Role and risk class, triaged.

Answer the questions chapter 18 asks, in its order: definition, reach, role, prohibited practices, high-risk, transparency and the GPAI track. You get indicative roles and classes with the reason behind each answer, and a classification decision record to file. Not a verdict: counsel confirms the reading.

Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.

JavaScript is off or has not loaded, so the live result, the link state and the record exports are not available. The questions, the criteria and the guide below still work as a worksheet you can read and fill in by hand.

Built from 18. The EU AI Act in one pass of the Body of Knowledge. Runs entirely in this page: no account and no upload.

Answer with the system as it is intended and used, not as it is marketed. Questions that do not apply to your earlier answers are skipped. Question set 1.0.0, as of 2026-09-24, read against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI) [2].

The system

The record is filed against one system or model and its intended purpose: re-run the triage whenever the purpose changes.

The id in your AI system register, so the record files next to the entry.

What it is used for, by whom and in which context. The classification follows the intended purpose, not the technology.

1 What you are triaging

The Act regulates two objects: AI systems, ranked by intended purpose, and general-purpose AI models, on a separate track.

What are you triaging?

A model is not an AI system on its own: it needs further components, such as a user interface, to become one. Choose one.

Rests on Art. 3(1), Art. 3(63) · chapter 18: What counts as an AI system

What each answer means
An AI system: software with an intended purpose that people or other systems use
The system track: the definition screen, then the risk ladder by intended purpose.
A model on its own, offered for integration into other systems
The model track: a model is not an AI system on its own, so only the GPAI questions apply.
Both: a model, and a system built on it
Both tracks: the system goes up the risk ladder and the model through the GPAI questions.
Does it infer, from the input it receives, how to generate outputs such as predictions, content, recommendations or decisions?

The Art. 3(1) definition has seven elements; the decisive one is inference. The Commission guidelines that read it are not binding. Choose one.

Rests on Art. 3(1) · chapter 18: What counts as an AI system · Ask when you triage an AI system (alone or with its model).

What each answer means
Yes: its outputs are inferred, for example by a trained model
It meets the decisive element of the Art. 3(1) definition: an AI system.
No: it only applies rules defined solely by natural persons
The Commission guidelines exclude systems based on rules defined solely by natural persons. Record ai_system: false, the element that fails and the reasoning.
It computes, but only as one of the four families the guidelines name: improving mathematical optimisation, basic data processing, classical heuristics or simple prediction
The guidelines name these families as ones that may still fall outside the definition. They are not binding, so the call is a recorded decision with its reasoning.
Not sure yet
Scope is a recorded decision, not an assumption. The triage carries on as if it were an AI system and lists the definition as an open point.

2 Reach and exclusions

Whether the Act reaches it at all: by placement, by use in the Union or by output used in the Union, less the narrow exclusions.

Where does it meet the EU?

Tick every link that holds. Where it is hosted is not the scope question; where its output is used is. Tick all that apply.

Rests on Art. 2(1) · chapter 18: Who is in scope

What each answer means
It is placed on the EU market or put into service in the EU, by us or by its provider
Art. 2(1) reaches providers placing AI systems or GPAI models on the EU market, wherever they are established.
We are established or located in the EU and use it
Art. 2(1) reaches deployers in the Union.
It runs outside the EU, but its output is used in the EU
Art. 2(1) reaches providers and deployers in third countries whose system's output is used in the Union: the reach is extraterritorial by output as well as by placement.
None of these
No placement on the EU market, no deployer in the Union and no output used in the Union: Art. 2(1) does not reach it on these answers.
Does one of the Act’s exclusions apply?

Each exclusion is narrow; the note on each option says how. Union data protection law applies alongside the Act in every case. Tick all that apply.

Rests on Art. 2(3) to 2(12) · chapter 18: What the Act excludes

What each answer means
Used exclusively for military, defence or national security purposes
Excluded (Art. 2(3)) only for those exclusive purposes: a dual-use system is in scope for its other uses.
Used by a third-country public authority or an international organisation in law-enforcement or judicial cooperation with the Union
Excluded (Art. 2(4)) only with adequate safeguards for fundamental rights.
Specifically developed and put into service for the sole purpose of scientific research and development
Excluded (Art. 2(6)): the system or model must be specifically developed and put into service for that purpose alone.
Still in research, testing or development, not yet placed on the market or put into service, and not tested in real-world conditions
Excluded for now (Art. 2(8)); testing in real-world conditions is not covered by the exclusion.
An AI system released under a free and open-source licence
Excluded (Art. 2(12)), but not if placed on the market as high-risk, or caught by Art. 5 or Art. 50: the triage checks those rungs before it applies the exclusion.
None of these
No exclusion claimed.

