AI risk assessment: which EU AI Act class is your system in?
Answer 24 yes/no questions about one AI system. You'll see whether it's likely prohibited, high-risk, subject to transparency rules or minimal risk, which answers put it there, and the deadline that applies.
Need the whole programme, not one check? AI Governance Toolkit: policy, risk register, EU AI Act, ISO/IEC 42001 and NIST AI RMF templates, from $199.
Your answers never leave your computer. The check runs in your browser, and this page is blocked from sending data anywhere.
Runs locally · 0 bytes uploaded
Turn one check into an AI governance programme
The AI Governance Toolkit gives you the policy, the inventory and risk register, a full per-system risk assessment (this screening plus 32 risk questions), and in the Professional edition the ISO/IEC 42001 gap assessment, NIST AI RMF mapping and AI vendor contract clauses.
The EU AI Act, part by part
- Prohibited practices (Article 5)
- High-risk uses (Annex III)
- High-risk products (Annex I)
- Transparency obligations (Article 50)
- General-purpose AI models
- Timeline: when each obligation applies
How the class is decided
- Any prohibited practice (Article 5) wins. Those have been banned since 2 February 2025.
- If the system isn't on the EU market, used in the EU, or producing output used there, it's likely outside scope.
- AI in a product under EU product-safety law is high-risk (Annex I); a use listed in Annex III is high-risk (Annex III).
- Chatbots, synthetic content, emotion recognition and deepfakes carry transparency obligations (Article 50).
- Everything else is minimal risk. "Unsure" answers send you to legal review rather than guessing.
EU AI Act dates
As amended by the Digital Omnibus on AI, which entered into force on 27 July 2026:
- 2 February 2025: prohibited practices and the AI literacy duty apply.
- 2 August 2025: obligations for general-purpose AI model providers apply.
- 2 August 2026: transparency obligations (Article 50) apply; systems already on the market have until 2 December 2026 for machine-readable marking of AI-generated content.
- 2 December 2027: stand-alone high-risk systems (Annex III), moved from 2 August 2026.
- 2 August 2028: high-risk AI in products under Annex I, moved from 2 August 2027.
What it can't tell you
This is a screening, not a legal opinion. Classification depends on details the questions can't see, such as the Article 6(3) exceptions for Annex III uses and whether you're the provider or the deployer. Anything that comes out prohibited or high-risk should go to counsel.
Questions
Are my answers stored or sent anywhere?
No. The page's security policy blocks every outgoing request (connect-src 'none'). Close the tab and they're gone.
Who made this?
Agent Trust Cloud, which builds software to discover, govern and monitor AI agents. The questions are our own summary of the EU AI Act, not legal text.