AuditBird

Free interactive compliance tool

Free EU AI Act Compliance Checker

Find out which EU AI Act requirements may apply to your company.

Answer a few questions about how your company builds or uses AI. Get a practical assessment of your likely role, risk areas, transparency obligations and next steps.

Free · No account · No email required

Up to 14 adaptive questions · deterministic rules · not legal advice

About 5–8 minutes

A practical EU AI Act assessment — not a quiz score

Answer based on how your company actually builds or uses AI. The result is a structured decision-tree assessment: likely role, risk areas, transparency signals, and next actions.

  • Adaptive questions — irrelevant follow-ups are skipped
  • Full result shown immediately
  • Runs in your browser — answers are not sent to our servers

Example company: A SaaS company uses an AI customer support chatbot and third-party generative AI internally.

How it works

This is a decision-tree assessment, not an LLM guess. Your answers stay in the browser. The engine maps practical facts to role, risk, transparency, GPAI, literacy, and next-action signals — with source references you can review.

Answer practical questions

No need to already know legal role names. We ask how you build, buy, import, or use AI.

Adaptive follow-ups

Workplace, biometric, and generative-content questions appear only when earlier answers make them relevant.

Structured result

Applicability, likely roles, risk areas, why flags were raised, and prioritized next actions — no fake percentage score.

Source-traceable rules

Legal rules reference official EU materials so the logic can be reviewed as guidance evolves.

EU AI Act timeline

Status language below reflects the implementation timeline as of 2026 10 (October 2026). High-risk dates incorporate the Digital Omnibus on AI update reported by official Commission / AI Act Service Desk materials.

  1. 1 August 2024

    Already applicable

    Regulation enters into force

    Regulation (EU) 2024/1689 entered into force. Application of most obligations followed in stages.

  2. 2 February 2025

    Currently applicable

    Prohibited practices and AI literacy

    Chapter I general provisions (including AI literacy) and Chapter II prohibitions became applicable.

  3. 2 August 2025

    Currently applicable

    GPAI model rules and governance

    Obligations for providers of general-purpose AI models, related governance arrangements, and certain penalty rules became applicable.

  4. 2 August 2026

    Currently applicable

    General application, including transparency

    The majority of the AI Act became applicable, including Article 50 transparency obligations. National and EU-level enforcement of applicable rules started for those provisions already in force.

  5. 2 December 2026

    Upcoming transition

    Additional prohibitions and synthetic-content transition

    Certain additional Article 5 prohibitions become applicable. Providers of systems already on the market before 2 August 2026 that generate synthetic content have a transitional deadline for Article 50(2) machine-readable marking.

  6. 2 December 2027

    Future obligations

    Annex III high-risk obligations

    Core high-risk obligations for AI systems classified under Article 6(2) and Annex III (including many employment, education, credit and biometric use cases) apply from this date, following the Digital Omnibus on AI timeline update.

  7. 2 August 2028

    Future obligations

    Annex I product-embedded high-risk rules

    High-risk rules for AI systems that are safety components of products covered by Annex I Union harmonisation legislation apply from this date.

Primary references: AI Act Service Desk timeline, Article 113, European Commission AI Act overview.

How the EU AI Act risk model works

Classification depends on context and intended purpose. One checkbox rarely settles the analysis.

Prohibited practices

Article 5 bans certain manipulative, social-scoring, biometric scraping, emotion-recognition (in workplace/education), and related practices — with narrow exceptions.

High-risk AI systems

Article 6 plus Annex III/I identify systems that may face the heaviest obligations. Many Annex III duties apply from 2 December 2027 under the current timeline.

Transparency-related obligations

Article 50 covers human–AI interaction notices, synthetic-content marking, deepfake/public-interest disclosures, and related transparency duties.

General-purpose AI

GPAI model providers have Chapter V duties. Merely using a third-party model/API is usually a different role.

Other / minimal-risk systems

Many everyday AI uses may not be high-risk, but literacy and (where triggered) transparency duties can still matter.

AI literacy

Since 2 February 2025, providers and deployers should take measures supporting AI literacy for people who operate or use AI systems on their behalf. Think practically: who uses AI, what guidance exists, whether people understand limitations and risks, and whether higher-risk uses get stronger oversight. Article 4 does not invent a mandatory certificate.

Official materials: Article 4 and the Commission AI literacy Q&A. A dedicated AI literacy guide is planned.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the European Union’s horizontal regulation for artificial intelligence. It sets rules for AI systems and general-purpose AI models placed on the market, put into service, or used in ways that engage Union scope — including prohibited practices, high-risk requirements, transparency duties, and GPAI obligations.

Who does the EU AI Act apply to?

Depending on the facts, it can apply to providers, deployers, importers, distributors, certain product manufacturers, authorised representatives, and affected persons in the Union. One company can hold more than one role.

Does the EU AI Act apply to non-EU companies?

Yes, it can. Non-EU providers placing systems or GPAI models on the Union market, and non-EU providers/deployers whose AI output is used in the Union, may fall within Article 2 scope. Being incorporated outside the EU is not an automatic exemption.

What are the EU AI Act risk categories?

In broad terms: prohibited practices; high-risk AI systems; transparency obligations for certain systems; general-purpose AI model rules; and other systems with lighter or no specific AI Act product duties beyond baseline obligations such as AI literacy where you are a provider or deployer.

What is a high-risk AI system?

A system may be high-risk when it is a safety component of certain regulated products (Annex I route) or when its intended purpose falls into Annex III areas such as certain biometrics, education, employment, essential services, law enforcement, migration, or justice uses — subject to Article 6 and possible derogations. This tool flags signals; it does not certify classification.

Related: high-risk AI systems — dedicated page coming soon.

What are Article 50 transparency obligations?

Article 50 is not one single “label everything AI” rule. It separates human–AI interaction notices, provider marking of certain synthetic outputs, deployer deepfake and public-interest text disclosures, and transparency for emotion recognition / biometric categorisation — each with conditions and exceptions.

What should startups do first?

Inventory AI systems, clarify whether you provide or deploy them, screen for Article 5 issues, check chatbot/generative transparency, and put basic AI literacy measures in place. If recruitment, credit, biometrics, or other Annex III-like uses exist, start a high-risk classification review early.

EU AI Act vs GDPR

The EU AI Act and GDPR can both apply to the same AI system. The AI Act does not replace GDPR. If AI processes personal data, GDPR obligations may remain relevant — lawful basis, purpose limitation, data-subject rights, DPIAs where required, and vendor/processor contracts. This checker does not perform a GDPR assessment.

AuditBird is expanding across frameworks and regulations. See AI compliance and pricing.

Related free tools

Use these alongside the EU AI Act checker while AuditBird grows beyond SOC 2.

Questions

Yes. No account and no email are required to see your full structured assessment and next actions.

Turn AI requirements into an actual compliance plan.

AuditBird is being built to help growing teams understand requirements, assign owners, manage evidence and keep compliance work moving across frameworks and regulations.

SOC 2 · ISO 27001 · GDPR · and more