3 Your role

Roles name tasks, not organisations: one organisation can be provider and deployer of the same system.

What does your organisation do with it?

A role attaches to an activity on this system, not to your company. Tick every activity that holds. Tick all that apply.

Rests on Art. 3(3) to 3(8), Art. 3(68) · chapter 18: The EU operator roles

What each answer means
We develop it, or have it developed, and place it on the market or put it into service under our own name (own use counts)
Provider (Art. 3(3)): develops an AI system or GPAI model, or has one developed, and places it on the market or into service under its own name. Putting into service includes own use.
We integrate an AI model, our own or a third party’s, into the system
Downstream provider (Art. 3(68)): integrates an AI model into an AI system and carries the provider duties for the system.
We use it under our authority, in a professional activity
Deployer (Art. 3(4)): uses an AI system under its authority, other than for personal, non-professional use.
We are EU-based and place on the market a system bearing the name of a non-EU provider
Importer (Art. 3(6)).
We make it available on the market without being its provider or importer
Distributor (Art. 3(7)).
We are EU-based and act under a written mandate from a non-EU provider
Authorised representative (Art. 3(5)).
We place it on the market, or put it into service, with our own product under our own name
Product manufacturer (Art. 25(3)): carries the provider duties when the system is a high-risk safety component of an Annex I, Section A product.
Only a natural person’s purely personal, non-professional use
Art. 2(10) removes deployer obligations for natural persons in purely personal, non-professional use: no operator role follows.
Have you done any of these to a system that someone else first placed on the market or put into service?

Each one makes a distributor, importer, deployer or other third party the provider of a high-risk system. A substantial modification is an unplanned change after placing on the market that affects compliance or changes the assessed intended purpose. Tick all that apply.

Rests on Art. 25(1) · chapter 18: Article 25: when someone else becomes the provider · Ask when you triage an AI system.

What each answer means
Put our name or trademark on a high-risk system already on the market
Art. 25(1)(a): you become its provider, subject to contracts allocating the obligations otherwise.
Made a substantial modification to a high-risk system, which stays high-risk
Art. 25(1)(b): you become its provider.
Changed the intended purpose of a system that was not high-risk, including a general-purpose AI system, so that it becomes high-risk
Art. 25(1)(c): you become the provider of a high-risk system. The high-risk questions must place it on that rung.
None of these
No Art. 25(1) trigger.

4 Prohibited practices

Article 5 is a list of banned uses, not a risk assessment.

Is the system intended or used for one of these practices?

If a practice is on the list, no mitigation makes it lawful. Four points have a narrow carve-out, named under each; the two practices the Omnibus added are asked next. Tick all that apply.

Rests on Art. 5(1) · chapter 18: Prohibited practices (Article 5) · Ask when you triage an AI system.

What each answer means
Subliminal, manipulative or deceptive techniques that materially distort behaviour, causing or likely to cause significant harm
Art. 5(1)(a): prohibited since 2025-02-02, no carve-out.
Exploiting vulnerabilities of age, disability or social or economic situation, to the same effect
Art. 5(1)(b): prohibited since 2025-02-02, no carve-out.
Social scoring leading to unjustified or out-of-context detrimental treatment
Art. 5(1)(c): prohibited since 2025-02-02, no carve-out.
Predicting crime risk based solely on profiling or personality traits
Art. 5(1)(d): prohibited since 2025-02-02. Narrow carve-out: support to a human assessment based on objective, verifiable facts.
Untargeted scraping of facial images to build recognition databases
Art. 5(1)(e): prohibited since 2025-02-02, no carve-out.
Inferring emotions at work or in education
Art. 5(1)(f): prohibited since 2025-02-02. Narrow carve-out: medical or safety reasons.
Biometric categorisation to infer sensitive traits such as race, beliefs or sexual orientation
Art. 5(1)(g): prohibited since 2025-02-02. Narrow carve-out: lawfully acquired datasets; law-enforcement categorisation.
Real-time remote biometric identification in public spaces for law enforcement
Art. 5(1)(h): prohibited since 2025-02-02. Narrow carve-out: three objectives, with prior authorisation (Art. 5(2) to 5(7)).
None of these
No practice on the original Art. 5 list.
For each practice you ticked that has a narrow carve-out, does that carve-out apply?

