Free tool · No signup required

EU AI Act Risk Tier Classifier

Answer five questions about your AI system and get a deterministic risk tier classification under Regulation (EU) 2024/1689. Minimal risk, limited risk, high-risk under Annex III, or prohibited practice. No AI, no signup, shareable result link.

What each risk tier requires

Prohibited practice

Certain AI uses are banned outright under Article 5: subliminal manipulation, exploitation of vulnerabilities, untargeted scraping of facial images, real-time biometric surveillance in public spaces (with narrow exceptions), social scoring by public authorities, and AI that infers emotions in workplaces or education.

Obligations: If your system falls here, it cannot be placed on the market or put into service in the EU.

High-risk AI system

Systems listed in Annex III — including biometric categorisation, critical infrastructure management, education and vocational training, employment decisions, essential private/public services, law enforcement, migration and asylum, justice and democratic processes — are high-risk.

Obligations: High-risk systems require a documented risk management system (Article 9), technical documentation (Article 11), logging (Article 12), transparency to users (Article 13), human oversight measures (Article 14), and accuracy/robustness requirements (Article 15). Conformity assessment is required before market placement.

Limited risk

AI systems that interact with people — chatbots, emotion recognition, AI-generated content — have transparency obligations but are not high-risk. Users must know they are interacting with AI.

Obligations: Providers must ensure users are informed that they are interacting with an AI system. AI-generated content (deepfakes, synthetic audio) must be disclosed. No conformity assessment required.

Minimal risk

The vast majority of AI systems — AI in video games, spam filters, recommendation engines, productivity tools — fall here. No specific obligations under the EU AI Act, though voluntary codes of conduct are encouraged.

Obligations: No mandatory obligations. Voluntary codes of practice and transparency commitments are encouraged but not required. General product safety and data protection law still applies.

If your system is high-risk: what to produce

The EU AI Act does not prescribe a format for Article 9 risk management records. In practice, a defensible record includes:

  • Risk identification. A list of foreseeable risks specific to your system — not a generic category list, but the risks that actually apply given your system's architecture, data, and use context.
  • Risk evaluation. An assessment of likelihood and severity for each identified risk, with the mitigating controls in place or required.
  • Technical documentation (Article 11 / Annex IV). A documentation file covering system description, design specifications, training data overview, testing methodology, and risk management records.
  • Conformity assessment. For Annex III systems: either a self-assessment (most categories) or a third-party notified body assessment (biometrics, law enforcement, some other categories).
  • Re-assessment plan. Named triggers that initiate a re-assessment: model updates, new training data, scope expansion, operational incidents.

Drel produces these records. Run an AI security review on your high-risk system to get a structured clearance decision backed by an Article 9-aligned risk management record, technical documentation inputs, and re-assessment triggers. See the EU AI Act system inventory guide →

Frequently asked questions

Does the EU AI Act apply to my organisation?

It applies to providers (who develop and place AI on the market) and deployers (who use AI in a professional context) where the system is used in the EU or affects people in the EU — regardless of where the organisation is based.

What is Annex III and how do I know if my system is in it?

Annex III lists 8 categories of high-risk AI: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration and asylum management, and justice. If your system makes or materially assists decisions in these areas, start with a high-risk classification and confirm with legal counsel.

What does Article 9 actually require for high-risk systems?

Article 9 requires a documented risk management system that runs throughout the system lifecycle — not a one-time assessment. It must identify and analyse risks, estimate and evaluate those risks, implement mitigation measures, and include a post-market monitoring plan. This is what a structured AI security review produces.

Is a chatbot high-risk?

Most chatbots are limited risk (transparency obligation only). A chatbot used to screen job candidates, triage medical cases, or assist with benefit eligibility decisions is likely high-risk under Annex III. The use case — not the technology — determines the tier.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops and places an AI system on the market. A deployer uses a provider's system for their own purposes. Both have obligations for high-risk systems — providers for conformity assessment and technical documentation, deployers for Article 9 risk management, transparency, and human oversight in their specific use.

Does GDPR still apply?

Yes. The EU AI Act is additive — it does not replace GDPR. Systems that process personal data must comply with both. For high-risk AI that involves automated decision-making with significant effects on individuals, a DPIA is likely required in addition to Article 9 risk management.

This tool provides a preliminary classification based on the EU AI Act (Regulation (EU) 2024/1689) as published. It does not constitute legal advice. Classification may be affected by implementation details, national transposition, and guidance from the EU AI Office not yet reflected here. Always verify with qualified legal counsel before making compliance decisions.