Legal & Compliance · EU AI Act
EU AI Act compliance checker and AI system inventory
Answer four questions about one AI system and see which part of the AI Act most likely applies, with the articles to read next. The check runs in this page. Nothing you click is sent or stored.
To record many systems for your reviewers, upload your system list and your governance checklist. You get a review workbook with quoted evidence, open questions and owner tasks.
- Free check
- 4 questions · indicative tier with article references
- Review workbook
- 2 AI credits per run · free account needed
Which AI Act tier fits this system?
Pick one system and answer for it. Not sure is a valid answer.
Answer the questions to see an indicative tier. If you answer Yes to question 2, the other answers no longer change the result.
Indicative tier: prohibited practice
Art. 5 bans placing such a system on the EU market, putting it into service and using it. The exceptions are narrow; most concern real-time remote biometric identification by law enforcement under Art. 5(2) to (7). Take this system to legal counsel before any further use.
Open question: Article 5
Settle this first. If a banned practice is involved, the other answers do not matter. Read Art. 5(1)(a) to (h) against the intended use and the way the system is actually used.
Indicative tier: high-risk
Art. 6(1) covers safety components of Annex I products, Art. 6(2) the Annex III areas. An Annex III system can fall outside high-risk under Art. 6(3) if it poses no significant risk, for example because it only performs a narrow procedural task. That exception never applies when the system profiles people, and the provider must document the assessment (Art. 6(4)).
What your role usually has to do
- Provider: meet the requirements in Art. 8 to 15 (risk management, data governance, technical documentation, logging, instructions for deployers, human oversight, accuracy and robustness), run a quality management system (Art. 17), pass conformity assessment (Art. 43) and register in the EU database (Art. 49). Art. 16 lists all provider duties.
- Deployer: use the system according to its instructions, assign trained people for human oversight, monitor it, keep the logs it generates and inform workers and affected persons where required (Art. 26). Public bodies and some other deployers must also carry out a fundamental rights impact assessment (Art. 27).
- Importer or distributor: before the system reaches the market, check the CE marking, the EU declaration of conformity and the instructions (Art. 23 for importers, Art. 24 for distributors).
- Role unclear: under Art. 25 a distributor, importer or deployer becomes a provider when it puts its own name on the system, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk.
Your answer to question 4 means the Art. 50 transparency duties apply on top.
Open question: Article 6 and Annex III
Compare the intended use with the eight Annex III areas and check whether the system is part of a product under an Annex I law. Art. 6(5) asks the Commission for guidelines with practical examples of high-risk and non-high-risk use. Until this is settled, keep the system on your review list.
Indicative tier: transparency obligations
Art. 50 applies. The duties depend on your role.
- Provider: design the system so people know they are dealing with an AI system, unless that is obvious (Art. 50(1)), and mark generated audio, image, video or text in a machine-readable way (Art. 50(2)).
- Deployer: tell people when they are exposed to emotion recognition or biometric categorisation (Art. 50(3)), and disclose deepfakes and generated text published to inform the public on matters of public interest (Art. 50(4)).
- Importer or distributor: Art. 50 is addressed to providers and deployers. Check that the provider's documentation covers it.
- Role unclear: settle the role first, because Art. 50(1) and (2) bind providers while Art. 50(3) and (4) bind deployers.
Open question: Article 50
Look at how people meet the system. If they talk to it, see content it generated, or are analysed for emotions or biometric categories, Art. 50 applies. If none of this happens, the system most likely sits in the minimal-risk group.
Indicative tier: minimal risk
The Act sets no tier-specific requirements for this system. Art. 4 still asks providers and deployers to ensure sufficient AI literacy among their staff, and voluntary codes of conduct are possible under Art. 95. Write down why you reached this result, because the tier can change when the intended use changes.
Indicative only, based on your four answers. Not legal advice. General-purpose AI models (Art. 51 to 56) are not covered. Source: Regulation (EU) 2024/1689.
