Role and risk class, triaged.
Answer the questions chapter 18 asks, in its order: definition, reach, role, prohibited practices, high-risk, transparency and the GPAI track. You get indicative roles and classes with the reason behind each answer, and a classification decision record to file. Not a verdict: counsel confirms the reading.
Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.
JavaScript is off or has not loaded, so the live result, the link state and the record exports are not available. The questions, the criteria and the guide below still work as a worksheet you can read and fill in by hand.
Built from 18. The EU AI Act in one pass of the Body of Knowledge. Runs entirely in this page: no account and no upload.
One task from the everyday practice of AI governance, defined and compared.
Indicative triage
Scope
Roles
Risk ladder and GPAI track
If it were in scope
Open points
What follows
Next: the obligations
| Question | Answer | Article | What it means |
|---|
An engineer's reading, not legal advice and not a conformity claim. The engineer builds the control and the evidence; counsel confirms that the obligation was read correctly [1].
Re-open a record
A record exported by this tool. It is read in this browser; the outcome is recomputed from its answers, never read from the file.
How the triage works
The chapter reads the Act as four ideas: a definition gate, a risk ladder, a set of operator roles and a timeline [1]. The triage asks them in that order, and skips what your earlier answers rule out.
- What you are triaging. The Act regulates two objects: AI systems, ranked by intended purpose, and general-purpose AI models, on a separate track.
- Reach and exclusions. Whether the Act reaches it at all: by placement, by use in the Union or by output used in the Union, less the narrow exclusions.
- Your role. Roles name tasks, not organisations: one organisation can be provider and deployer of the same system.
- Prohibited practices. Article 5 is a list of banned uses, not a risk assessment.
- High-risk. Two routes: a safety component of an Annex I product, or an Annex III use not filtered out by Art. 6(3).
- Transparency. Article 50 applies to any AI system that fits one of its cases, whatever else the system is.
- General-purpose AI models. The model track: generality, the systemic-risk presumption and the open-source carve-out.
How to read the result
- Indicative, never a verdict. The result names the roles and classes your answers imply, with the reason and the article behind each. It never declares conformity: that is a claim about evidence, not about answers.
- Roles are per system. A role attaches to an activity on a specific
system, not to a company: an in-house system is often
["provider", "deployer"][1]. - Classes stack. One system can sit on two rungs at once: an Annex III chatbot carries both the high-risk duties and the Art. 50 disclosure duty. A system built on your own GPAI model has the model track as well.
- Out of scope assigns nothing. When the definition, reach or an exclusion takes it out, the result shows what the other answers would give, so you know what to plan for if the facts change.
- Open points are the work. A "not sure" answer never disappears: it becomes an open point in the record until someone settles it.
The rules, written out
Without JavaScript, answer the questions above and read the outcome off these rules. They are the same data the live result runs on (question set 1.0.0).
Scope
In scope unless one of these holds (a "not settled" rule keeps the triage going):
- Out of scope when the system only applies rules defined solely by natural persons. Not an AI system on the definition screen: the Commission guidelines exclude systems based on rules defined solely by natural persons. The guidelines are not binding, so record the element that fails and the reasoning. ( Art. 3(1))
- Out of scope when you triage a model alone and it is not a GPAI model. A model that is not a GPAI model carries no model-level duties, and a model is not an AI system on its own. ( Art. 3(63))
- Out of scope when you triage a model alone and it is still in research, development or prototyping. A model used for research, development or prototyping before it is placed on the market is outside the GPAI model definition. ( Art. 3(63))
- Out of scope when none of the Art. 2(1) links holds. No placement on the EU market, no deployer in the Union and no output used in the Union: Art. 2(1) does not reach it on these answers. ( Art. 2(1))
- Out of scope when the military, defence or national security exclusion is claimed. Used exclusively for military, defence or national security purposes. A dual-use system is in scope for its other uses. ( Art. 2(3))
- Out of scope when the third-country authority exclusion is claimed. A third-country public authority or international organisation in law-enforcement or judicial cooperation, with adequate safeguards for fundamental rights. ( Art. 2(4))
- Out of scope when the scientific research exclusion is claimed. Specifically developed and put into service for the sole purpose of scientific research and development. ( Art. 2(6))
- Out of scope when the pre-market research and testing exclusion is claimed. Research, testing or development before placing on the market or putting into service. Testing in real-world conditions is not covered by the exclusion. ( Art. 2(8))
- Out of scope when the open-source exclusion is claimed and no system rung other than minimal applies. An AI system released under a free and open-source licence that is not high-risk and not caught by Art. 5 or Art. 50. ( Art. 2(12))
- Out of scope when only purely personal, non-professional use by a natural person. A natural person’s purely personal, non-professional use: Art. 2(10) removes the deployer obligations. ( Art. 2(10))
- Not settled when the inference answer is "one of the four families" or "not sure". The Art. 3(1) definition is not settled. Scope is a recorded decision, not an assumption: the triage carries on as if it were an AI system. ( Art. 3(1))
Classes
- Prohibited practice (Art. 5) when:
- You ticked point (a), (b), (c) or (e) of Art. 5. A practice on the Art. 5 list with no carve-out. It may not be placed on the market, put into service or used, and no mitigation makes it lawful. Applies from 2025-02-02.
