ISHIGHRISK AI

Is your AI system high-risk?

A seven-stage triage against the current, post-Digital Omnibus text. Scope, prohibitions, Annex III, the Article 6(3) derogation, GPAI, Article 50 and your role. Free, and every determination is anchored to the article it rests on. Triage, not legal advice.

Free triage classifier - 7 stages
Stage 1 of 7 · Scope · Article 3(1)

Does your system meet the AI-system definition?

Machine-based, operates with some autonomy, and infers from input how to generate outputs (predictions, content, recommendations, decisions). Deterministic rule-based software generally does not.

Triage, not legal advice. Ambiguous cases need qualified counsel.
Why you can trust this
01
Every classification maps to the exact article text - no black box.
02
Verified against the consolidated regulation on 22 July 2026.
03
Updated within 48 hours of any Official Journal change.
01 - The cornerstone question

What actually applies on 2 August 2026?

“Deadlines delayed” is a dangerous half-truth. The Digital Omnibus split one date into two very different categories. If you stood down your AI Act programme on that headline, you may be exposed.

Applies now - as written
  • Chatbot disclosure- users must be told they're interacting with AI. Art 50(1)
  • Emotion & biometric categorisation notice to exposed persons. Art 50(3)
  • Deepfake & public-interest text disclosure. Art 50(4)
  • AI Office enforcement begins.
Moved later - don't stand down
  • Machine-readable marking of synthetic content → 2 Dec 2026 (grace for systems already on the market). Art 50(2)
  • High-risk obligations, standalone Annex III → 2 Dec 2027.
  • High-risk obligations, embedded Annex I products → 2 Aug 2028.
Note - the trapOnly the 50(2) marking obligation and the high-risk regime moved. Transparency under Article 50 still bites on 2 August 2026 for a huge population - any chatbot, any generative tool, any deepfake.
02 - Application timeline

The AI Act timeline, as amended

Date
Milestone
Status
2 Feb 2025
Prohibitions & AI literacy
Article 5 prohibited practices and the Article 4 AI-literacy duty applied.
In force
2 Aug 2025
GPAI, governance & penalties
General-purpose AI model obligations, the governance framework and penalty provisions applied.
In force
2 Aug 2026
Article 50 transparency
Chatbot, emotion and deepfake disclosure apply; AI Office enforcement begins.
Next cliff
2 Dec 2026
Marking & the nudifier ban
Art 50(2) machine-readable marking (grace period) and the CSAM / non-consensual-imagery prohibition apply.
Upcoming
2 Dec 2027
High-risk, standalone
High-risk obligations for standalone Annex III systems apply - a 17-month extension.
Upcoming
2 Aug 2028
High-risk, embedded
High-risk obligations for Annex I embedded-product systems apply.
Upcoming
03 - The tools

Two checks that give a real answer, free.

See your classification on screen. Leave an email only when you want the compiled, defensible deliverables.

01 - 7-stage decision tree

AI Act triage classifier

Scope → prohibited → high-risk → the Article 6(3) derogation → GPAI → transparency → your role. Goes deep where the ambiguity actually lives.

Free
Every determination with the article it rests on, plus the deadlines that attach to your answers.
Obligation checklist, Annex IV documentation list, deadline calendar and a dated self-assessment record.
Start the classifier →
02 - Stage 5 · due 2 Aug 2026

Article 50 transparency

Chatbot, deepfake, emotion recognition, synthetic-content marking. Built into the classifier as its own stage, because these duties apply whatever your risk tier, the nearest hard cliff for most businesses, and the most misunderstood.

Free
Which 50(1)–(4) duties apply to you, and exactly when - including whether the 50(2) marking grace period reaches you.
The duty-by-duty checklist and the Code of Practice marking requirements, in the same report.
Run the check →
04 - Who it's for

Built for the people who have to give the answer.

Compliance & legal leads
Triage a portfolio fast, then hand counsel a documented starting point.
Founders & product teams
Know before you ship whether a feature drags you into the high-risk regime.
In-house counsel
Article-anchored results and defensible self-assessment records you can rely on.
Procurement & vendor risk
Spot the Article 25 “flip” that turns a buyer into an accountable provider.
05 - How the report works

Answer, see your tier, then get the paperwork.

