Is your AI system high-risk?
Common AI systems, each run through the AnnexWise classification engine and published with whatever it returned: the risk tier, every obligation with the date it binds, and the single answers that would move the verdict. Same engine as the product, no language model in the verdict path.
Prohibited practice
Banned outright under Article 5. No runway, no conformity route — the answer is to stop.
Inferring emotions from workers is an Article 5 prohibited practice, not a high-risk category with a 2027 runway. What that means for a system already in production.
Article 5 bans scoring people by general behaviour where it leads to unjustified detrimental treatment. Where an ordinary customer-scoring system crosses that line.
High-risk system
The full obligation stack, on the timeline the Omnibus postponed to December 2027 or August 2028.
A CV-screening or candidate-ranking system classified by the AnnexWise engine: risk tier, every applicable obligation with the date it binds, and what would change the verdict.
The obligations that land on the employer deploying a third-party AI hiring tool, as opposed to the vendor building it — computed by the AnnexWise engine, article by article.
Creditworthiness evaluation is named in Annex III point 5(b). The AnnexWise engine's verdict for a credit-scoring system: tier, obligations, binding dates and counsel flags.
Risk assessment and pricing in life and health insurance sits in Annex III point 5(c). What the deploying insurer owes, including the fundamental rights impact assessment.
Monitoring and detecting prohibited behaviour during tests is named in Annex III point 3. The engine's verdict for a proctoring system, with every obligation and its date.
Remote biometric identification sits in Annex III point 1, and one-to-one verification is expressly carved out of it. Which side of that line an access system falls on, and what it owes if it lands on the wrong one.
AI inside a regulated product follows the Annex I route, and the Omnibus moved it to a different date from Annex III. Which one binds, and what the second limb of Article 6(1) changes.
Limited risk — transparency duties
No high-risk category, but Article 50 transparency duties — and those have been enforceable since August 2026.
A support chatbot is rarely high-risk and never exempt. What Article 50 requires, what it costs to comply, and why the date on this one has already passed.
Synthetic text, image, audio and video carry Article 50 marking duties that have been enforceable since August 2026. What the engine says applies, and from when.
Deploying deepfake content triggers Article 50 disclosure duties that are live now, not in 2027. The engine's verdict for an advertiser using synthetic likenesses.
Minimal risk
No mandatory product obligations beyond AI literacy. Most systems land here, and saying so is the point.
Annex III point 5(b) covers creditworthiness but expressly excludes AI used to detect financial fraud. The engine's verdict for a fraud system, and where the exclusion stops.
Most industrial AI is minimal risk, and the honest answer is a short one. What still applies — including the Article 4 literacy duty that has been live since February 2025.
None of these is your system
They are generic configurations, and a single different answer moves the verdict. The free assessment settles yours in about ten minutes and runs entirely in your browser.
Start a free assessment →Prefer the reasoning to the verdicts? The guides walk through the law itself, and /methodology publishes every rule the engine applies.