WoluTools

Legal & Compliance · EU AI Act

EU AI Act compliance checker and AI system inventory

Answer four questions about one AI system and see which part of the AI Act most likely applies, with the articles to read next. The check runs in this page. Nothing you click is sent or stored.

To record many systems for your reviewers, upload your system list and your governance checklist. You get a review workbook with quoted evidence, open questions and owner tasks.

Free check
4 questions · indicative tier with article references
Review workbook
2 AI credits per run · free account needed
Free check · 4 questions

Which AI Act tier fits this system?

Pick one system and answer for it. Not sure is a valid answer.

1What is your role for this system?
Which role is mine?

Provider: you develop the system, or have it developed, and place it on the market or put it into service under your own name (Art. 3(3)). Deployer: you use it under your authority in a professional context (Art. 3(4)). Importer: you bring a system from a non-EU provider onto the EU market. Distributor: you make it available further down the supply chain.

2Does it use a practice banned by Article 5?
Banned practices, Art. 5(1)(a) to (h)
  • Subliminal, manipulative or deceptive techniques that distort behaviour and cause significant harm
  • Exploiting vulnerabilities due to age, disability or a social or economic situation
  • Social scoring that leads to unjustified or unrelated detrimental treatment
  • Predicting that a person will commit a crime based solely on profiling or personality traits
  • Building facial recognition databases by untargeted scraping of images from the internet or CCTV
  • Emotion recognition at work or in education, except for medical or safety reasons
  • Biometric categorisation to infer race, political opinions, trade union membership, religion, sex life or sexual orientation
  • Real-time remote biometric identification in publicly accessible spaces for law enforcement, outside narrow exceptions
3Is it used in an Annex III area, or is it a safety component of a product covered by Annex I?
Annex III areas and Annex I products
  • Biometrics, such as remote identification or emotion recognition
  • Critical infrastructure, such as safety components for road traffic, water, gas, heating or electricity
  • Education and vocational training: admission, assessment, exam monitoring
  • Employment: recruitment, promotion, termination, task allocation, performance monitoring
  • Essential private and public services: public benefits, creditworthiness, life and health insurance pricing, emergency call triage
  • Law enforcement
  • Migration, asylum and border control
  • Administration of justice and democratic processes, including influencing elections

Annex I lists EU product laws, for example machinery, toys, lifts, radio equipment and medical devices. A system counts under Art. 6(1) when it is a safety component of such a product, or the product itself, and a third-party conformity assessment is required.

4Does it talk to people, generate content, read emotions or create deepfakes?
Cases covered by Art. 50
  • People interact with it directly, for example a chatbot or voice assistant
  • It generates or alters images, audio, video or text
  • It recognises emotions or sorts people into categories from biometric data
  • It produces deepfakes, or text published to inform the public on matters of public interest

Answer the questions to see an indicative tier. If you answer Yes to question 2, the other answers no longer change the result.

Indicative tier: prohibited practice

Art. 5 bans placing such a system on the EU market, putting it into service and using it. The exceptions are narrow; most concern real-time remote biometric identification by law enforcement under Art. 5(2) to (7). Take this system to legal counsel before any further use.

Open question: Article 5

Settle this first. If a banned practice is involved, the other answers do not matter. Read Art. 5(1)(a) to (h) against the intended use and the way the system is actually used.

Indicative tier: high-risk

Art. 6(1) covers safety components of Annex I products, Art. 6(2) the Annex III areas. An Annex III system can fall outside high-risk under Art. 6(3) if it poses no significant risk, for example because it only performs a narrow procedural task. That exception never applies when the system profiles people, and the provider must document the assessment (Art. 6(4)).

What your role usually has to do

  • Provider: meet the requirements in Art. 8 to 15 (risk management, data governance, technical documentation, logging, instructions for deployers, human oversight, accuracy and robustness), run a quality management system (Art. 17), pass conformity assessment (Art. 43) and register in the EU database (Art. 49). Art. 16 lists all provider duties.
  • Deployer: use the system according to its instructions, assign trained people for human oversight, monitor it, keep the logs it generates and inform workers and affected persons where required (Art. 26). Public bodies and some other deployers must also carry out a fundamental rights impact assessment (Art. 27).
  • Importer or distributor: before the system reaches the market, check the CE marking, the EU declaration of conformity and the instructions (Art. 23 for importers, Art. 24 for distributors).
  • Role unclear: under Art. 25 a distributor, importer or deployer becomes a provider when it puts its own name on the system, makes a substantial modification, or changes the intended purpose so that the system becomes high-risk.

Your answer to question 4 means the Art. 50 transparency duties apply on top.

Open question: Article 6 and Annex III

Compare the intended use with the eight Annex III areas and check whether the system is part of a product under an Annex I law. Art. 6(5) asks the Commission for guidelines with practical examples of high-risk and non-high-risk use. Until this is settled, keep the system on your review list.

Indicative tier: transparency obligations

Art. 50 applies. The duties depend on your role.

  • Provider: design the system so people know they are dealing with an AI system, unless that is obvious (Art. 50(1)), and mark generated audio, image, video or text in a machine-readable way (Art. 50(2)).
  • Deployer: tell people when they are exposed to emotion recognition or biometric categorisation (Art. 50(3)), and disclose deepfakes and generated text published to inform the public on matters of public interest (Art. 50(4)).
  • Importer or distributor: Art. 50 is addressed to providers and deployers. Check that the provider's documentation covers it.
  • Role unclear: settle the role first, because Art. 50(1) and (2) bind providers while Art. 50(3) and (4) bind deployers.