Points (d), (f), (g) and (h) each have one narrow carve-out, named under the option. The other points have none. Choose one.

Rests on Art. 5(1)(d), (f), (g), (h) · chapter 18: Prohibited practices (Article 5) · Ask when you ticked point (d), (f), (g) or (h).

What each answer means
Yes, the carve-out applies to each such practice ticked
The carve-out is relied on: the record keeps it and the facts behind it, for counsel to confirm.
No
Outside the carve-out, no mitigation makes the practice lawful.
Not sure
Until the carve-out is confirmed, the triage treats the practice as prohibited.
Can the system generate or manipulate realistic images, video or audio?

From 2026-12-02, Art. 5 also bans generating or manipulating realistic intimate imagery of an identifiable person without explicit consent, and child sexual abuse material. The test turns on the intended purpose, foreseeability and the safeguards. Choose one.

Rests on Art. 5(1)(ba), (bb), Art. 5(1a) · chapter 18: Prohibited practices (Article 5) · Ask when you triage an AI system.

What each answer means
No
Points (ba) and (bb) do not arise.
Yes, and producing such imagery or material is its intended purpose, or the deployer uses it for that
Prohibited from 2026-12-02 (Art. 5(1)(ba) or (bb)).
Yes; such output is a reasonably foreseeable and reproducible outcome, and the system lacks reasonable and adequate technical safety measures to prevent it and correct observed misuse
Placing it on the market is prohibited from 2026-12-02 (Art. 5(1a)).
Yes; such output is foreseeable, but reasonable and adequate technical safety measures prevent it and correct observed misuse
Not prohibited on these answers, as long as the safeguard holds: the evidence that it holds is part of the legal test.
Yes, but such output is not a reasonably foreseeable and reproducible outcome
Not prohibited on these answers; keep the evaluation that shows it.

5 High-risk

Two routes: a safety component of an Annex I product, or an Annex III use not filtered out by Art. 6(3).

Is the system a product, or a component of a product, covered by the Union harmonisation legislation in Annex I?

Section A covers products such as toys, lifts, radio equipment, medical devices and in vitro diagnostics; Section B covers sectoral regimes such as civil aviation and vehicles. Machinery moved to Section B with the Omnibus. Choose one.

Rests on Art. 6(1), Annex I · chapter 18: High-risk through products (Annex I) · Ask when you triage an AI system.

What each answer means
No
The Annex I route does not arise.
Yes, under Annex I, Section A
The Art. 6(1) route: two conditions follow.
Yes, under Annex I, Section B
The Art. 6(1) route; for Section B products, only Art. 6(1), Art. 60a and Arts. 102 to 112 of the Act apply.
Not sure
Left open: check the product’s legislation against Annex I.
Is it the product itself, or a safety component in the Act’s narrowed sense?

After the Omnibus, a safety component must have the intended purpose of preventing or mitigating risks to health and safety, or be one whose failure endangers them. Choose one.

Rests on Art. 3(14), Art. 6(1a), 6(1b) · chapter 18: High-risk through products (Annex I) · Ask when the product is covered by Annex I.

What each answer means
The AI system is itself the product
First Art. 6(1) condition met: the system is itself a product covered by Annex I.
Its intended purpose is to prevent or mitigate risks to health and safety
A safety component (Art. 3(14) as amended): first Art. 6(1) condition met.
Its failure or malfunction would endanger health and safety
A safety component whatever its stated function (Art. 6(1b)): first Art. 6(1) condition met.
It is used solely for user assistance, performance optimisation, efficiency, automation, convenience or quality control, and its failure would not endanger health and safety
Not a safety component (Art. 6(1a)): the Annex I route does not apply.
Must that product undergo a third-party conformity assessment under that legislation?

Only an assessment required for health and safety counts. One required only for other reasons, such as radio spectrum, does not. Choose one.

Rests on Art. 6(1)(b), Art. 6(1c) · chapter 18: High-risk through products (Annex I) · Ask when it is the product itself or a safety component.