Step 1
Answer a short wizard
Plain-English questions, one at a time. No jargon, no account.
Step 2
See your classification free
Your tier on screen, with the article it rests on and the deadline that applies.
Step 3
Get the compiled report
Leave your email for the citation-backed checklist, documentation list and deadline calendar.
06 - Penalties & enforcement

What non-compliance costs.

Three tiers under Article 99, enforceable since 2 August 2025.

€35M / 7%
Article 5 prohibited practices - the highest tier.
of worldwide annual turnover
€15M / 3%
Most obligations - including Article 50 transparency and the high-risk regime.
of worldwide annual turnover
€7.5M / 1%
Incorrect or misleading information supplied to authorities.
of worldwide annual turnover
For companies the higher of the fixed sum or the percentage applies - but SMEs and start-ups pay the lower of the two. Article 99(6)

When triage isn't enough.

The Article 6(3) derogation and accidental “provider” status are where classification gets genuinely hard - and where a wrong call is expensive. We help you build a defensible position.

Book a consult →
07 - The guides

Every test the classifier runs, written out.

Each stage of the triage has a page behind it: what the article says, how it is tested in practice, and where the determination is genuinely contested.

The cornerstone questionWhat actually applies on 2 August 2026Article 50 transparency still bites on 2 August 2026. Only the 50(2) marking duty and the high-risk regime moved. Here is the split, duty by duty.TransparencyArticle 50 transparency obligationsArticle 50 covers chatbots, deepfakes, emotion recognition and synthetic content marking. Who owes what, and the 2 August and 2 December 2026 dates.Key datesThe EU AI Act timeline, as amendedEvery EU AI Act application date from February 2025 to August 2028, as amended by the Digital Omnibus, with what each one obliges and who it binds.The amendmentThe Digital Omnibus, and what it changedThe Digital Omnibus split one deadline into four, added a ninth prohibition and kept database registration. What changed, what did not, what is pending.ClassificationWhat counts as a high-risk AI systemTwo routes make an AI system high-risk under Article 6: Annex I product safety law and the eight Annex III use cases. Here is how each one is tested.The ambiguity hotspotThe Article 6(3) derogationFour conditions can lift an Annex III system out of the high-risk regime, and profiling forecloses all of them. Where the derogation gets over-claimed.RolesProvider, deployer, and the Article 25 flipThree acts turn a deployer into a provider under Article 25 and hand you the full Article 16 obligation set. How role determination actually works.GPAIGeneral-purpose AI model obligationsArticle 53 documentation, the 10^25 FLOP systemic-risk presumption and the Article 55 duties. What makes a model GPAI, and what each tier owes.DocumentationAnnex IV technical documentationAnnex IV takes nine documentation blocks, drawn up before market placement, kept current and retained ten years. What each block has to contain.EnforcementPenalties and enforcementThree Article 99 tiers, enforceable since 2 August 2025. Which breach lands in which tier, and why SMEs pay the lower of the two figures, not the higher.Sector guideRecruitment and HR AI under the AI ActAnnex III point 4 covers job ads, CV filtering, interviews, promotion and monitoring. Which HR tools are high-risk and which clear the derogation.Territorial scopeDoes the EU AI Act apply to US companies?Article 2 pulls in US companies with no EU office the moment an AI system's output is used in the Union. Here is the extraterritorial test in plain terms.
08 - Questions

Common questions.

Is this legal advice?

No. This is triage - a structured first pass to tell you where your system likely sits and which articles apply. Ambiguous cases, and any final classification you rely on, should be confirmed with qualified counsel.

How current is this?

Verified against Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026. The Omnibus was adopted and signed but awaiting Official Journal publication at the review date; we update the moment the consolidated text and regulation number are published.

Do I have to sign up to see my result?

No. Your classification and the article it rests on are free, on screen. You only leave an email if you want the compiled report - the obligation checklist, Annex IV documentation list and deadline calendar.

What actually changed with the Digital Omnibus?

The single 2 August 2026 date split in two. Article 50 transparency still applies then, but the 50(2) marking obligation moved to 2 December 2026 and the high-risk regime moved to 2 December 2027 (standalone) and 2 August 2028 (embedded). “Deadlines delayed” is only half the story.

My system isn't high-risk - am I done?

Not necessarily. A system can fall outside Annex III and still owe Article 50 transparency duties - for instance a customer-facing chatbot or a generative-content tool. The classifier routes you to the transparency check when that applies.