Home / Which EU AI Act risk tier is your AI in?

Which EU AI Act risk tier is your AI in?

The EU AI Act sorts every AI system into four risk tiers, and each tier carries its own obligations and deadlines. Take a short check and see where your system lands, who carries which duty and from when, with the article cited. Based on the AI Act as amended by Regulation (EU) 2026/1744. Free, no email required, not legal advice.

  1. 1Prohibited practicesDoes your system fall under Art. 5?
  2. 2High-risk usesAnnex I or III, with the Art. 6(3) exception.
  3. 3TransparencyProvider or deployer duties, by role.
  4. 4Your tier + deadlineObligations and the compliance date.
Free · no email · ~2 min

EU AI Act risk checker

A short check in six steps: your role, prohibited practices, high risk, the Article 6(3) exception, transparency and general-purpose AI models. Every result cites the article it rests on.

6 steps~2 minutesNo email needed

This tool gives an indication based on Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, and is not legal advice. Final classification depends on your system and context. · Source: EUR-Lex

EU AI Act: frequently asked questions

What are the EU AI Act risk tiers?

Four: unacceptable risk (banned), high risk (heaviest obligations), limited risk (transparency duty) and minimal risk (no obligations). Separate rules also apply to general-purpose AI models (GPAI).

When does the EU AI Act take effect?

The regulation has been in force since 1 August 2024. Prohibited practices apply from 2 February 2025 (two new prohibitions from 2 December 2026), GPAI rules from 2 August 2025 and the Article 50 transparency duties from 2 August 2026. Under Regulation (EU) 2026/1744, high-risk requirements apply from 2 December 2027 for Annex III uses and from 2 August 2028 for Annex I products.

Does the EU AI Act apply to SMEs?

Yes. It applies to any provider or user of AI in the EU regardless of company size. Small companies get lighter burdens and support (such as regulatory sandboxes), and most SME use cases fall into the minimal-risk tier.

Is my chatbot a high-risk system?

Usually not. A customer-service chatbot is typically covered by Article 50(1): the provider must design it so people know they are talking to AI, unless that is obvious. High risk arises in uses such as recruitment, credit scoring or critical infrastructure, and even then the Article 6(3) exception can apply if the system does not profile people.

What are the penalties for non-compliance?

Up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for other breaches, whichever is higher. SMEs face proportionally lower caps.

What is a general-purpose AI model (GPAI)?

A broadly usable model (such as a foundation or language model) that you train and provide yourself. Providers have their own obligations: technical documentation, a copyright policy and a training-data summary, with extra requirements at systemic risk.