Free checker · updated for Regulation (EU) 2026/1744 · not legal advice
EU AI Act risk categories: which tier is your system in, and by when?
This EU AI Act risk categories checker walks the Article 6 decision tree with the dates that apply after the 2026 Digital Omnibus. Answer nine questions about role, EU nexus, prohibited practices, Annex I and Annex III uses, general-purpose models and Article 50 interaction. You get the risk tier, the obligations that follow, and the applicable deadline: stand-alone Annex III high-risk systems from 2 December 2027, Annex I embedded systems from 2 August 2028, Article 50 transparency in force since 2 August 2026. Orientation only, not legal advice.
- Obligation 1
- Article 50(1): inform people they are interacting with an AI system unless obvious. In force since 2 August 2026.
- Fines
- Up to EUR 35M or 7% of global turnover for prohibited practices; lower tiers for other breaches (Art. 99)
Limited risk (Article 50) as a provider; in force since 2 August 2026.
Assumptions and sources (8)
| Constant | Value | Basis |
|---|---|---|
| Annex III high-risk obligations | from 2 December 2027 | sourcedDigital Omnibus, Regulation (EU) 2026/1744, in force 2026-07-27 (Gibson Dunn summary) |
| Annex I high-risk obligations | from 2 August 2028 | sourcedSame |
| Article 50 transparency | in force 2 August 2026; legacy systems 2 December 2026 | sourcedMayer Brown, July 2026; CSA research note |
| Article 50(2) legacy systems | from 2 December 2026 | sourcedCloud Security Alliance research note |
| GPAI obligations (Art. 53 / 55) | in force 2 August 2025 | sourcedMayer Brown, July 2026 |
| Prohibited practices (Art. 5) | applied since 2 February 2025; fines up to EUR 35M or 7% (Art. 99) | sourcedRegulation (EU) 2024/1689 as amended |
| Decision tree | Art. 2 scope, Art. 5, Art. 6(1) Annex I, Art. 6(2) Annex III, Art. 6(3) exemption, Art. 53/55, Art. 50 | proxySimplified orientation tree; verify against the Regulation and Commission guidance |
| Countdown | computed from your device date | estimateClient clock |
Key takeaways
- The Omnibus moved Annex III high-risk duties to 2 December 2027 and Annex I to 2 August 2028. It deferred them, it did not remove them.
- Article 50 transparency duties applied from 2 August 2026 regardless of tier. Chatbots must say they are AI.
- Credit scoring and insurance pricing for natural persons are Annex III 5(b) and 5(c). Deferred, still high-risk.
- Article 6(3) can take a listed system out of high-risk, but only with a documented assessment.
- Most older checkers still show 2 August 2026 for Annex III. Check the date on any tool you use.
EU AI Act risk categories explained
The EU AI Act sorts systems into four risk categories, plus a separate regime for general-purpose models. The category sets the obligations; the 2026 Digital Omnibus, Regulation (EU) 2026/1744 (in force 27 July 2026), reset the dates for the high-risk tier without changing the tiers themselves (Gibson Dunn; Freshfields). The four tiers, with what each one requires and when, are below; run the checker above to see which one your system lands in. Orientation only, not legal advice.
- Unacceptable risk (Article 5), banned since 2 February 2025. Social scoring by public authorities, manipulative or exploitative techniques, untargeted facial-image scraping, emotion recognition at work or in education, and most real-time remote biometric identification in public spaces. Obligation: do not place on the market or use. Fines up to EUR 35M or 7% of global turnover (Art. 99). Source: artificialintelligenceact.eu.
- High risk (Article 6 and Annex III), stand-alone systems from 2 December 2027. Annex III lists creditworthiness and credit scoring of natural persons (5(b)), life and health insurance risk assessment and pricing (5(c)), recruitment and worker management (4), education (3), access to essential services (5(a)), critical infrastructure (2), biometrics (1) and law enforcement, migration and justice (6 to 8). Obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, EU database registration, conformity assessment; deployers add Article 26 duties. Annex I safety components in regulated products follow from 2 August 2028. Post-Omnibus dates: Gibson Dunn.
- Limited risk (Article 50 transparency), in force since 2 August 2026. Chatbots and voice agents must tell people they are AI unless obvious; synthetic audio, image, video and certain text must be marked; deepfakes disclosed. Article 50(2) marking for legacy systems applies from 2 December 2026. These duties were not deferred by the Omnibus and apply on top of any other tier. Sources: Mayer Brown; Cloud Security Alliance.
- Minimal risk, no fixed deadline. Spam filters, inventory forecasting, most internal productivity agents that neither decide about people nor talk to the public. Obligation: none specific under the Act; voluntary codes of conduct (Art. 95) and existing law (GDPR, consumer, sectoral rules) still apply. Source: European Commission, AI Act overview.