- You ticked point (d), (f), (g) or (h) of Art. 5 and did not confirm its carve-out. A practice on the Art. 5 list whose narrow carve-out is not confirmed. Outside the carve-out, no mitigation makes it lawful. Applies from 2025-02-02.
- Such output is the generator’s intended purpose or use, or a foreseeable outcome without reasonable and adequate safeguards. One of the two practices the Omnibus added (intimate imagery without consent, child sexual abuse material): prohibited from 2026-12-02. Applies from 2026-12-02.
- High-risk (Annex I) (Art. 6(1)) when:
- Annex I product, the system is the product or a safety component, and a third-party assessment is required for health and safety. Both Art. 6(1) conditions hold: a safety component of an Annex I product, or the product itself, that must undergo a third-party conformity assessment. The Annex I route applies from 2028-08-02. Applies from 2028-08-02.
- High-risk (Annex III) (Art. 6(2)) when:
- An Annex III area is ticked and the system profiles natural persons. An Annex III system that profiles natural persons is always high-risk: the override beats all four Art. 6(3) conditions. Applies from 2027-12-02.
- An Annex III area is ticked and no Art. 6(3) condition is claimed. An Annex III use with no Art. 6(3) condition claimed: high-risk. Applies from 2027-12-02.
- An Annex III area is ticked and the profiling answer is "not sure". An Annex III use whose profiling flag is not settled: the filter is not applied until it is. Applies from 2027-12-02.
- Transparency (Art. 50) (Art. 50) when:
- You ticked at least one Article 50 case. Fits an Article 50 case, whatever else the system is. The information must reach people at the latest at first interaction or exposure; the article has applied since 2026-08-02. Applies from 2026-08-02.
- Minimal risk (Arts. 4, 95) when:
- An AI system on no other rung. Everything else is minimal risk: nothing specific beyond AI literacy (Art. 4), and voluntary codes of conduct (Art. 95). Minimal is a legal category, not a risk verdict: data protection, consumer, product-liability and anti-discrimination law still apply. Applies from 2025-02-02.
- GPAI model (Arts. 51 to 56) when:
- The model is a GPAI model, or meets the guidelines’ indicative criterion. A general-purpose AI model. GPAI obligations have applied since 2025-08-02 and Commission fines under Art. 101 since 2026-08-02; models placed on the market before 2025-08-02 must comply by 2027-08-02. Applies from 2025-08-02.
- GPAI model with systemic risk (Arts. 51, 52, 55) when:
- Cumulative training compute above 10^25 FLOP. Presumed to have high-impact capabilities above 10^25 FLOP of cumulative training compute. Notify the Commission within two weeks; the provider may argue that the model exceptionally presents no systemic risk. Applies from 2025-08-02.
- The Commission designated the model. Designated by the Commission on the Annex XIII criteria. Applies from 2025-08-02.
- Planned training will cross 10^25 FLOP. Planned training will cross 10^25 FLOP: the presumption applies once it does, and the two-week notification clock can start before training ends.
Roles
- Provider (Art. 3(3)) when:
- You develop the AI system, or have it developed, under your own name. You develop the system, or have it developed, and place it on the market or put it into service under your own name. Putting into service includes own use.
- You integrate an AI model into the system. A downstream provider carries the provider duties for the system it builds.
- You ticked an Art. 25(1) trigger and the system is high-risk. An Art. 25(1) trigger on a high-risk system makes you its provider, with all of the Art. 16 duties.
- Downstream provider (Art. 3(68)) when:
- You integrate an AI model into the system. You integrate an AI model, your own or a third party’s, into the AI system.
- Deployer (Art. 3(4)) when:
- You use the AI system in a professional activity. You use the AI system under your authority, other than for personal, non-professional use.
- Importer (Art. 3(6)) when:
- You import the system. EU-based, you place on the market a system bearing a non-EU provider’s name.
- Distributor (Art. 3(7)) when:
- You distribute the system. You make the system available without being its provider or importer.
- Authorised representative (Art. 3(5)) when:
- You act as authorised representative. EU-based, you act under a written mandate from a non-EU provider.
