# EU AI Act risk level test

Five questions to classify your use of AI under Regulation (EU) 2024/1689 and see which obligations apply and from when. Updated with the June 2026 Digital Omnibus, which deferred the high-risk rules.

- Human version: https://rubitec.co/tools/eu-ai-act-risk-test
- All tools: https://rubitec.co/tools
- llms.txt: https://rubitec.co/llms.txt

Free tool by Rubitec. No sign-up required and the calculation runs in the browser.

## What it asks for

| Input | Default value |
| --- | --- |
| 1. What is your relationship to the AI system? | We are deployers: we use third-party AI in our operations |
| 2. Does the system do any of the following? | No, none of them |
| 3. Is it used in any of these areas? | No, none of those |
| 4. Does it interact with people or generate content? | Yes, it talks to people or generates content |
| 5. Do you train or release your own general-purpose AI model? | No |

## Example with default values

| Result | Value |
| --- | --- |
| Risk level | Transparency risk |
| Date it applies to you | 2 August 2026 |
| Maximum penalty | €15M or 3% of worldwide turnover |
| Your role under the Regulation | Deployer |

### Your main obligation is disclosure, and it applies from 2 August 2026

Article 50 was not deferred by the Digital Omnibus. It is the live date on the calendar and the one that affects almost any SME using a chatbot or a phone agent. The good news is that compliance is cheap.

- Clearly disclose that the person is interacting with an AI, at the start of the conversation and without them having to ask.
- Mark AI-generated or manipulated content in a machine-readable format.
- Visibly label deepfakes and published text on matters of public interest.
- Ensure a sufficient level of AI literacy among the people operating the system, an obligation in force since February 2025.

## How it is calculated

Regulation (EU) 2024/1689 classifies AI systems into four levels: unacceptable risk (banned by Article 5), high risk (Annex III for standalone systems in sensitive areas, Annex I for safety components of already regulated products), transparency risk (Article 50) and minimal risk.

The test applies that order of precedence: first banned practices, then high risk, and only then transparency obligations. A high-risk system that also talks to people has to meet both.

Timeline in force after the Digital Omnibus on AI, adopted by the European Parliament on 16 June 2026 and the Council on 29 June 2026: prohibitions and AI literacy since 2 February 2025, general-purpose models since 2 August 2025, Article 50 transparency from 2 August 2026 (unchanged), Annex III high risk from 2 December 2027 and Annex I high risk from 2 August 2028.

Penalties reach €35M or 7% of worldwide turnover for banned practices, €15M or 3% for other obligations and €7.5M or 1% for supplying incorrect information to authorities. For SMEs and startups the lower of the two amounts applies, not the higher.

> **Notice.** General guidance, not legal advice. Final classification depends on the system's specific purpose and context of use, and should be checked with a specialist before making decisions.

## Frequently asked questions

### Is a chatbot or AI phone agent high risk?

Usually not. An agent that answers calls, books appointments and handles FAQs is transparency risk: the obligation is to tell the caller they are speaking to an AI. It would only become high risk if used to screen job candidates, decide access to an essential service or something similar from Annex III.

### What did the 2026 Digital Omnibus change?

It deferred the high-risk obligations: Annex III moved from 2 August 2026 to 2 December 2027, and Annex I from 2 August 2027 to 2 August 2028. It did not touch the prohibitions, the general-purpose model rules, or the Article 50 transparency date, which remains 2 August 2026.

### If I use ChatGPT at work, am I a provider or a deployer?

A deployer. The provider is whoever develops the system and places it on the market under their own name. That said, if you take a third-party model and market it under your own brand or substantially change its purpose, you become a provider and take on those obligations.

### Does the Regulation apply to a five-person SME?

Yes. There is no size or turnover threshold: obligations depend on the system's risk level, not the company's size. What SMEs do get are capped penalties, regulatory sandboxes and simplified technical documentation.

### What happens if my system is high risk and I do nothing?

From the date that applies to you, the national market surveillance authority can require withdrawal of the system and impose fines of up to €15M or 3% of worldwide turnover. Before that date there is no penalty, which is why the window to December 2027 is time to document, not time to ignore it.

## Related links

- [Full EU AI Act guide for SMEs](https://rubitec.co/guia-eu-ai-act)
- [GDPR checklist for generative AI](https://rubitec.co/tools/gdpr-generative-ai-checklist)
- [How to comply with the EU AI Act as an SME](https://rubitec.co/insights/como-cumplir-eu-ai-act-pyme)