Open question: Article 50

Look at how people meet the system. If they talk to it, see content it generated, or are analysed for emotions or biometric categories, Art. 50 applies. If none of this happens, the system most likely sits in the minimal-risk group.

Indicative tier: minimal risk

The Act sets no tier-specific requirements for this system. Art. 4 still asks providers and deployers to ensure sufficient AI literacy among their staff, and voluntary codes of conduct are possible under Art. 95. Write down why you reached this result, because the tier can change when the intended use changes.

Indicative only, based on your four answers. Not legal advice. General-purpose AI models (Art. 51 to 56) are not covered. Source: Regulation (EU) 2024/1689.

Next step: record this system and the rest of your list in a review workbook

Next step for many systems

Build a review workbook from your own documents

The workbook lists each system with its intended use and your role, maps your governance checklist to quoted evidence, and turns every missing fact into an open question with an owner task. It does not assign a risk tier. Your reviewers make that call, and the free check above can help them start.

or drop it here

You need 2 files: your system list (CSV, XLSX, PDF or DOCX, up to 30 rows, 64,000 extracted characters) and your AI governance checklist, which you add on the next screen.

No file at hand? See an excerpt of the result

This run: 2 AI credits (€0.47 to €0.70 from a credit pack) · free account needed · cost shown before you start

  • Encrypted source, result kept for 24 hours
  • Larger lists go through in batches of 30 rows
  • Credit packs from €6.99; Pro includes 40 credits a month
Result excerpt · fictional sample data

One system, two checklist questions, role set to Deployer

System list
System: Helpdesk Draft Assistant. Intended use: drafts replies for agent review. Operator: support team. Final send requires a human click.
Governance checklist
Question: Is human review documented?
Question: Is provider documentation retained?

ai-system-inventory.csv

systemintended_useprovider_or_deployersource_quote
Helpdesk Draft Assistantdrafts replies for agent reviewDeployer“Intended use: drafts replies for agent review.”

evidence-map.csv

questionanswersource_quote
Is human review documented?Yes, a person sends each reply“Final send requires a human click.”

open-questions.csv

questionreason
Is provider documentation retained?The source does not mention provider documentation.

review-tasks.csv

taskownerstatus
Collect the provider documentationsupport teamopen

File and column names match the download. Every source_quote must appear word for word in your files, and a quote that cannot be found is rejected before it reaches the workbook.

How the four answers lead to a tier

  1. Article 5 first. A banned practice ends the check: the system may not be placed on the market or used.
  2. Then Article 6. An Annex III area or an Annex I product points to high-risk, unless the documented Art. 6(3) exception applies.
  3. Then Article 50. Systems that talk to people, generate content, read emotions or make deepfakes carry transparency duties. High-risk systems can have these duties as well.
  4. Otherwise minimal risk. No tier-specific requirements, but AI literacy under Art. 4 still applies.

Your role (question 1) decides which duties are yours: Art. 16 for providers, Art. 26 for deployers, Art. 23 and 24 for importers and distributors.

From upload to download

  1. 1

    Add your system list

    CSV, XLSX, PDF or DOCX with up to 30 rows. The file stays in this browser until the workspace opens.

  2. 2

    Add the checklist and pick your role

    Add your AI governance checklist and choose provider, deployer, importer or distributor, or Unsure.

  3. 3

    Check the preview, then download

    Look at the preview and warnings. The download uses 2 AI credits.

What the workbook does and what stays with you

Facts stay as your documents state them

If your file says a final send needs a human click, the workbook quotes that line with its source. It does not turn it into an assessment. Before you pass the pack on, compare the quoted facts with the file you supplied.

Your checklist, not a generic template

The governance checklist is a required second file. Your systems are mapped against the questions your organization already asks. A fact that is missing becomes an open question rather than a guess.

The role setting

Primary role records if you act as provider, deployer, importer or distributor. Unsure is a valid answer. The role shapes which questions the workbook raises. It does not settle your legal position, and the workbook gives no risk class and makes no compliance claim. Scope, risk class and compliance decisions stay with your legal or governance reviewers.

Questions before you run it

Will it tell me if my system is high risk under the AI Act?

The free four-question check on this page gives an indicative tier and the articles to read, based only on your answers. The review workbook does not classify. Risk classification and legal scope are decisions for your reviewers; the workbook organizes what you supplied and lists the questions still open.

Is the four-question check legal advice?

No. It follows the order of the Regulation (Article 5, then Article 6 with Annexes I and III, then Article 50) and shows where to read next. It does not cover general-purpose AI models (Articles 51 to 56) and does not replace a review of the full text of Regulation (EU) 2024/1689.

What does the primary role setting change?

It records whether you are acting as provider, deployer, importer or distributor, and Unsure is a valid answer. The role shapes which questions the workbook surfaces; it does not settle your legal position.

Do I have to supply a governance checklist?

Yes, it is a required second file. Your systems are mapped against your own organization checklist rather than a generic template. You add it in the workspace after choosing the system list.

How many systems can I inventory in one run?

Up to 30 rows per job from CSV, XLSX, PDF or DOCX, with a 64,000 character extraction ceiling. Larger estates go through in batches.

How does it handle human oversight claims?

It records the oversight step as your documentation states it, for instance that a final send requires a human click, and keeps it as a quoted fact with its source rather than as an assessment.