How we classify — and why you can defend it
A risk classification is only worth something if you can stand behind it. So ours isn't a black box or a chatbot's opinion — it's a deterministic engine that binds every verdict to the exact provision of the Regulation (EU) 2024/1689 (EU Artificial Intelligence Act) that decided it, and tells you honestly where the law itself is contested.
Deterministic, never a guess
The same inputs always produce the same class. There is no model temperature, no black box — a fixed set of rules drawn straight from the Act decides, and you can reproduce it every time.
Every verdict cites the exact law
Each factor that determines a class is bound to its precise provision — the article or Annex point — with a faithful summary of what it says. A classification you can hand an auditor, not just a colour.
Versioned to the law
Every classification is stamped with the legal basis it was made under, so you always know which state of the Act — including the 2026 Digital Omnibus changes — produced it.
Honest where the law is contested
The Act is deliberately vague in places. Rather than fake certainty, we flag genuinely debated boundaries, give the argument both ways, and recommend the safer course — so you can document your reading.
No AI decides your risk class
Our optional AI assistant explains obligations and drafts documents. It never decides the classification — that stays fully rule-based, so the answer can always be traced to a rule and a provision.
We publish the method
Most tools hide how they classify. We publish it, because a compliance decision you cannot inspect is not one you can defend. Read the rules, check our citations, hold us to them.
How the engine decides
Every AI system runs through the same fixed order of questions, drawn directly from the Act. The first tier it matches is its class:
- 1In scope?
Is the system used, or its output used, in the EU (Art. 2)? If not, the Act's obligations generally don't apply.
- 2Prohibited?
Does it match a banned practice under Article 5 — social scoring, manipulation, workplace/education emotion recognition, unlawful biometric identification? If so, it cannot be placed on the market as described.
- 3High-risk?
Is it an Annex III use case — employment, credit, insurance, education, essential services, law enforcement, migration, justice, biometrics or critical infrastructure? If so, the full obligation set applies.
- 4Transparency?
Does it trigger Article 50 — a chatbot, generated content, a deepfake, or emotion/biometric-categorisation? If so, disclosure and marking duties apply.
- 5Minimal.
If none of the above, the system carries no mandatory obligations — only voluntary good practice.
Behind those tiers sits a provenance registry of 20 legal anchors — each classification factor mapped to its precise article or Annex point, its status and its penalty tier. When you classify a system, you can export a Classification Rationale: every factor, its citation, the confidence, and — where relevant — an honest note on where reasonable readings differ.
What this is — and isn't
This engine automates the organisational and documentation work of classification: it is fast, reproducible and fully cited. It is not legal advice, and for genuinely contested edge cases it will say so and point you to counsel rather than manufacture certainty. The goal isn't to replace a lawyer — it's to give you, and your lawyer, a defensible, article-by-article starting point instead of a blank page.
See it decide your system
Run the free risk check and get your class in two minutes — with the articles behind it.