Free EU AI Act compliance tool · legal dates verified October 2026

EU AI Act Compliance Checker

A free risk classifier for one AI system: its tier, your obligations and the dates as amended by the 2026 Digital Omnibus

This EU AI Act compliance checker classifies one AI system in up to twelve questions. It tests the Article 2 exclusions, the Article 5 bans, both high-risk routes in Article 6, the Article 50 transparency triggers and the rules for general-purpose models, then lists your role’s obligations with article references and the application dates as amended by Regulation (EU) 2026/1744.

Check one AI system

Answer for a single system and its intended purpose; when one model serves several purposes, run the check once per purpose. Each finding and obligation in the result names the article behind it and links to the consolidated text on EUR-Lex. Not legal advice. Your answers are not saved or sent; site analytics counts only the risk tier and role each result shows.

How the checker decides

The AI Act attaches duties to what a system is used for and to your place in its supply chain, not to the model or vendor behind it. The checker asks its questions in the order the Act applies them:

  1. Definition. Article 3(1) covers machine-based systems that infer from their input how to generate predictions, content, recommendations or decisions. The Commission’s 2025 definition guidelines leave out basic data processing, classical heuristics, mathematical optimisation and simple prediction rules.
  2. Exclusions. Article 2 sets aside exclusively military, defence and national-security uses, systems built only for scientific research, pre-market development and testing, and purely personal use. Open-source systems are excluded too, unless they are high-risk, prohibited or caught by Article 50.
  3. Role and reach. Providers carry most of the duties, deployers the operational ones, and importers and distributors the supply-chain checks. Providers outside the EU are covered when they place systems on the EU market or when the output is used there.
  4. Prohibitions. Article 5 lists practices that no safeguard makes lawful. Eight have applied since 2 February 2025, and the Digital Omnibus added two, on intimate imagery and child sexual abuse material, from 2 December 2026.
  5. High-risk. Article 6(1) catches AI that is, or is a safety component of, an Annex I product needing third-party conformity assessment. Article 6(2) adds the eight Annex III areas, unless one of four Article 6(3) conditions applies, and a system that profiles people never qualifies for that exemption.
  6. Transparency. Article 50 applies on top of any risk class: chatbots must say they are AI, generated content must be machine-readably marked, and deployers must disclose emotion recognition, deepfakes and AI-written text on matters of public interest.
  7. General-purpose models. Chapter V binds the providers of the models themselves, with extra duties once training compute passes the 10²⁵ FLOP presumption of systemic risk in Article 51.

The results stack. A recruiting assistant can be high-risk under Annex III and a chatbot under Article 50 at the same time, and every provider and deployer in scope also owes AI literacy measures under Article 4. Record each result: our AI risk assessment template has a section for the classification and its reasoning, and the compliance roadmap sequences the work from inventory to impact assessment.

EU AI Act dates after the Digital Omnibus

Regulation (EU) 2026/1744 is dated 8 July 2026, was published in the Official Journal on 24 July and has been in force since 27 July. It pushed back the high-risk dates and added two bans, but left the Article 50 start date where it was. Each row links to the provision that sets the date.

Application dates of the AI Act, as amended in 2026
DateWhat appliesLegal basis
1 August 2024 The AI Act enters into force, twenty days after it appeared in the Official Journal on 12 July 2024. Art. 113
2 February 2025 Chapters I and II start to apply: the definitions, the AI literacy duty in Article 4 and the eight Article 5 prohibitions. Art. 113(a)
2 August 2025 Duties for providers of general-purpose AI models apply, with the governance and penalty chapters; the Commission’s fines on model providers wait for August 2026. Art. 113(b)
27 July 2026 The Digital Omnibus on AI, Regulation (EU) 2026/1744, enters into force three days after its publication on 24 July 2026. Reg. 2026/1744, Art. 4
2 August 2026 General date of application: the Article 50 transparency duties take effect and Article 101 fines on model providers become possible. Art. 113; Art. 101
2 December 2026 Two added bans take effect, on non-consensual intimate imagery and child sexual abuse material, and generative systems placed on the market before 2 August 2026 must mark their output. Art. 113(a); Art. 111(4)
2 August 2027 General-purpose models placed on the market before 2 August 2025 must meet the model provider duties. Art. 111(3)
2 December 2027 High-risk obligations reach AI systems intended for the eight Annex III areas, from hiring and credit scoring to education and border control. Art. 113(c)(i)
2 August 2028 High-risk obligations reach AI that is, or is a safety component of, a product under Annex I that needs third-party conformity assessment. Art. 113(c)(ii)
2 August 2030 High-risk systems intended for use by public authorities that were already on the market must comply, even without a design change. Art. 111(2)

A high-risk system already placed on the market or put into service before its Chapter III date falls under the rules only after a significant change to its design (Article 111(2)), and the Omnibus recitals judge that by type and model rather than by unit. Our deployer readiness timeline sets each phase against the controls it calls for.

Who owes what: obligations by role

The same system can leave very different work for each organisation around it. This is the short version of the checklists the checker prints; a result adds the conditions, the dates and a reference for every line.

