Answer practical questions
No need to already know legal role names. We ask how you build, buy, import, or use AI.
Free interactive compliance tool
Find out which EU AI Act requirements may apply to your company.
Answer a few questions about how your company builds or uses AI. Get a practical assessment of your likely role, risk areas, transparency obligations and next steps.
Free · No account · No email required
Up to 14 adaptive questions · deterministic rules · not legal advice
About 5–8 minutes
Answer based on how your company actually builds or uses AI. The result is a structured decision-tree assessment: likely role, risk areas, transparency signals, and next actions.
Example company: A SaaS company uses an AI customer support chatbot and third-party generative AI internally.
This is a decision-tree assessment, not an LLM guess. Your answers stay in the browser. The engine maps practical facts to role, risk, transparency, GPAI, literacy, and next-action signals — with source references you can review.
No need to already know legal role names. We ask how you build, buy, import, or use AI.
Workplace, biometric, and generative-content questions appear only when earlier answers make them relevant.
Applicability, likely roles, risk areas, why flags were raised, and prioritized next actions — no fake percentage score.
Legal rules reference official EU materials so the logic can be reviewed as guidance evolves.
Status language below reflects the implementation timeline as of 2026 10 (October 2026). High-risk dates incorporate the Digital Omnibus on AI update reported by official Commission / AI Act Service Desk materials.
1 August 2024
Already applicableRegulation enters into force
Regulation (EU) 2024/1689 entered into force. Application of most obligations followed in stages.
2 February 2025
Currently applicableProhibited practices and AI literacy
Chapter I general provisions (including AI literacy) and Chapter II prohibitions became applicable.
2 August 2025
Currently applicableGPAI model rules and governance
Obligations for providers of general-purpose AI models, related governance arrangements, and certain penalty rules became applicable.
2 August 2026
Currently applicableGeneral application, including transparency
The majority of the AI Act became applicable, including Article 50 transparency obligations. National and EU-level enforcement of applicable rules started for those provisions already in force.
2 December 2026
Upcoming transitionAdditional prohibitions and synthetic-content transition
Certain additional Article 5 prohibitions become applicable. Providers of systems already on the market before 2 August 2026 that generate synthetic content have a transitional deadline for Article 50(2) machine-readable marking.
2 December 2027
Future obligationsAnnex III high-risk obligations
Core high-risk obligations for AI systems classified under Article 6(2) and Annex III (including many employment, education, credit and biometric use cases) apply from this date, following the Digital Omnibus on AI timeline update.
2 August 2028
Future obligationsAnnex I product-embedded high-risk rules
High-risk rules for AI systems that are safety components of products covered by Annex I Union harmonisation legislation apply from this date.
Primary references: AI Act Service Desk timeline, Article 113, European Commission AI Act overview.
Classification depends on context and intended purpose. One checkbox rarely settles the analysis.
Article 5 bans certain manipulative, social-scoring, biometric scraping, emotion-recognition (in workplace/education), and related practices — with narrow exceptions.
Article 6 plus Annex III/I identify systems that may face the heaviest obligations. Many Annex III duties apply from 2 December 2027 under the current timeline.
Article 50 covers human–AI interaction notices, synthetic-content marking, deepfake/public-interest disclosures, and related transparency duties.
GPAI model providers have Chapter V duties. Merely using a third-party model/API is usually a different role.
Many everyday AI uses may not be high-risk, but literacy and (where triggered) transparency duties can still matter.
Since 2 February 2025, providers and deployers should take measures supporting AI literacy for people who operate or use AI systems on their behalf. Think practically: who uses AI, what guidance exists, whether people understand limitations and risks, and whether higher-risk uses get stronger oversight. Article 4 does not invent a mandatory certificate.
Official materials: Article 4 and the Commission AI literacy Q&A. A dedicated AI literacy guide is planned.
The EU AI Act (Regulation (EU) 2024/1689) is the European Union’s horizontal regulation for artificial intelligence. It sets rules for AI systems and general-purpose AI models placed on the market, put into service, or used in ways that engage Union scope — including prohibited practices, high-risk requirements, transparency duties, and GPAI obligations.
Depending on the facts, it can apply to providers, deployers, importers, distributors, certain product manufacturers, authorised representatives, and affected persons in the Union. One company can hold more than one role.
Yes, it can. Non-EU providers placing systems or GPAI models on the Union market, and non-EU providers/deployers whose AI output is used in the Union, may fall within Article 2 scope. Being incorporated outside the EU is not an automatic exemption.
In broad terms: prohibited practices; high-risk AI systems; transparency obligations for certain systems; general-purpose AI model rules; and other systems with lighter or no specific AI Act product duties beyond baseline obligations such as AI literacy where you are a provider or deployer.
A system may be high-risk when it is a safety component of certain regulated products (Annex I route) or when its intended purpose falls into Annex III areas such as certain biometrics, education, employment, essential services, law enforcement, migration, or justice uses — subject to Article 6 and possible derogations. This tool flags signals; it does not certify classification.
Related: high-risk AI systems — dedicated page coming soon.
Article 50 is not one single “label everything AI” rule. It separates human–AI interaction notices, provider marking of certain synthetic outputs, deployer deepfake and public-interest text disclosures, and transparency for emotion recognition / biometric categorisation — each with conditions and exceptions.
Inventory AI systems, clarify whether you provide or deploy them, screen for Article 5 issues, check chatbot/generative transparency, and put basic AI literacy measures in place. If recruitment, credit, biometrics, or other Annex III-like uses exist, start a high-risk classification review early.
The EU AI Act and GDPR can both apply to the same AI system. The AI Act does not replace GDPR. If AI processes personal data, GDPR obligations may remain relevant — lawful basis, purpose limitation, data-subject rights, DPIAs where required, and vendor/processor contracts. This checker does not perform a GDPR assessment.
AuditBird is expanding across frameworks and regulations. See AI compliance and pricing.
Use these alongside the EU AI Act checker while AuditBird grows beyond SOC 2.
Yes. No account and no email are required to see your full structured assessment and next actions.
AuditBird is being built to help growing teams understand requirements, assign owners, manage evidence and keep compliance work moving across frameworks and regulations.
SOC 2 · ISO 27001 · GDPR · and more