Does the EU AI Act Apply to You?
Answer 5 quick questions to discover your AI system's risk classification and compliance gaps under the EU AI Act.
Under 90 seconds
No signup required
Based on EU 2024/1689
Instant risk result
The EU AI Act (Regulation 2024/1689) classifies AI systems into risk levels with different compliance obligations. This free assessment takes under 90 seconds and tells you exactly where your AI system stands — and what you need to do before the August 2, 2026 deadline.
Based on Regulation (EU) 2024/1689. For guidance only — not legal advice.
How the EU AI Act Risk Assessment Works
The EU AI Act (Regulation 2024/1689) establishes a risk-based framework that classifies AI systems into four tiers: prohibited, high-risk, limited-risk, and minimal-risk. Each tier carries different compliance obligations, from outright bans on certain AI practices to transparency requirements for chatbots and content generators. Our free assessment maps your AI system against these tiers using the same criteria defined in the regulation.
The assessment evaluates five factors: your geographic market nexus (Article 2 scope), your role in the AI value chain (provider, deployer, or GPAI), your use case against Annex III high-risk categories, the impact of AI decisions on individuals, and your current documentation readiness. Based on your answers, the tool calculates your risk classification and estimates the number of compliance gaps to address before the August 2, 2026 enforcement deadline.
EU AI Act Risk Levels Explained
Prohibited (Article 5)
AI practices that are banned outright: social scoring, subliminal manipulation, exploitation of vulnerabilities, real-time biometric ID in public spaces, emotion recognition in workplace/education, and facial recognition database scraping. In force since February 2, 2025. Fines up to EUR 35M or 7% of global turnover.
High-Risk (Annex III)
AI systems in 8 sensitive categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Full compliance with Articles 9-15 required by August 2, 2026. Includes risk management, technical documentation, logging, transparency, human oversight, and conformity assessment.
Limited-Risk (Article 50)
AI systems that interact with people (chatbots), generate content (deepfakes, synthetic media), or perform emotion recognition. Transparency obligations apply: disclose AI interaction, label AI-generated content, inform subjects of emotion recognition. Lighter than high-risk but still mandatory.
Minimal-Risk
AI systems that do not fall into any higher category. No mandatory obligations beyond AI literacy (Article 4, in force since February 2025). Voluntary codes of conduct encouraged. Examples: spam filters, AI-powered inventory management, game AI.
Frequently Asked Questions
How do I know if the EU AI Act applies to my company?
The EU AI Act applies if you place an AI system on the EU market, put it into service in the EU, or if the output of your AI system is used by persons located in the EU. This includes non-EU companies with EU customers. Take our free 5-question assessment above to check your specific situation.
What is a high-risk AI system under the EU AI Act?
A high-risk AI system is one that falls into the 8 categories listed in Annex III of the EU AI Act: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. High-risk systems must comply with Articles 9-15 requirements including risk management, technical documentation, logging, transparency, human oversight, and accuracy. Full enforcement begins August 2, 2026.
Is my AI system high risk under the EU AI Act?
Whether your AI system is high-risk depends on its use case and the sector it operates in. If it makes or influences decisions about people in areas like hiring, credit scoring, education, healthcare, or law enforcement, it is likely high-risk under Annex III. Use the assessment tool above to get an instant classification based on your specific AI system.
What are the EU AI Act risk levels?
The EU AI Act defines four risk tiers: Prohibited (banned practices like social scoring, in force since Feb 2025), High-Risk (8 Annex III categories, full obligations by Aug 2026), Limited-Risk (transparency for chatbots/deepfakes), and Minimal-Risk (no mandatory obligations beyond AI literacy). GPAI models have separate obligations under Articles 53-55, in force since August 2025.
Do I need to comply with the EU AI Act if I'm not in the EU?
Yes, potentially. The EU AI Act has extraterritorial reach similar to GDPR. If your AI system's output is used by persons in the EU, the Act applies regardless of where your company is based. This includes SaaS products, APIs, and AI models used by EU customers. Non-EU companies with EU users must comply with the same obligations as EU-based companies.
Related Resources
EU AI Act Risk Classification Guide
Deep dive into the four risk tiers, Annex III categories, and the decision tree for classifying your AI system.
EU AI Act Compliance Checklist
Article-by-article compliance checklist covering all obligations for providers, deployers, and GPAI models.
EU AI Act Overview
Comprehensive guide to Regulation (EU) 2024/1689 — scope, timeline, and what it means for your organization.
Scanara Features
Automated code scanning, document validation, and compliance reporting for EU AI Act — in your CI/CD pipeline.