Skip to content

Quick-check · AI compliance

The EU AI Act Product Quick-Check

The EU AI Act applies since August 2026, and the high-risk obligations land on 2 December 2027. Place every AI feature in its risk tier — the four tiers, the Annex III trigger areas, and the five things a product team must have in place now.

5 min readInteractive

Nobody schedules the classification work. It surfaces the week before a launch, when the answer is expensive.

Eight trigger areas and five must-haves, in the order a product team can actually run them.

Risk tiers
4
Annex III areas
8
Must-haves per team
5
Answers stay in your browser
100%

How it works

  1. Run each feature through it

    Work feature by feature, in the order the steps are laid out.

  2. Your answers stay with you

    Answers are saved only in this browser — no account, nothing to submit.

  3. Take it into the room

    Download the PDF and bring the same questions to the meeting where the decision actually gets made.

At a glance

Format
Quick-check
Topic
AI compliance
Published
Reading time
5 min read
EU AI ActComplianceAI

This is written for product managers, not lawyers. If your product touches the EU market and uses AI, the first job is not compliance — it's classification. You cannot scope the work until you know which tier you're in.

One date to hold on to: the Act has applied in general since 2 August 2026, but the Digital Omnibus on AI moved the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (regulated products under Annex I). That is runway for classification, not a reason to postpone it. Current as of 30 August 2026 — this page is orientation, not legal advice; the consolidated Act on EUR-Lex is the source of truth.

The Act sorts AI systems into four tiers. Most product features land in the bottom two; the cost of being wrong lives in the top two.

  • Unacceptable risk — prohibited. Social scoring, manipulative or exploitative systems, most real-time biometric identification in public spaces. If a feature is here, it doesn't ship in the EU. Full stop.
  • High risk — heavy obligations. Systems used in the contexts listed in Annex III (see Step 2), or that act as a safety component of a regulated product. These duties apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) — the classification work that decides whether they hit you is due now.
  • Limited risk — transparency obligations. Chatbots, generative content, emotion recognition. Users must be told they're interacting with AI; synthetic media must be labelled.
  • Minimal risk — no specific obligations. Spam filters, recommendations, most internal tooling. Document the call and move on.
0 of 8 apply

Annex III lists exactly eight areas. A feature used in any of them is presumed high-risk. Check what applies to your product:

If your feature decides, ranks, or gates a person's access to one of these, assume high-risk until proven otherwise.

Whatever the tier, these five move you from exposed to defensible. Two are duties written into the Act, three are the groundwork that makes those duties cheap. Mark what you already have:

0 of 5 covered

The Act has no finish line — the Digital Omnibus already moved the high-risk dates once. The Commission is still issuing guidance, the AI Office is revising codes of practice, and national regulators are operationalising penalties. Treat classification as a living document you revisit each quarter, not a one-time gate.

Getting the classification right is the cheap part; discovering you were high-risk in production is the expensive one. If you're staring at a backlog of features and aren't sure which ones are already in scope, that triage is exactly the kind of thing I help product teams work through.

Take it with you

The one-page PDF, ready to forward internally.

The conversation after

Thirty minutes, no deck. Bring what you just answered and we work out what it means for your platform.

Discuss what this means for your product

Get in touch