Before you build an AI agent
Six short questions on use case, data and oversight. You get a rough classification and concrete next steps for implementation.
This is not legal advice and does not replace a review by qualified counsel or a data protection officer. The check only provides initial orientation.
Takes about two minutes. Your answers stay in the browser and are not stored.
How the EU AI Act roughly classifies systems
The check above follows the same order as the regulation: prohibitions first, then high-risk, then transparency and cross-cutting duties. This is orientation, not a documented provider assessment under Art. 6(4) and not legal advice.
- Prohibited? Art. 5: manipulative systems, social scoring, exploiting vulnerability and similar bans.
- Product / Annex I? Is the AI a safety component of a regulated product (e.g. medical device, machinery)? Then Art. 6(1) applies.
- Annex III? Eight areas, including HR, education, essential public services, biometrics. Only if the legal test truly fits.
- Does a human decide? Drafts with approval differ from automated effect. Art. 6(3) allows exceptions; profiling cancels them.
- What remains anyway? Even without high-risk: AI literacy (Art. 4), often transparency (Art. 50), plus GDPR and possibly co-determination.
Providers who deliberately classify a system with Annex III relevance as not high-risk should document the reasoning (Art. 6(4)). The online check does not replace that.
What I derive technically from this
Regardless of the result, I design AI solutions so that traceability is built in from the start: audit logs, approval workflows, roles, version history, and documentation of agents and tool calls.
Ready for the next step?
Briefly describe what you have in mind. I usually reply within 1 to 2 business days.