Answer five questions about your AI system and get a deterministic risk tier classification under Regulation (EU) 2024/1689. Minimal risk, limited risk, high-risk under Annex III, or prohibited practice. No AI, no signup, shareable result link.
Certain AI uses are banned outright under Article 5: subliminal manipulation, exploitation of vulnerabilities, untargeted scraping of facial images, real-time biometric surveillance in public spaces (with narrow exceptions), social scoring by public authorities, and AI that infers emotions in workplaces or education.
Obligations: If your system falls here, it cannot be placed on the market or put into service in the EU.
Systems listed in Annex III — including biometric categorisation, critical infrastructure management, education and vocational training, employment decisions, essential private/public services, law enforcement, migration and asylum, justice and democratic processes — are high-risk.
Obligations: High-risk systems require a documented risk management system (Article 9), technical documentation (Article 11), logging (Article 12), transparency to users (Article 13), human oversight measures (Article 14), and accuracy/robustness requirements (Article 15). Conformity assessment is required before market placement.
AI systems that interact with people — chatbots, emotion recognition, AI-generated content — have transparency obligations but are not high-risk. Users must know they are interacting with AI.
Obligations: Providers must ensure users are informed that they are interacting with an AI system. AI-generated content (deepfakes, synthetic audio) must be disclosed. No conformity assessment required.
The vast majority of AI systems — AI in video games, spam filters, recommendation engines, productivity tools — fall here. No specific obligations under the EU AI Act, though voluntary codes of conduct are encouraged.
Obligations: No mandatory obligations. Voluntary codes of practice and transparency commitments are encouraged but not required. General product safety and data protection law still applies.
The EU AI Act does not prescribe a format for Article 9 risk management records. In practice, a defensible record includes:
Drel produces these records. Run an AI security review on your high-risk system to get a structured clearance decision backed by an Article 9-aligned risk management record, technical documentation inputs, and re-assessment triggers. See the EU AI Act system inventory guide →
It applies to providers (who develop and place AI on the market) and deployers (who use AI in a professional context) where the system is used in the EU or affects people in the EU — regardless of where the organisation is based.
Annex III lists 8 categories of high-risk AI: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration and asylum management, and justice. If your system makes or materially assists decisions in these areas, start with a high-risk classification and confirm with legal counsel.
Article 9 requires a documented risk management system that runs throughout the system lifecycle — not a one-time assessment. It must identify and analyse risks, estimate and evaluate those risks, implement mitigation measures, and include a post-market monitoring plan. This is what a structured AI security review produces.
Most chatbots are limited risk (transparency obligation only). A chatbot used to screen job candidates, triage medical cases, or assist with benefit eligibility decisions is likely high-risk under Annex III. The use case — not the technology — determines the tier.
A provider develops and places an AI system on the market. A deployer uses a provider's system for their own purposes. Both have obligations for high-risk systems — providers for conformity assessment and technical documentation, deployers for Article 9 risk management, transparency, and human oversight in their specific use.
Yes. The EU AI Act is additive — it does not replace GDPR. Systems that process personal data must comply with both. For high-risk AI that involves automated decision-making with significant effects on individuals, a DPIA is likely required in addition to Article 9 risk management.
This tool provides a preliminary classification based on the EU AI Act (Regulation (EU) 2024/1689) as published. It does not constitute legal advice. Classification may be affected by implementation details, national transposition, and guidance from the EU AI Office not yet reflected here. Always verify with qualified legal counsel before making compliance decisions.