Free tool · No signup required

EU AI Act Risk Tier Classifier

Answer focused questions about your AI system and get a deterministic risk tier under Regulation (EU) 2024/1689, updated for the 2026 AI Omnibus. Minimal, limited, Annex III high-risk, or prohibited. No AI, no signup, shareable result link.

What each risk tier requires

Prohibited practice

Article 5 bans ten categories, including manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, restricted biometric and emotion-recognition uses, and — from 2 December 2026 — AI used for non-consensual intimate material or child sexual abuse material.

Obligations: If your system falls here, it cannot be placed on the market or put into service in the EU.

High-risk AI system

Systems listed in Annex III — including biometric categorisation, critical infrastructure management, education and vocational training, employment decisions, essential private/public services, law enforcement, migration and asylum, justice and democratic processes — are high-risk.

Obligations: For Annex III systems, the high-risk obligations apply from 2 December 2027. They include risk management (Article 9), technical documentation, logging, transparency, human oversight, accuracy and robustness, plus conformity assessment where required.

Limited risk

AI systems that interact with people — chatbots, emotion recognition, AI-generated content — have transparency obligations but are not high-risk. Users must know they are interacting with AI.

Obligations: Providers must ensure users are informed that they are interacting with an AI system. AI-generated content (deepfakes, synthetic audio) must be disclosed. No conformity assessment required.

Minimal risk

The vast majority of AI systems — AI in video games, spam filters, recommendation engines, productivity tools — fall here. No specific obligations under the EU AI Act, though voluntary codes of conduct are encouraged.

Obligations: No mandatory obligations. Voluntary codes of practice and transparency commitments are encouraged but not required. General product safety and data protection law still applies.

If your system is high-risk: what to produce

The EU AI Act does not prescribe a format for Article 9 risk management records. In practice, a defensible record includes:

  • Risk identification. A list of foreseeable risks specific to your system — not a generic category list, but the risks that actually apply given your system's architecture, data, and use context.
  • Risk evaluation. An assessment of likelihood and severity for each identified risk, with the mitigating controls in place or required.
  • Technical documentation (Article 11 / Annex IV). A documentation file covering system description, design specifications, training data overview, testing methodology, and risk management records.
  • Conformity assessment. For Annex III systems: either a self-assessment (most categories) or a third-party notified body assessment (biometrics, law enforcement, some other categories).
  • Re-assessment plan. Named triggers that initiate a re-assessment: model updates, new training data, scope expansion, operational incidents.

Drel produces these records. Run an AI security review on your high-risk system to get a structured clearance decision backed by an Article 9-aligned risk management record, technical documentation inputs, and re-assessment triggers. See the EU AI Act system inventory guide →

Frequently asked questions

Does the EU AI Act apply to my organisation?

It applies to providers (who develop and place AI on the market) and deployers (who use AI in a professional context) where the system is used in the EU or affects people in the EU — regardless of where the organisation is based.

What is Annex III and how do I know if my system is in it?

Annex III lists 8 categories of high-risk AI: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration and asylum management, and justice. If your system makes or materially assists decisions in these areas, start with a high-risk classification and confirm with legal counsel.

What does Article 9 actually require for high-risk systems?

For providers of high-risk systems, Article 9 requires a documented lifecycle risk management system: identify and evaluate risks, test and mitigate them, and maintain the record as the system changes. Deployers have separate operational obligations under Article 26.

Is a chatbot high-risk?

Most chatbots are limited risk (transparency obligation only). A chatbot used to screen job candidates, triage medical cases, or assist with benefit eligibility decisions is likely high-risk under Annex III. The use case — not the technology — determines the tier.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system or places it on the market under its name. A deployer uses a system under its authority for a professional purpose. Providers own the Article 9–15 system requirements and conformity route; deployers have the separate operational duties in Article 26.

Does GDPR still apply?

Yes. The EU AI Act is additive — it does not replace GDPR. Systems that process personal data must comply with both. For high-risk AI that involves automated decision-making with significant effects on individuals, a DPIA is likely required in addition to Article 9 risk management.

This preliminary classifier reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, including the 2 December 2026 Article 5 additions and the revised high-risk dates. It is not legal advice. Verify classification and applicability with qualified legal counsel. Official sources: Regulation (EU) 2026/1744 and the European Commission summary. Last reviewed 29 August 2026.