Javascript on your browser is not enabled.

HomeCalculators › EU AI Act Risk Classifier

EU AI Act Risk Classifier

Is your AI product prohibited, high, limited or minimal risk? Answer a few guided questions and this free classifier walks the same decision tree regulators use — then tells you the obligations and deadlines that follow. Everything runs in your browser.

EU AI ACT RISK Classifier Calculator

The EU AI Act sorts AI into four risk tiers — unacceptable (prohibited), high (strict obligations), limited (transparency duties) and minimal (no mandatory rules) — with a separate track for general-purpose AI models. Your tier decides your obligations, your costs and your deadlines, so getting it right is the first compliance step.

1. What are you classifying?

A — Prohibited practices (Article 5)

Tick anything your system does. Any one of these makes it prohibited.

The first eight practices have been banned since Feb 2025. The ninth was added by the Digital Omnibus; safeguards are required by 2 Dec 2026.

B — High risk (Annex I & Annex III)

Tick anything that applies. Any one of these makes it high risk.

C — Transparency triggers (Article 50)

Tick anything that applies. If none of A or B applied, any of these makes it limited risk.

General-purpose AI model

Does your model have systemic risk?

Not legal advice. This classifier is an educational guide based on the EU AI Act (Regulation (EU) 2024/1689) as amended by the Digital Omnibus on AI (adopted July 2026). Classification can turn on fine detail and the rules continue to evolve. Confirm your classification with qualified legal counsel before acting. Your answers stay in your browser.

How classification actually works

The Act is a cascade, not a menu. You don't pick the tier that feels right; you fall through the tests in order and stop at the first that fits. A recruitment chatbot is not "limited risk" because it's a chatbot — employment screening is an Annex III high-risk use, and high risk wins. This ordering is what most self-assessments get wrong.

The four tiers

Unacceptable (prohibited) — banned practices under Article 5. The original eight have been in force since February 2025; the Digital Omnibus added a ninth in 2026 targeting AI that generates CSAM or non-consensual intimate imagery ("nudifier" apps). No compliance path exists; these systems simply must not be placed on the market or used.

High risk — Annex I (safety components of regulated products) or Annex III (eight standalone domains). Triggers the heavy obligations: risk management, data governance, technical documentation, logging, human oversight, conformity assessment and EU registration.

Limited risk — transparency duties under Article 50: tell people they're dealing with AI, and label synthetic or deepfake content.

Minimal risk — everything else (spam filters, AI in games). No mandatory obligations, though voluntary codes are encouraged.

Information Gain — the "low-risk" trap

The most expensive classification error isn't calling a minimal system high risk; it's the reverse. Teams label an HR-screening or credit model "limited risk" because it has a friendly chat interface, ship it, and discover at audit that the use case — not the interface — put it squarely in Annex III. The interface never determines the tier. The decision the AI influences does.

Pro Tip

Classify by intended purpose and use case, not by the technology. The same model can be minimal risk in one product and high risk in another. Re-classify whenever you repurpose a system or substantially modify it — that can turn a deployer into a provider.

Compliance Note — the timeline after the Digital Omnibus

The Digital Omnibus on AI was adopted in 2026 (Parliament 16 Jun, Council 29 Jun, signed 8 Jul) and deferred the heaviest deadlines. Current dates: prohibitions Feb 2025; GPAI rules Aug 2025; Article 50 transparency 2 Aug 2026 (marking of legacy AI-generated content 2 Dec 2026); new "nudifier"/CSAM ban safeguards 2 Dec 2026; high-risk Annex III 2 Dec 2027 (was Aug 2026); high-risk Annex I product-embedded 2 Aug 2028 (was Aug 2027). The obligations themselves did not change — only the deadlines. The extended runway is for building, not for waiting.

Frequently asked questions

What are the EU AI Act risk categories?

The EU AI Act sorts AI systems into four tiers: unacceptable risk, which is prohibited outright; high risk, which carries strict obligations; limited risk, which triggers transparency duties; and minimal risk, which has no mandatory requirements. General-purpose AI models follow a separate track of their own.

How does this EU AI Act classifier work?

It walks the same decision tree regulators use. It first checks whether your AI is a prohibited practice, then whether it is high risk under Annex I or Annex III, then whether transparency duties apply, and otherwise lands on minimal risk. General-purpose models are assessed separately.

What makes an AI system high risk under the Act?

An AI system is high risk if it is a safety component of, or itself, a product covered by EU safety law requiring third-party assessment (Annex I), or if it is used in an Annex III domain such as employment, credit scoring, education, biometrics, critical infrastructure, law enforcement, migration or justice.

What AI practices are prohibited?

Article 5 now bans nine practices. The original eight — harmful manipulation, exploiting vulnerabilities, social scoring, purely profiling-based crime prediction, untargeted facial image scraping, emotion recognition at work or school, sensitive biometric categorisation, and most real-time remote biometric identification in public spaces — have been prohibited since February 2025. The Digital Omnibus added a ninth in 2026: AI that generates child sexual abuse material or non-consensual intimate imagery, with safeguards required by December 2026.

What are limited-risk transparency obligations?

Under Article 50, limited-risk systems must be transparent. Chatbots must tell users they are AI, generative systems must mark synthetic output as artificially generated, deepfakes must be disclosed, and emotion-recognition or biometric-categorisation systems must inform the people exposed to them.

When do the EU AI Act obligations apply?

The Act entered into force in August 2024 and phases in. Prohibitions applied from February 2025 and general-purpose AI rules from August 2025. The Digital Omnibus, adopted in 2026, kept Article 50 transparency at 2 August 2026 but deferred the high-risk deadlines: standalone Annex III systems now apply from 2 December 2027 and product-embedded Annex I systems from 2 August 2028.

What changed in the EU AI Act in 2026?

The Digital Omnibus on AI, adopted in mid-2026, made several targeted changes. It deferred the high-risk deadlines — standalone Annex III systems to 2 December 2027 and product-embedded Annex I systems to 2 August 2028 — while keeping Article 50 transparency at 2 August 2026, with a three-month grace to 2 December 2026 for marking content from systems already on the market. It added a ninth Article 5 prohibition on AI that generates child sexual abuse material or non-consensual intimate imagery, carved AI in Machinery Regulation products out of the high-risk regime, and expanded the AI Office's supervisory powers. The four-tier structure and the underlying obligations did not change.

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies to providers and deployers placing AI on the EU market or putting it into service in the EU, and to those outside the EU whose AI output is used inside the EU. Location of the company does not by itself remove you from scope.

What about general-purpose AI models?

General-purpose AI models follow a separate track. All providers face documentation, copyright and training-data summary duties. Models with systemic risk, meaning very high-impact capabilities, carry extra obligations such as model evaluation, adversarial testing, incident reporting and cybersecurity. These rules applied from August 2025.

Is this classifier legal advice?

No. This tool is an educational guide to help you orient quickly; it is not legal advice and cannot account for your full context. Classification often turns on fine detail, and the rules are still evolving. Always confirm your classification with qualified legal counsel before acting.

What are the penalties for non-compliance?

Penalties are tiered. Engaging in prohibited practices can draw fines up to thirty-five million euros or seven percent of global annual turnover, whichever is higher. Other breaches carry lower caps. The exact figure depends on the infringement, the operator and national enforcement decisions.