What each answer means
Yes, for health and safety reasons
Both Art. 6(1) conditions hold: high-risk through Annex I, from 2028-08-02.
Yes, but only for reasons other than health and safety, such as radio spectrum
Does not count (Art. 6(1c)): the Annex I route does not apply.
No
The second Art. 6(1) condition fails: the Annex I route does not apply.
Not sure
Left open: the Annex I route turns on this answer.
Does its intended purpose fall in one of the eight Annex III areas?

Tick an area only if the use it lists matches the intended purpose. The Commission can add use cases to Annex III by delegated act (Art. 7), so the list here carries the question set’s version. Tick all that apply.

Rests on Art. 6(2), Annex III · chapter 18: High-risk through use (Annex III) · Ask when you triage an AI system.

What each answer means
1. Biometrics: remote biometric identification (not one-to-one verification), biometric categorisation by sensitive attributes, emotion recognition
Annex III, point 1: high-risk unless the Art. 6(3) filter takes it out.
2. Critical infrastructure: safety components in critical digital infrastructure, road traffic, and the supply of water, gas, heating or electricity
Annex III, point 2: high-risk unless the Art. 6(3) filter takes it out.
3. Education and vocational training: admission, evaluating learning outcomes, assessing the level of education, detecting prohibited behaviour in tests
Annex III, point 3: high-risk unless the Art. 6(3) filter takes it out.
4. Employment and workers’ management: recruitment and selection, decisions on terms, promotion or termination, task allocation, monitoring and evaluating performance
Annex III, point 4: high-risk unless the Art. 6(3) filter takes it out.
5. Essential private and public services: eligibility for public benefits, creditworthiness and credit scoring (not fraud detection), life and health insurance pricing, emergency call triage and dispatch
Annex III, point 5: high-risk unless the Art. 6(3) filter takes it out.
6. Law enforcement: victim risk, polygraphs, evidence reliability, offending risk not based solely on profiling, profiling in investigations
Annex III, point 6: high-risk unless the Art. 6(3) filter takes it out.
7. Migration, asylum and border control: polygraphs, risk assessment of persons, examining applications, detecting or identifying persons (not travel-document checks)
Annex III, point 7: high-risk unless the Art. 6(3) filter takes it out.
8. Administration of justice and democratic processes: assisting judicial authorities with facts and law (and ADR), influencing elections or voting behaviour
Annex III, point 8: high-risk unless the Art. 6(3) filter takes it out.
None of these
The Annex III route does not arise.
Does one of the four Art. 6(3) conditions hold, so that it does not materially influence the outcome of decision-making?

The filter takes an Annex III system out only where it does not pose a significant risk of harm to health, safety or fundamental rights. Tick the condition you rely on. Tick all that apply.

Rests on Art. 6(3) · chapter 18: The Annex III filter and the profiling override · Ask when you ticked an Annex III area.

What each answer means
It performs a narrow procedural task
First Art. 6(3) condition claimed.
It improves the result of a previously completed human activity
Second Art. 6(3) condition claimed.
It detects decision-making patterns or deviations without replacing or influencing the completed human assessment without proper human review
Third Art. 6(3) condition claimed.
It performs a preparatory task to an assessment relevant to an Annex III use case
Fourth Art. 6(3) condition claimed.
None of these
No condition claimed: the filter cannot take it out.
Does the system profile natural persons?

One override beats all four conditions. State the answer explicitly: the record keeps it as a flag. Choose one.

Rests on Art. 6(3), third subparagraph · chapter 18: The Annex III filter and the profiling override · Ask when you ticked an Annex III area.

What each answer means
Yes
Always high-risk, whatever condition is claimed: the override beats all four.
No
The override does not apply: a condition, if one holds, can take the system out.
Not sure
Until the profiling flag is settled, the triage does not apply the filter.

6 Transparency

Article 50 applies to any AI system that fits one of its cases, whatever else the system is.

Does the system fit one of the Article 50 cases?

One system can sit on two rungs at once: an Annex III chatbot carries both the high-risk duties and the Art. 50 disclosure duty. Tick all that apply.

Rests on Art. 50 · chapter 18: Transparency cases (Article 50) · Ask when you triage an AI system.

