Does the EU AI Act apply to you?

Six questions, two minutes. Deadlines reflect the Digital Omnibus — the July 2026 amendment most checklists haven't caught up with.

General regulatory information, not legal advice. Based on Regulation (EU) 2024/1689 as amended, and Commission guidance as of August 2026.

How this check works

The checker asks you six questions about how your company touches AI: whether you develop or brand AI systems, whether your staff use third-party AI tools, whether any use falls into a sensitive Annex III area (such as recruitment or credit), whether you operate chatbots or generate synthetic content, whether you use emotion recognition or biometric categorisation, and your company size. From your answers it derives your likely role under the EU AI Act — provider, deployer, or both — and maps the obligations that attach to that role today and at the upcoming deadlines, with article references for each.

The check runs entirely in your browser. Your answers are never transmitted, stored or logged — no data leaves your device, and you can verify this: the page makes no network requests when you answer. There is no signup and no tracking of your responses.

Who the EU AI Act applies to

The AI Act — Regulation (EU) 2024/1689, as amended by the Digital Omnibus, Regulation (EU) 2026/1744 — applies to providers placing AI systems or general-purpose AI models on the EU market wherever they are established; to deployers using AI systems professionally in the EU; to providers and deployers outside the EU where the system's output is used in the EU; and to importers and distributors (Article 2). Purely personal, non-professional use is out of scope. In practice, almost any company whose staff use AI tools at work, or whose products contain AI, has at least some obligations — company size does not remove them, though SMEs, start-ups and small mid-caps benefit from proportionate fine caps under Article 99(6).

Provider vs deployer in one paragraph

A provider develops an AI system (or has it developed) and places it on the market or puts it into service under its own name or trademark, paid or free (Article 3(3)); a deployer uses an AI system under its own authority in a professional context (Article 3(4)). The role is assessed per system — one company is often provider of its own AI feature and deployer of the third-party tools its staff use — and it decides your duties: providers owe the market a compliant product, deployers owe affected people a responsible use of it. Beware the white-label trap: putting your own name or trademark on someone else's system, or substantially modifying a high-risk system, can make you its provider (Article 25(1)). Full guide: provider vs deployer.

Which obligations are in force in 2026

As of August 2026 the binding layers are:

  • Article 5 prohibited practices — since 2 February 2025; the new CSAM/NCII prohibitions added by the Omnibus apply from 2 December 2026.
  • Article 4 AI literacy — since 2 February 2025; as amended, a duty to take measures supporting the development of sufficient AI literacy among staff, with no guaranteed competence level required per individual.
  • Article 50 transparency — since 2 August 2026: providers must design in AI-interaction disclosure (50(1)) and machine-readable marking of synthetic content (50(2), grace until 2 December 2026 for generative systems on the market before 2 August 2026); deployers must inform about emotion recognition and biometric categorisation (50(3)) and disclose deepfakes and AI-generated public-interest text (50(4)).
  • General-purpose AI model rules — since 2 August 2025 for model providers, enforceable with fines up to €15 million or 3% since August 2026.

Not yet in force: the high-risk obligations — 2 December 2027 for Annex III systems, 2 August 2028 for Annex I products. See the full deadline timeline.

What your result means — and what it is not

Your result is a structured first assessment: the role the Act most likely assigns you for the uses you described, the obligations attached to that role, and the deadlines to diarise. Use it to scope your compliance work and to pick the right templates — it maps directly onto our seven-step compliance checklist.

What it is not: legal advice, or a determination by any authority. The checker works from six answers; real classification can turn on facts a short questionnaire cannot capture — contractual arrangements, substantial modifications, whether a system performs profiling, or whether an Article 6(3) derogation is available. Borderline cases (white-labelling, fine-tuned models offered to customers, possible Annex III uses) deserve a documented per-system assessment and, where the stakes are high, qualified legal advice. Treat the result as your starting map, not your final classification.

Methodology and primary sources

The checker's logic is built directly on the primary texts: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force 27 July 2026) — including the amended Article 4 standard, the post-Omnibus deadlines (2 December 2026 for the new prohibitions and the marking grace period; 2 December 2027 for Annex III; 2 August 2028 for Annex I), the Article 50 provider/deployer split as confirmed by the Commission's July 2026 transparency guidelines, and the Article 99(6) fine caps for SMEs, start-ups and small mid-caps (Recommendation (EU) 2025/1099).

We maintain a public changelog for the checker: every change to the question logic or obligation mapping is dated and referenced to the legal source that prompted it, so you can see exactly which version of the law your result reflects. When guidance or amendments land — such as the post-market-monitoring guidance the Commission must issue by 2 September 2027 — the logic and changelog are updated together.

Checker FAQ

Is my data stored when I use the checker?+

No. The check runs entirely in your browser; your answers are never sent to a server, stored or logged. Closing the page discards them.

Is the result legal advice?+

No. It is an informational first assessment based on six questions and the current text of the AI Act as amended. Borderline classifications — white-labelling, substantial modifications, possible Annex III uses — need a documented per-system assessment and, where stakes are high, qualified legal advice.

Is the checker up to date with the Digital Omnibus?+

Yes. The logic reflects Regulation (EU) 2026/1744 (in force 27 July 2026), including the amended Article 4, the new prohibitions from 2 December 2026, and the postponed high-risk deadlines of 2 December 2027 (Annex III) and 2 August 2028 (Annex I). A public changelog documents every update.

What should I do with my result?+

Use it to scope your compliance work: confirm your role per AI system in an inventory, then work through the obligations the result lists — prohibition screening, Article 4 literacy measures, Article 50 duties — using our step-by-step checklist and templates.

Last reviewed: 26 August 2026 · Primary sources: Regulation (EU) 2024/1689 (consolidated), Regulation (EU) 2026/1744 (Digital Omnibus on AI).