Main AI Act duties by role and situation
WhoMain dutiesArticles
Provider of a high-risk system Build in the Articles 9 to 15 requirements, run a quality management system, pass conformity assessment, affix the CE marking, register Annex III systems, monitor after release and report serious incidents 16 to 22, 43 to 49, 72, 73
Deployer of a high-risk system Use it as instructed, assign human oversight, check the input data you control, monitor it, keep logs for at least six months and tell workers; public bodies, public-service providers and credit or life and health insurance deployers also assess fundamental-rights impact 26, 27, 86
Importer or distributor of a high-risk system Check the conformity documents and CE marking before supply, hold back non-conforming systems and cooperate with authorities; importers keep the papers for ten years 23, 24
Provider or deployer of any AI system in scope Take measures to support the AI literacy of the people who run and use it 4
Provider of a chatbot or generative system Tell people they are dealing with AI unless that is obvious, and mark generated output in a machine-readable way 50(1), 50(2)
Deployer of emotion recognition, deepfakes or public-interest text Inform the people exposed, and disclose that the content was generated or manipulated 50(3), 50(4)
Provider of a general-purpose AI model Document the model, inform downstream providers, adopt a copyright policy and publish a training-content summary; systemic-risk models add evaluation, risk mitigation, incident reports and cybersecurity 53 to 55

Roles can change hands. A distributor, importer, deployer or other third party becomes the provider of a high-risk system by putting its name on it, modifying it substantially, or repurposing a system that was not high-risk, general-purpose ones included, for a high-risk use (Article 25(1)). Sector guides go further for hiring and workforce tools, credit and insurance models, medical devices and chatbots and agents, and the Article 5 guide walks through each ban.

What the checker leaves out

  • Other law. The GDPR, including impact assessments and the rules on automated decisions, sector regimes such as the MDR or DORA, and national labour law all apply alongside the Act, and Article 2(11) lets Member States protect workers more strongly.
  • Guidance still being written. The Commission’s Article 6 guidelines, with worked examples of high-risk and exempt systems, were still a consultation draft in October 2026, published on 19 May 2026.
  • Facts only you hold. Whether a system materially influences decisions, whether a product needs a notified body, and whether a law-enforcement exception applies all turn on details a questionnaire cannot see.
  • Changes over time. Classification follows the intended purpose, so a new use, data source or user group calls for a fresh check.

For a second opinion, the Commission’s AI Act Service Desk runs its own beta checker and takes questions. Keep each outcome in an AI system register so the reasoning survives staff changes and audits.

How VDF AI fits

VDF AI runs assistants and agents on infrastructure you control, whether on-premises, in a private cloud or air-gapped, and VDF AI Agents keeps an audit log of every execution from input through retrieval and tool calls to the model’s response. Its risk classification agent maps each system in your inventory to the Act’s tiers and Annex III categories with a rationale that cites the provisions, and the EU AI Act agents hub adds agents for technical documentation, record-keeping, transparency notices and literacy training. The decision on each system stays with your legal and compliance team.

EU AI Act checker questions

How do I know if my AI system is high-risk under the EU AI Act?

There are two routes. Under Article 6(1), AI that is a product, or a safety component of a product, covered by the laws in Annex I is high-risk when that product needs third-party conformity assessment, such as a medical device that needs a notified body under the MDR. Under Article 6(2), AI intended for a use listed in Annex III, such as recruitment, credit scoring or exam proctoring, is high-risk unless an Article 6(3) condition applies, and a system that profiles people never qualifies for that exemption. The Annex III duties apply from 2 December 2027 and the Annex I duties from 2 August 2028.

Does the EU AI Act apply to companies outside the EU?

Yes. Article 2(1) covers providers that place AI systems or general-purpose models on the EU market wherever they are established, and providers and deployers outside the EU whose system output is used in the EU. Importers and distributors that bring systems onto the EU market are covered as well. A provider based outside the EU must appoint an authorised representative in the EU before supplying a high-risk system or a general-purpose model, unless the model is released as free and open-source software and carries no systemic risk.

When do EU AI Act obligations apply after the Digital Omnibus?

Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved only some dates. The Article 5 bans and the AI literacy duty have applied since 2 February 2025, the duties of general-purpose model providers since 2 August 2025 and the Article 50 transparency duties since 2 August 2026. Two new bans and the end of a marking grace period follow on 2 December 2026. High-risk duties start on 2 December 2027 for Annex III systems and on 2 August 2028 for AI in Annex I products.

What are the four risk levels of the EU AI Act?

The Act is usually summarised in four levels. Unacceptable-risk practices are banned outright by Article 5. High-risk systems, defined in Article 6 with Annexes I and III, carry the heaviest duties, from risk management and logging to human oversight and conformity assessment. Systems that talk to people or generate content carry the Article 50 transparency duties, often called limited risk, and everything else is minimal risk, where AI literacy is the remaining duty. The levels overlap: a recruiting chatbot can be high-risk and covered by Article 50 at once.

Is a chatbot high-risk under the EU AI Act?

Usually not. A customer service or internal help-desk chatbot is not listed in Annex III, so it is not high-risk, but since 2 August 2026 Article 50(1) requires that people are told they are talking to an AI system unless that is obvious. It becomes high-risk when it is used for an Annex III purpose, for example screening job applicants or assessing a customer’s creditworthiness. Under Article 25(1)(c), whoever repurposes a general-purpose chatbot that way takes on the provider’s high-risk obligations.

Is there an official EU AI Act compliance checker?

Yes. The European Commission’s AI Act Service Desk runs a compliance checker, labelled beta in October 2026, alongside a form for sending questions to its experts, who work with the AI Office. Neither that tool nor this one is legally binding: national market surveillance authorities apply the Act, and only the Court of Justice can interpret it authoritatively. Use a checker to triage your AI inventory and find the articles that matter, then record each classification and have your legal or compliance team confirm it.