system into the risk levels of the EU AI Act (Regulation (EU) 2024/1689) based on 10 questions: prohibited practices, high risk, limited risk or minimal risk, plus the GPAI branch. The result includes the obligations and deadlines of your level. It is indicative: a formal classification requires an inventory and a system-by-system analysis.

What are the risk levels of the EU AI Act?

Four: unacceptable (prohibited: subliminal manipulation, social scoring, mass biometric surveillance), high (strictly regulated: HR, credit, justice, healthcare, education, critical infrastructure), limited (transparency obligations: chatbots, deepfakes) and minimal (no specific obligations). General-purpose AI models (GPAI) additionally carry obligations of their own.

What happens on 2 August 2026?

The full requirements for high-risk AI systems under Annex III apply: risk management, data quality, technical documentation, human oversight and robustness. On the same day, fines for GPAI model providers become applicable. For high-risk AI embedded in regulated products (Annex I), the deadline arrives on 2 August 2027.

How high are the EU AI Act fines?

Up to €35M or 7% of global annual turnover (whichever is higher) for prohibited practices. For other infringements, including high-risk obligations and those of GPAI providers: up to €15M or 3%. For supplying incorrect information to authorities: up to €7.5M or 1%. For SMEs and startups, the lower of the two amounts applies (Article 99(6)).

I only use third-party AI: does the regulation affect me?

Yes. Even if you only use third-party AI (a chatbot, ChatGPT, an HR tool), you are a deployer and have obligations of your own: AI literacy for your team (Article 4, in force since 2 February 2025), not using prohibited practices and, if the system is high risk, human oversight, transparency and impact assessment. These obligations cannot be delegated to the provider.

What is a GPAI model and what obligations does it carry?

A general-purpose AI model (GPAI) is a model trained at scale that serves many different tasks, like GPT, Claude or Gemini. Its providers have had obligations since 2 August 2025 (technical documentation, transparency, copyright compliance) and the associated fines are applicable from 2 August 2026. If you integrate one of these models via API, you are a deployer, with obligations of your own but different ones.

Is the assessment result legal advice?

No. The self-assessment is indicative and does not constitute legal advice, nor does it replace an analysis of your case by qualified professionals. A formal classification requires a system inventory, risk classification under Annex III and a documented gap analysis: that is the job of a compliance diagnostic.

Reach 2 August 2026 With Your File Ready

The assessment result is the starting point. Turning it into real compliance takes inventory, classification and documentation: our EU AI Act compliance service does it with you.

Talk to us
No commitment Response in 24h Custom proposal