- Product manufacturer (Art. 25(3)) when:
- You place it with your own Annex I, Section A product, and it is high-risk through Annex I. You place a high-risk safety component with your Annex I, Section A product under your own name: the provider duties of Art. 16 are yours.
- General-purpose AI model provider (Art. 53) when:
- You develop a GPAI model, or modified one above the indicative criterion. You are the provider of a general-purpose AI model: Arts. 53 to 55 apply to you.
The classification decision record
The chapter asks for a classification decision record for every Annex III candidate, with the Art. 6(3) condition relied on and the profiling flag stated explicitly, filed in the registry and re-evaluated whenever the intended purpose changes [1]. The record lives in Layer 2 (Inventory & Transparency); the rule that computes it lives in Layer 1. The exported record carries the question-set version, every answer with its article and meaning, the outcome with its reasons, the reviewer, the date, the legal-review state and the re-review triggers.
- JSON Schema (draft 2020-12)
- Filled example (a CV screening system under Annex III, point 4)
- Human template (the same fields as a document)
- The whole library: templates and schemas
The JSON export re-opens here: import it above and the outcome is recomputed from its answers with the question set this page runs. A record made with another version loads the answers that still exist and says what it dropped.
Hand-off to the obligations planner
The result opens the obligations planner with the roles and classes it found, in the part of
the link after #, which the browser keeps to itself. The planner reads role
codes (r), class codes (c) and a reference date (d,
the decision date); the triage adds from and qs so the plan can say
where its answers came from:
/toolkit/obligations-planner#v=1&r=pr.de&c=h3&d=2026-09-24&from=ai-act-triage&qs=1.0.0 -
pr: Provider -
pr: Downstream provider -
pr: Product manufacturer -
de: Deployer -
im: Importer -
di: Distributor -
ar: Authorised representative -
gp: General-purpose AI model provider -
gs: a general-purpose AI model provider whose model has systemic risk -
h3: High-risk (Annex III) -
h1: High-risk (Annex I) -
tr: Transparency (Art. 50)
The planner adds the duties every AI system carries (AI literacy and the Art. 5 screen) by itself. Out of scope, there is nothing to hand off. Until the planner is published, the obligation register lists every EU AI Act duty with its holder and the classes it applies to.
What this is not
It is an engineer's reading of the Act, not legal advice, not a conformity assessment and not a certification. The Commission's classification guidelines were still a draft as of 2026-09-24 [7], and until they are final the defence is a good record, not a good argument. The definition and GPAI guidelines it relies on are not binding [5][6]. The tool asserts only what chapter 18 states; mappings are illustrative, not a claim of conformity.
Question set and versioning
Question set aige.eu-ai-act-triage version 1.0.0, as of
2026-09-24. A change to a rule, a question's meaning or an option value is a major
version; a new question or option is a minor one; a wording fix is a patch. Question ids and
option values stay stable within a major version, because saved records and copied links carry
them. The graph has 20 questions in 7 steps.
Sources
- [1] 18. The EU AI Act in one pass: every question, option, rule, reason and date this tool shows, and the illustrative classification decision record it extends. AI Governance Engineering Body of Knowledge. 2026-09-24. https://aigovernanceengineer.com/bok/eu-ai-act (verified: primary)
- [2] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 Jul 2026 incorporating Regulation (EU) 2026/1744: Arts. 2, 3, 5, 6, 25, 50 to 53 and Annexes I and III, the anchors each question links to. Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
- [3] Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), original text; OJ L, 2024/1689, 12.7.2024. Publications Office of the EU (EUR-Lex). 2024-07-12. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (verified: primary)
- [4] Regulation (EU) 2026/1744 (Digital Omnibus on AI) of 8 Jul 2026: new Art. 5(1)(ba), (bb), (1a), (1b); Art. 3(14) and Art. 6(1a) to (1c); Art. 2(2) and 2(13); Art. 25(2); Art. 111(4); Art. 113 dates; OJ L, 2026/1744, 24.7.2026, in force on the third day after publication. Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)
- [5] Commission Guidelines on the definition of an artificial intelligence system (seven elements; four families that may fall outside; non-binding), as cited in chapter 18. European Commission. 2025-02-06. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application (verified: primary)
- [6] Commission Guidelines on the scope of the obligations for providers of general-purpose AI models (C(2025) 7719 final; 10^23 FLOP indicative criterion; one-third modification criterion; monetisation), as cited in chapter 18. European Commission. 2025-11-19. https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act (verified: primary)
- [7] Draft Commission guidelines on the classification of high-risk AI systems (Art. 6; still a draft as of 2026-09-24), as cited in chapter 18. European Commission. 2026-05-19. https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems (verified: primary)