Skip to content
NLEN
Illustration: EU AI Act Category Checker

EU AI Act category checker

By Ivo Donker - 6 August 2026

🔒 100% Client-side: No data ever leaves your device. All calculations take place locally in your browser.
Progress Question 1 of 4

Step 1: What is your role in this AI application?

Obligations under the EU AI Act differ significantly depending on your organization's role in the value chain.

    Explicit disclaimer: This tool provides an indicative first assessment based on the answers entered. It does not constitute formal legal advice. To determine exactly which specific legal requirements apply to your situation, tailored guidance and a thorough legal & compliance audit are required.

    How risk categories and roles work under the EU AI Act

    The European AI Regulation (EU AI Act) introduces a risk-based approach to regulating artificial intelligence within the European Union. The underlying principle is that regulatory pressure and obligations increase proportionally with the potential risk of harm the AI application poses to citizens' safety, health, or fundamental rights.

    The four risk categories at a glance

    Why the role (Provider vs. Deployer) is crucial

    When determining your obligations, it's not enough to look only at the category of the system. The EU AI Act draws a strict legal distinction between the Provider and the Deployer:

    A Provider is the party that develops the AI system (or has it developed) and places it on the market or puts it into use under its own brand name. Providers carry the heaviest set of obligations: among other things, they must set up risk management systems, ensure data governance, draw up technical documentation, carry out conformity assessments, and affix the CE marking.

    A Deployer is the organization that deploys an externally sourced or provided AI system within its professional activities. Their task lies primarily in correctly applying the system according to the provider's instructions, setting up human oversight during operational use, and monitoring any risks in the workplace.

    Integration into your organization and governance

    Determining the category is the first step in responsible implementation. For organizations deploying AI solutions, building a structural AI governance for SMEs is essential to guarantee compliance and operational continuity.

    For high-risk AI applications, a prior AI risk analysis and DPIA is also often required to identify potential impact on fundamental rights and privacy in good time. To give employees clear guidelines on what is and isn't permitted, establishing an internal AI policy is essential. Also make sure that agreements with external software vendors are clearly contracted.

    For extensive background on the structure of the legislation, you can also EU AI Act explanation on nieuws.llmnet.nl is worth consulting.