- General-purpose AI models (Articles 53 and 55), in force since 2 August 2025. Not a risk tier but a parallel regime for model providers: technical documentation, downstream information, copyright policy and a training-data summary; systemic-risk models (10^25 FLOPs and above) add evaluation, adversarial testing and incident reporting. Source: Mayer Brown.
EU AI Act risk categories: how risk classification works
Article 6 has two routes into high-risk. Route one: the system is a safety component of a product covered by Annex I harmonised legislation, such as a medical device or machinery. Route two: the system is used for one of the stand-alone purposes in Annex III, such as creditworthiness, insurance pricing, recruitment or education.
Article 6(3) is the exit. A listed system that only performs a narrow procedural task, improves a prior human decision, or detects patterns without replacing human assessment can be documented out of high-risk. The Commission published new classification guidance in July 2026 (Mayer Brown). TheoSym's AI consulting practice builds that assessment into the design record from the first sprint.
- Unacceptable: Article 5, banned since February 2025
- High: Annex I (2028) or Annex III (2027)
- Limited: Article 50 transparency, live since August 2026
- GPAI: Article 53, systemic risk adds Article 55
- Minimal: no specific duties
Is my AI system high-risk under the EU AI Act after the Omnibus?
The test did not change. The dates did. Regulation (EU) 2026/1744, in force 27 July 2026, moved stand-alone Annex III obligations to 2 December 2027 and Annex I to 2 August 2028 (Gibson Dunn). Article 50 was not deferred and has applied since 2 August 2026.
For lenders and insurers the answer is usually yes. Annex III 5(b) covers creditworthiness and credit scoring of natural persons; 5(c) covers life and health insurance risk assessment and pricing. QGI builds those decision layers deterministic, with the logging, reproducibility and human-oversight evidence Chapter III asks for, so the conformity file writes itself as the system runs. Shipped examples are in the AI Factory workproofs.
Article 50 transparency obligations vs high-risk obligations
Article 50 is about disclosure, not conformity assessment. If your agent talks to people, they must be told it is AI unless that is obvious. If it generates synthetic audio, image, video or certain text, the output must be marked. These duties apply to minimal-risk systems too, and they are live now.
High-risk obligations are heavier: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, registration and conformity assessment. A chatbot that also scores credit carries both sets. The harness TheoSym ships with every production agent covers the Article 50 disclosure and the logging line by default.
When do you need an EU AI Act compliance checker, and what are the fines?
Before the architecture is fixed. Classification decides whether you need a fundamental-rights impact assessment, a registration and a notified body, and those change what you build. The incumbent checker reports 150,000 monthly users (Future of Life Institute); many still show the pre-Omnibus dates.
Run it again when the use case changes, when you add a general-purpose model, or when the system starts talking to customers. Dr. Sam Sammane, QGI Founder & CEO, has published on formal verification and explainable AI for two decades; announcements are in the press center. None of this is legal advice. Verify against the Regulation as amended and your counsel.
EU AI Act risk categories: questions people ask
Is a credit scoring or lending AI high-risk under the EU AI Act?+
Yes, in most cases. Annex III point 5(b) lists AI used to evaluate creditworthiness or establish credit scores for natural persons, and 5(c) covers life and health insurance risk assessment and pricing. The 2026 Digital Omnibus deferred these obligations to 2 December 2027; it did not remove them.
What changed with the EU AI Act Digital Omnibus in 2026?+
Regulation (EU) 2026/1744, in force 27 July 2026, moved stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. Article 50 transparency duties still applied from 2 August 2026, and GPAI obligations have applied since August 2025.
Does my chatbot or AI agent need to tell users it is AI?+
If it interacts directly with people, Article 50 requires that they are informed they are dealing with an AI system unless it is obvious. Synthetic audio, image, video and certain text must be marked as AI-generated. These transparency duties applied from 2 August 2026, regardless of risk tier.
What are the EU AI Act risk categories?+
Four categories plus general-purpose models: unacceptable (Article 5, banned), high (Annex I products and Annex III stand-alone uses), limited (Article 50 transparency) and minimal. Article 6(3) lets a provider document that a listed system only performs a narrow procedural task or supports a human decision, which can take it out of the high-risk category.
Is this checker legal advice?+
No. It is an orientation tool built on public summaries of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. It simplifies the decision tree and cannot see your facts. Confirm the tier, the obligations and the dates with counsel and against the primary text before you rely on them.
Next step
Take the result to the QGI team
Send the score. Dr. Sam Sammane, QGI Founder & CEO, or an engineer who has shipped replies within one business day with the gaps that matter first.
Prefer to talk? +1 657-888-0688 or contact@theosym.com