Free · 2 minutes · no sign-up
Does the EU AI Act apply to you?
Everyone’s talking about it; almost no one can tell you whether it’s their problem. Answer a handful of plain-language questions and find out exactly where you stand — what risk level you’re in, what you’d have to do, and what it could cost if you don’t. No legalese, unless you ask for it.

The basics, in plain English
Every idea you need, without the jargon
The EU AI Act runs to hundreds of pages. Here are the handful of ideas that actually decide where you stand — each one you can flip to the exact legal wording whenever you want it.

What counts as an “AI system”?
Software that isn't just following fixed rules a human wrote out. It learns patterns or reasons from what you feed it, and produces things like predictions, recommendations, content, or decisions that affect the world. A spam filter that learns, a CV-ranking model, an image generator, a chatbot — all AI. A plain calculator or an if-this-then-that automation is not.

The four risk levels
The Act sorts AI by how much it could hurt people. Unacceptable risk is banned outright. High risk is allowed but heavily regulated. Limited risk mostly just needs honesty (tell people it's AI). Minimal risk — most software — has no special obligations.

Prohibited practices
A short list of uses the EU considers unacceptable — like manipulating people to their harm, social scoring, scraping faces off the internet to build recognition databases, or reading emotions at work or school. If your system does one of these, it can't be sold or used in the EU at all.

High-risk use cases
AI used in sensitive, high-stakes situations — hiring and firing, credit and insurance, education, healthcare and other essential services, law enforcement, migration, justice, critical infrastructure, or biometric ID. Also AI that acts as a safety component in a regulated product. These are allowed, but come with the heaviest duties.

Transparency duties
Even when AI is low-risk, people deserve to know when they're dealing with it. If users chat with a bot, see AI-generated or deepfake images, or have their emotions or biometrics read, you generally have to tell them — and label synthetic content so it can be recognised.

General-purpose AI models
The big, flexible models (like large language models) that can be adapted to lots of tasks. If you train one yourself, you have extra duties around documentation and copyright. If you just call someone else's model through an API, that's usually them, not you — unless you substantially modify it.

Who are you in the chain?
Your duties depend on your role. The provider builds it. The deployer uses it. Importers and distributors move it along. The same company can wear more than one hat — and if you rebrand or heavily change someone else's system, you can become the provider.

What's at stake
The fines are deliberately large so the rules can't just be ignored. Breaking the outright bans is the most expensive; missing your obligations or misleading regulators cost less, but still run into the millions or a slice of global turnover.