What each answer means
It interacts directly with people
Art. 50(1), a provider duty: people must know it is AI, unless obvious.
It generates synthetic audio, image, video or text
Art. 50(2), a provider duty: machine-readable, detectable marking.
It performs emotion recognition or biometric categorisation
Art. 50(3), a deployer duty: inform the people exposed.
It generates or manipulates deep fakes
Art. 50(4), a deployer duty: disclose the manipulation (lighter for evident art or satire).
It generates text published to inform the public
Art. 50(4), a deployer duty: disclose, unless a human holds editorial responsibility.
None of these
No Article 50 case.

7 General-purpose AI models

The model track: generality, the systemic-risk presumption and the open-source carve-out.

Is it a general-purpose AI model?

A GPAI model displays significant generality, competently performs a wide range of distinct tasks and can be integrated into a variety of downstream systems. Choose one.

Rests on Art. 3(63) · chapter 18: Model, system and the indicative criterion · Ask when you triage a model (alone or with a system).

What each answer means
Yes: it displays significant generality and competently performs a wide range of distinct tasks
A GPAI model (Art. 3(63)): the model-level duties apply to its provider.
It meets the guidelines’ indicative criterion: training compute above 10^23 FLOP, and it generates language (text or audio), text-to-image or text-to-video
The Commission guidelines give this as an indicative criterion; the triage treats it as a GPAI model.
It is used only for research, development or prototyping before being placed on the market
Outside the Art. 3(63) definition while it stays there.
No
Not a GPAI model: the model-level duties of Arts. 51 to 56 do not apply to it.
What is its cumulative training compute, and has the Commission designated it?

High-impact capabilities are presumed above 10^25 FLOP of cumulative training compute, a threshold the Commission can amend. Choose one.

Rests on Art. 51, Art. 52 · chapter 18: Systemic risk: threshold, notification, designation · Ask when it is a GPAI model.

What each answer means
Above 10^25 FLOP
Presumed to have high-impact capabilities: systemic risk (Art. 51(2)). Notify the Commission within two weeks; the provider may argue that the model exceptionally presents no systemic risk (Art. 52).
Below today, but planned training will cross 10^25 FLOP
The two-week notification clock can start before training ends: plan for the systemic-risk duties now.
The Commission designated it on the Annex XIII criteria
Systemic risk by designation (Art. 51(1)).
Below 10^25 FLOP, not planned to cross it, and not designated
No systemic risk on these answers: the duties of every GPAI provider apply.
Not known
Left open: keep a compute ledger, cumulative training FLOP per model lineage with the estimation method.
Did you train the model, or modify (for example fine-tune) someone else’s?

A modifier becomes the provider of a new GPAI model only if the change is significant for generality, capabilities or systemic risk. This is a different test from Art. 25, on a different object. Choose one.

Rests on Art. 3(63), Art. 53 · chapter 18: When a fine-tuner becomes a GPAI provider · Ask when it is a GPAI model that you develop or have developed.

What each answer means
We trained it
You are the provider of the GPAI model.
We modified it with more than one third of the original training compute (if unknown: a third of 10^25 FLOP for a systemic-risk original, of 10^23 FLOP otherwise)
Provider of a new GPAI model on the guidelines’ indicative criterion: your Art. 53(1) duties are limited to the modification and its data, and Art. 54 applies; if the original model has systemic risk, the modified one is presumed to have it, so notify the Commission (Art. 52) and meet Art. 55.
We modified it with less compute than that
Not a new GPAI model on the guidelines’ indicative criterion: the model duties stay with the original provider.
Is the model released under a free and open-source licence, with its weights, architecture and usage information public?

The carve-out never covers a systemic-risk model, and monetisation defeats it. Choose one.

Rests on Art. 53(2), Art. 54(6) · chapter 18: Open-source carve-outs and their limits · Ask when it is a GPAI model.

What each answer means
Yes, and it is not monetised
Exempt from Art. 53(1)(a) and (b) and from the authorised-representative duty, unless it has systemic risk; the copyright policy and training summary still apply.
Yes, but it is monetised: dual licensing, paid support without which it cannot be used, or exclusive paid hosting
Monetisation defeats the carve-out.
No
No open-source carve-out.

8 The decision record

Who reviewed the triage, when, and what should make you run it again. The record is the output of intake and classification: it lives in the registry, next to the system.

Review

Write roles, not personal names. The reviewer is needed for the exports, not for the result.

The facts a carve-out or a filter rests on, what counsel said, what is still open.

Re-review triggers

Events that should re-open the record. The tool ticks the ones your answers suggest; change them as you need.

