AI Risk Assessment Tool AI Governance Toolkit

AI risk assessment: which EU AI Act class is your system in?

Answer 24 yes/no questions about one AI system. You'll see whether it's likely prohibited, high-risk, subject to transparency rules or minimal risk, which answers put it there, and the deadline that applies.

Need the whole programme, not one check? AI Governance Toolkit: policy, risk register, EU AI Act, ISO/IEC 42001 and NIST AI RMF templates, from $199.

Your answers never leave your computer. The check runs in your browser, and this page is blocked from sending data anywhere.

Runs locally · 0 bytes uploaded

Turn one check into an AI governance programme

The AI Governance Toolkit gives you the policy, the inventory and risk register, a full per-system risk assessment (this screening plus 32 risk questions), and in the Professional edition the ISO/IEC 42001 gap assessment, NIST AI RMF mapping and AI vendor contract clauses.

The EU AI Act, part by part

How the class is decided

  1. Any prohibited practice (Article 5) wins. Those have been banned since 2 February 2025.
  2. If the system isn't on the EU market, used in the EU, or producing output used there, it's likely outside scope.
  3. AI in a product under EU product-safety law is high-risk (Annex I); a use listed in Annex III is high-risk (Annex III).
  4. Chatbots, synthetic content, emotion recognition and deepfakes carry transparency obligations (Article 50).
  5. Everything else is minimal risk. "Unsure" answers send you to legal review rather than guessing.

EU AI Act dates

As amended by the Digital Omnibus on AI, which entered into force on 27 July 2026:

What it can't tell you

This is a screening, not a legal opinion. Classification depends on details the questions can't see, such as the Article 6(3) exceptions for Annex III uses and whether you're the provider or the deployer. Anything that comes out prohibited or high-risk should go to counsel.

Questions

Are my answers stored or sent anywhere?

No. The page's security policy blocks every outgoing request (connect-src 'none'). Close the tab and they're gone.

Who made this?

Agent Trust Cloud, which builds software to discover, govern and monitor AI agents. The questions are our own summary of the EU AI Act, not legal text.