Next step: record this system and the rest of your list in a review workbook
Next step for many systems
Build a review workbook from your own documents
The workbook lists each system with its intended use and your role, maps your governance checklist to quoted evidence, and turns every missing fact into an open question with an owner task. It does not assign a risk tier. Your reviewers make that call, and the free check above can help them start.
or drop it here
This run: 2 AI credits (€0.47 to €0.70 from a credit pack) · free account needed · cost shown before you start
- Encrypted source, result kept for 24 hours
- Larger lists go through in batches of 30 rows
- Credit packs from €6.99; Pro includes 40 credits a month
One system, two checklist questions, role set to Deployer
System: Helpdesk Draft Assistant. Intended use: drafts replies for agent review. Operator: support team. Final send requires a human click.Governance checklist
Question: Is human review documented? Question: Is provider documentation retained?
ai-system-inventory.csv
| system | intended_use | provider_or_deployer | source_quote |
|---|---|---|---|
| Helpdesk Draft Assistant | drafts replies for agent review | Deployer | “Intended use: drafts replies for agent review.” |
evidence-map.csv
| question | answer | source_quote |
|---|---|---|
| Is human review documented? | Yes, a person sends each reply | “Final send requires a human click.” |
open-questions.csv
| question | reason |
|---|---|
| Is provider documentation retained? | The source does not mention provider documentation. |
review-tasks.csv
| task | owner | status |
|---|---|---|
| Collect the provider documentation | support team | open |
File and column names match the download. Every source_quote must appear word for word in your files, and a quote that cannot be found is rejected before it reaches the workbook.
How the four answers lead to a tier
- Article 5 first. A banned practice ends the check: the system may not be placed on the market or used.
- Then Article 6. An Annex III area or an Annex I product points to high-risk, unless the documented Art. 6(3) exception applies.
- Then Article 50. Systems that talk to people, generate content, read emotions or make deepfakes carry transparency duties. High-risk systems can have these duties as well.
- Otherwise minimal risk. No tier-specific requirements, but AI literacy under Art. 4 still applies.
Your role (question 1) decides which duties are yours: Art. 16 for providers, Art. 26 for deployers, Art. 23 and 24 for importers and distributors.
From upload to download
- 1
Add your system list
CSV, XLSX, PDF or DOCX with up to 30 rows. The file stays in this browser until the workspace opens.
- 2
Add the checklist and pick your role
Add your AI governance checklist and choose provider, deployer, importer or distributor, or Unsure.
- 3
Check the preview, then download
Look at the preview and warnings. The download uses 2 AI credits.
What the workbook does and what stays with you
Facts stay as your documents state them
If your file says a final send needs a human click, the workbook quotes that line with its source. It does not turn it into an assessment. Before you pass the pack on, compare the quoted facts with the file you supplied.
Your checklist, not a generic template
The governance checklist is a required second file. Your systems are mapped against the questions your organization already asks. A fact that is missing becomes an open question rather than a guess.
The role setting
Primary role records if you act as provider, deployer, importer or distributor. Unsure is a valid answer. The role shapes which questions the workbook raises. It does not settle your legal position, and the workbook gives no risk class and makes no compliance claim. Scope, risk class and compliance decisions stay with your legal or governance reviewers.
Questions before you run it
Will it tell me if my system is high risk under the AI Act?
The free four-question check on this page gives an indicative tier and the articles to read, based only on your answers. The review workbook does not classify. Risk classification and legal scope are decisions for your reviewers; the workbook organizes what you supplied and lists the questions still open.
Is the four-question check legal advice?
No. It follows the order of the Regulation (Article 5, then Article 6 with Annexes I and III, then Article 50) and shows where to read next. It does not cover general-purpose AI models (Articles 51 to 56) and does not replace a review of the full text of Regulation (EU) 2024/1689.
What does the primary role setting change?
It records whether you are acting as provider, deployer, importer or distributor, and Unsure is a valid answer. The role shapes which questions the workbook surfaces; it does not settle your legal position.
Do I have to supply a governance checklist?
Yes, it is a required second file. Your systems are mapped against your own organization checklist rather than a generic template. You add it in the workspace after choosing the system list.
How many systems can I inventory in one run?
Up to 30 rows per job from CSV, XLSX, PDF or DOCX, with a 64,000 character extraction ceiling. Larger estates go through in batches.
How does it handle human oversight claims?
It records the oversight step as your documentation states it, for instance that a final send requires a human click, and keeps it as a quoted fact with its source rather than as an assessment.