How the triage works

The chapter reads the Act as four ideas: a definition gate, a risk ladder, a set of operator roles and a timeline [1]. The triage asks them in that order, and skips what your earlier answers rule out.

  1. What you are triaging. The Act regulates two objects: AI systems, ranked by intended purpose, and general-purpose AI models, on a separate track.
  2. Reach and exclusions. Whether the Act reaches it at all: by placement, by use in the Union or by output used in the Union, less the narrow exclusions.
  3. Your role. Roles name tasks, not organisations: one organisation can be provider and deployer of the same system.
  4. Prohibited practices. Article 5 is a list of banned uses, not a risk assessment.
  5. High-risk. Two routes: a safety component of an Annex I product, or an Annex III use not filtered out by Art. 6(3).
  6. Transparency. Article 50 applies to any AI system that fits one of its cases, whatever else the system is.
  7. General-purpose AI models. The model track: generality, the systemic-risk presumption and the open-source carve-out.

How to read the result

  • Indicative, never a verdict. The result names the roles and classes your answers imply, with the reason and the article behind each. It never declares conformity: that is a claim about evidence, not about answers.
  • Roles are per system. A role attaches to an activity on a specific system, not to a company: an in-house system is often ["provider", "deployer"] [1].
  • Classes stack. One system can sit on two rungs at once: an Annex III chatbot carries both the high-risk duties and the Art. 50 disclosure duty. A system built on your own GPAI model has the model track as well.
  • Out of scope assigns nothing. When the definition, reach or an exclusion takes it out, the result shows what the other answers would give, so you know what to plan for if the facts change.
  • Open points are the work. A "not sure" answer never disappears: it becomes an open point in the record until someone settles it.

The rules, written out

Without JavaScript, answer the questions above and read the outcome off these rules. They are the same data the live result runs on (question set 1.0.0).

Scope

In scope unless one of these holds (a "not settled" rule keeps the triage going):

  • Out of scope when the system only applies rules defined solely by natural persons. Not an AI system on the definition screen: the Commission guidelines exclude systems based on rules defined solely by natural persons. The guidelines are not binding, so record the element that fails and the reasoning. ( Art. 3(1))
  • Out of scope when you triage a model alone and it is not a GPAI model. A model that is not a GPAI model carries no model-level duties, and a model is not an AI system on its own. ( Art. 3(63))
  • Out of scope when you triage a model alone and it is still in research, development or prototyping. A model used for research, development or prototyping before it is placed on the market is outside the GPAI model definition. ( Art. 3(63))
  • Out of scope when none of the Art. 2(1) links holds. No placement on the EU market, no deployer in the Union and no output used in the Union: Art. 2(1) does not reach it on these answers. ( Art. 2(1))
  • Out of scope when the military, defence or national security exclusion is claimed. Used exclusively for military, defence or national security purposes. A dual-use system is in scope for its other uses. ( Art. 2(3))
  • Out of scope when the third-country authority exclusion is claimed. A third-country public authority or international organisation in law-enforcement or judicial cooperation, with adequate safeguards for fundamental rights. ( Art. 2(4))
  • Out of scope when the scientific research exclusion is claimed. Specifically developed and put into service for the sole purpose of scientific research and development. ( Art. 2(6))
  • Out of scope when the pre-market research and testing exclusion is claimed. Research, testing or development before placing on the market or putting into service. Testing in real-world conditions is not covered by the exclusion. ( Art. 2(8))
  • Out of scope when the open-source exclusion is claimed and no system rung other than minimal applies. An AI system released under a free and open-source licence that is not high-risk and not caught by Art. 5 or Art. 50. ( Art. 2(12))
  • Out of scope when only purely personal, non-professional use by a natural person. A natural person’s purely personal, non-professional use: Art. 2(10) removes the deployer obligations. ( Art. 2(10))
  • Not settled when the inference answer is "one of the four families" or "not sure". The Art. 3(1) definition is not settled. Scope is a recorded decision, not an assumption: the triage carries on as if it were an AI system. ( Art. 3(1))

