Answer focused questions about your AI system and get a deterministic risk tier under Regulation (EU) 2024/1689, updated for the 2026 AI Omnibus. Minimal, limited, Annex III high-risk, or prohibited. No AI, no signup, shareable result link.
Article 5 bans ten categories, including manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, restricted biometric and emotion-recognition uses, and — from 2 December 2026 — AI used for non-consensual intimate material or child sexual abuse material.
Obligations: If your system falls here, it cannot be placed on the market or put into service in the EU.
Systems listed in Annex III — including biometric categorisation, critical infrastructure management, education and vocational training, employment decisions, essential private/public services, law enforcement, migration and asylum, justice and democratic processes — are high-risk.
Obligations: For Annex III systems, the high-risk obligations apply from 2 December 2027. They include risk management (Article 9), technical documentation, logging, transparency, human oversight, accuracy and robustness, plus conformity assessment where required.
AI systems that interact with people — chatbots, emotion recognition, AI-generated content — have transparency obligations but are not high-risk. Users must know they are interacting with AI.
Obligations: Providers must ensure users are informed that they are interacting with an AI system. AI-generated content (deepfakes, synthetic audio) must be disclosed. No conformity assessment required.
The vast majority of AI systems — AI in video games, spam filters, recommendation engines, productivity tools — fall here. No specific obligations under the EU AI Act, though voluntary codes of conduct are encouraged.
Obligations: No mandatory obligations. Voluntary codes of practice and transparency commitments are encouraged but not required. General product safety and data protection law still applies.
The EU AI Act does not prescribe a format for Article 9 risk management records. In practice, a defensible record includes:
Drel produces these records. Run an AI security review on your high-risk system to get a structured clearance decision backed by an Article 9-aligned risk management record, technical documentation inputs, and re-assessment triggers. See the EU AI Act system inventory guide →
It applies to providers (who develop and place AI on the market) and deployers (who use AI in a professional context) where the system is used in the EU or affects people in the EU — regardless of where the organisation is based.
Annex III lists 8 categories of high-risk AI: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration and asylum management, and justice. If your system makes or materially assists decisions in these areas, start with a high-risk classification and confirm with legal counsel.
For providers of high-risk systems, Article 9 requires a documented lifecycle risk management system: identify and evaluate risks, test and mitigate them, and maintain the record as the system changes. Deployers have separate operational obligations under Article 26.
Most chatbots are limited risk (transparency obligation only). A chatbot used to screen job candidates, triage medical cases, or assist with benefit eligibility decisions is likely high-risk under Annex III. The use case — not the technology — determines the tier.
A provider develops an AI system or places it on the market under its name. A deployer uses a system under its authority for a professional purpose. Providers own the Article 9–15 system requirements and conformity route; deployers have the separate operational duties in Article 26.
Yes. The EU AI Act is additive — it does not replace GDPR. Systems that process personal data must comply with both. For high-risk AI that involves automated decision-making with significant effects on individuals, a DPIA is likely required in addition to Article 9 risk management.
This preliminary classifier reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, including the 2 December 2026 Article 5 additions and the revised high-risk dates. It is not legal advice. Verify classification and applicability with qualified legal counsel. Official sources: Regulation (EU) 2026/1744 and the European Commission summary. Last reviewed 29 August 2026.