EU AI Act Risk Classifier
Classify your AI system into its EU AI Act risk tier — prohibited, high-risk, limited-risk or minimal-risk, plus the GPAI track — and read off the applicable articles by role, the in-force date, and the Article 99 fine ceiling.
Regulation (EU) 2024/1689 · Regulation snapshot: 2026-09-25
- Risk tiers
- 4 Prohibited · high-risk · limited-risk · minimal-risk, plus the GPAI track.
- In-force dates
- 3 2 Feb 2025 prohibited · 2 Aug 2025 GPAI · 2 Dec 2027 high-risk (Annex III).
- Max fine
- 7% Up to €35M or 7% of worldwide turnover (Art. 99(3)).
Key tiers, dates and fines at a glance
Updated 2026-09-25. Under Regulation (EU) 2024/1689, as amended by the AI Omnibus (in force since 27 July 2026), the application date depends on the risk tier: prohibited practices have applied since 2 Feb 2025, GPAI-model obligations since 2 Aug 2025, and Article 50 transparency rules since 2 Aug 2026. Annex III high-risk systems now apply from 2 December 2027, and high-risk AI that is a safety component of an Annex I regulated product applies from 2 August 2028 (Article 113(c)) — both moved back from the original 2 Aug 2026 / 2 Aug 2027 dates by the AI Omnibus. Maximum administrative fines are €35M or 7% of worldwide turnover for prohibited practices (Article 99(3)) and €15M or 3% for other high-risk and transparency breaches (Article 99(4)); minimal-risk systems carry no fine tier — both unchanged by the AI Omnibus. The AI Omnibus also added new prohibited practices (e.g. AI-generated non-consensual intimate imagery / "nudification" apps) not yet reflected in the Article 5 checklist below — verify against the current consolidated Article 5 text.
The Act sorts every AI system into a risk pyramid. UNACCEPTABLE practices are banned outright (Article 5) — social scoring, manipulative or exploitative systems, and untargeted scraping of facial images. HIGH-RISK covers the Annex III use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) plus AI that is a safety component of an Annex I product — these face conformity assessment, risk management, data governance, human oversight and registration (Article 6). LIMITED-RISK systems such as chatbots and deepfakes carry transparency duties only (Article 50). MINIMAL-RISK systems have no obligations beyond voluntary codes (Article 95). General-purpose AI (GPAI) models follow their own track (Articles 53 / 55).
The AI Omnibus simplification package — proposed 19 Nov 2025, reaching a provisional political agreement on 7 May 2026 — was formally adopted and entered into force on 27 July 2026. It pushed the high-risk Annex III deadline to 2 Dec 2027 and the Annex I safety-component deadline to 2 Aug 2028; the dates above already reflect this adopted law, not a proposal.
Frequently asked questions
When do the EU AI Act high-risk rules apply?
Under the law in force (as amended by the AI Omnibus, in force since 27 July 2026), Annex III high-risk systems apply from 2 December 2027 and high-risk AI that is a safety component of an Annex I regulated product applies from 2 August 2028 (Article 113(c)). These dates were pushed back from the original 2 August 2026 / 2 August 2027 by the AI Omnibus, which reached a provisional agreement on 7 May 2026 and was formally adopted before the original deadline arrived.
What is the maximum fine under the EU AI Act?
Up to €35 million or 7% of total worldwide annual turnover (whichever is higher) for breaching the Article 5 prohibited practices (Article 99(3)), and up to €15 million or 3% for other high-risk and Article 50 transparency obligations (Article 99(4)). For SMEs and start-ups, Article 99(6) applies whichever amount is lower. These ceilings are unchanged by the AI Omnibus.
Is there a fine for minimal-risk AI systems?
No. Minimal-risk systems carry no AI Act obligations beyond voluntary codes of conduct (Article 95), so there is no obligation to breach and no administrative-fine tier. (Article 99(5)'s €7.5M / 1% tier penalises supplying incorrect or misleading information to authorities — it is not a tier for minimal-risk classification.)
Do different roles in the value chain have different obligations?
Yes. Providers carry the full design and quality-management stack (Article 16); deployers carry use obligations (Article 26); importers (Article 23), distributors (Article 24) and product manufacturers (Article 25) each have their own narrower verification duties. This tool maps obligations to the role you select.
Does this tool give legal advice?
No. It is a structured estimate based on the published text of Regulation (EU) 2024/1689 as amended by the AI Omnibus, and the official implementation timeline. It does not assess Annex I harmonised conformity routes, substantial-modification triggers, or national derogations. Verify against the consolidated regulation and engage qualified counsel before acting.