Classes

  • Prohibited practice (Art. 5) when:
    • You ticked point (a), (b), (c) or (e) of Art. 5. A practice on the Art. 5 list with no carve-out. It may not be placed on the market, put into service or used, and no mitigation makes it lawful. Applies from 2025-02-02.
    • You ticked point (d), (f), (g) or (h) of Art. 5 and did not confirm its carve-out. A practice on the Art. 5 list whose narrow carve-out is not confirmed. Outside the carve-out, no mitigation makes it lawful. Applies from 2025-02-02.
    • Such output is the generator’s intended purpose or use, or a foreseeable outcome without reasonable and adequate safeguards. One of the two practices the Omnibus added (intimate imagery without consent, child sexual abuse material): prohibited from 2026-12-02. Applies from 2026-12-02.
  • High-risk (Annex I) (Art. 6(1)) when:
    • Annex I product, the system is the product or a safety component, and a third-party assessment is required for health and safety. Both Art. 6(1) conditions hold: a safety component of an Annex I product, or the product itself, that must undergo a third-party conformity assessment. The Annex I route applies from 2028-08-02. Applies from 2028-08-02.
  • High-risk (Annex III) (Art. 6(2)) when:
    • An Annex III area is ticked and the system profiles natural persons. An Annex III system that profiles natural persons is always high-risk: the override beats all four Art. 6(3) conditions. Applies from 2027-12-02.
    • An Annex III area is ticked and no Art. 6(3) condition is claimed. An Annex III use with no Art. 6(3) condition claimed: high-risk. Applies from 2027-12-02.
    • An Annex III area is ticked and the profiling answer is "not sure". An Annex III use whose profiling flag is not settled: the filter is not applied until it is. Applies from 2027-12-02.
  • Transparency (Art. 50) (Art. 50) when:
    • You ticked at least one Article 50 case. Fits an Article 50 case, whatever else the system is. The information must reach people at the latest at first interaction or exposure; the article has applied since 2026-08-02. Applies from 2026-08-02.
  • Minimal risk (Arts. 4, 95) when:
    • An AI system on no other rung. Everything else is minimal risk: nothing specific beyond AI literacy (Art. 4), and voluntary codes of conduct (Art. 95). Minimal is a legal category, not a risk verdict: data protection, consumer, product-liability and anti-discrimination law still apply. Applies from 2025-02-02.
  • GPAI model (Arts. 51 to 56) when:
    • The model is a GPAI model, or meets the guidelines’ indicative criterion. A general-purpose AI model. GPAI obligations have applied since 2025-08-02 and Commission fines under Art. 101 since 2026-08-02; models placed on the market before 2025-08-02 must comply by 2027-08-02. Applies from 2025-08-02.
  • GPAI model with systemic risk (Arts. 51, 52, 55) when:
    • Cumulative training compute above 10^25 FLOP. Presumed to have high-impact capabilities above 10^25 FLOP of cumulative training compute. Notify the Commission within two weeks; the provider may argue that the model exceptionally presents no systemic risk. Applies from 2025-08-02.
    • The Commission designated the model. Designated by the Commission on the Annex XIII criteria. Applies from 2025-08-02.
    • Planned training will cross 10^25 FLOP. Planned training will cross 10^25 FLOP: the presumption applies once it does, and the two-week notification clock can start before training ends.

Roles

  • Provider (Art. 3(3)) when:
    • You develop the AI system, or have it developed, under your own name. You develop the system, or have it developed, and place it on the market or put it into service under your own name. Putting into service includes own use.
    • You integrate an AI model into the system. A downstream provider carries the provider duties for the system it builds.
    • You ticked an Art. 25(1) trigger and the system is high-risk. An Art. 25(1) trigger on a high-risk system makes you its provider, with all of the Art. 16 duties.
  • Downstream provider (Art. 3(68)) when:
    • You integrate an AI model into the system. You integrate an AI model, your own or a third party’s, into the AI system.
  • Deployer (Art. 3(4)) when:
    • You use the AI system in a professional activity. You use the AI system under your authority, other than for personal, non-professional use.
  • Importer (Art. 3(6)) when:
    • You import the system. EU-based, you place on the market a system bearing a non-EU provider’s name.
  • Distributor (Art. 3(7)) when:
    • You distribute the system. You make the system available without being its provider or importer.
  • Authorised representative (Art. 3(5)) when:
    • You act as authorised representative. EU-based, you act under a written mandate from a non-EU provider.
  • Product manufacturer (Art. 25(3)) when:
    • You place it with your own Annex I, Section A product, and it is high-risk through Annex I. You place a high-risk safety component with your Annex I, Section A product under your own name: the provider duties of Art. 16 are yours.
  • General-purpose AI model provider (Art. 53) when:
    • You develop a GPAI model, or modified one above the indicative criterion. You are the provider of a general-purpose AI model: Arts. 53 to 55 apply to you.

The classification decision record

The chapter asks for a classification decision record for every Annex III candidate, with the Art. 6(3) condition relied on and the profiling flag stated explicitly, filed in the registry and re-evaluated whenever the intended purpose changes [1]. The record lives in Layer 2 (Inventory & Transparency); the rule that computes it lives in Layer 1. The exported record carries the question-set version, every answer with its article and meaning, the outcome with its reasons, the reviewer, the date, the legal-review state and the re-review triggers.

The JSON export re-opens here: import it above and the outcome is recomputed from its answers with the question set this page runs. A record made with another version loads the answers that still exist and says what it dropped.

Hand-off to the obligations planner

The result opens the obligations planner with the roles and classes it found, in the part of the link after #, which the browser keeps to itself. The planner reads role codes (r), class codes (c) and a reference date (d, the decision date); the triage adds from and qs so the plan can say where its answers came from:

/toolkit/obligations-planner#v=1&r=pr.de&c=h3&d=2026-09-24&from=ai-act-triage&qs=1.0.0
  • pr: Provider
  • pr: Downstream provider
  • pr: Product manufacturer
  • de: Deployer
  • im: Importer
  • di: Distributor
  • ar: Authorised representative
  • gp: General-purpose AI model provider
  • gs: a general-purpose AI model provider whose model has systemic risk
  • h3: High-risk (Annex III)
  • h1: High-risk (Annex I)
  • tr: Transparency (Art. 50)

The planner adds the duties every AI system carries (AI literacy and the Art. 5 screen) by itself. Out of scope, there is nothing to hand off. Until the planner is published, the obligation register lists every EU AI Act duty with its holder and the classes it applies to.

What this is not

It is an engineer's reading of the Act, not legal advice, not a conformity assessment and not a certification. The Commission's classification guidelines were still a draft as of 2026-09-24 [7], and until they are final the defence is a good record, not a good argument. The definition and GPAI guidelines it relies on are not binding [5][6]. The tool asserts only what chapter 18 states; mappings are illustrative, not a claim of conformity.

Question set and versioning

Question set aige.eu-ai-act-triage version 1.0.0, as of 2026-09-24. A change to a rule, a question's meaning or an option value is a major version; a new question or option is a minor one; a wording fix is a patch. Question ids and option values stay stable within a major version, because saved records and copied links carry them. The graph has 20 questions in 7 steps.

Sources

  1. [1] 18. The EU AI Act in one pass: every question, option, rule, reason and date this tool shows, and the illustrative classification decision record it extends. AI Governance Engineering Body of Knowledge. 2026-09-24. https://aigovernanceengineer.com/bok/eu-ai-act (verified: primary)
  2. [2] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 Jul 2026 incorporating Regulation (EU) 2026/1744: Arts. 2, 3, 5, 6, 25, 50 to 53 and Annexes I and III, the anchors each question links to. Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
  3. [3] Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), original text; OJ L, 2024/1689, 12.7.2024. Publications Office of the EU (EUR-Lex). 2024-07-12. https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (verified: primary)
  4. [4] Regulation (EU) 2026/1744 (Digital Omnibus on AI) of 8 Jul 2026: new Art. 5(1)(ba), (bb), (1a), (1b); Art. 3(14) and Art. 6(1a) to (1c); Art. 2(2) and 2(13); Art. 25(2); Art. 111(4); Art. 113 dates; OJ L, 2026/1744, 24.7.2026, in force on the third day after publication. Publications Office of the EU (EUR-Lex). 2026-07-24. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng (verified: primary)
  5. [5] Commission Guidelines on the definition of an artificial intelligence system (seven elements; four families that may fall outside; non-binding), as cited in chapter 18. European Commission. 2025-02-06. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application (verified: primary)
  6. [6] Commission Guidelines on the scope of the obligations for providers of general-purpose AI models (C(2025) 7719 final; 10^23 FLOP indicative criterion; one-third modification criterion; monetisation), as cited in chapter 18. European Commission. 2025-11-19. https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act (verified: primary)
  7. [7] Draft Commission guidelines on the classification of high-risk AI systems (Art. 6; still a draft as of 2026-09-24), as cited in chapter 18. European Commission. 2026-05-19. https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems (verified: primary)