Six questions, adapted to your answers. Your system's actual status under Regulation (EU) 2024/1689 — prohibited, high-risk, limited, or minimal — with the obligations, role-specific duties, and exposure that follow.
This determines which obligations apply to you specifically, not just to the system in general.
These are banned outright since 2 Feb 2025. No documentation or safeguard makes them legal.
Eight domains are automatically high-risk under Annex III. A system built into a regulated product follows Annex I instead.
A narrow set of tasks stay exempt from high-risk status — unless the system profiles individuals.
Public-sector deployment, or certain financial-services use cases, add a Fundamental Rights Impact Assessment on top of the standard high-risk obligations.
These disclosure duties stack on top of whatever tier your system lands in. Select all that apply.
This is the same triage logic every AI system in your org needs before it ships — done consistently, at scale, with a paper trail a regulator can follow. The AI Use Case Intake & Risk Register Toolkit turns this exact logic into an 87-question workbook mapped to the EU AI Act, NIST AI RMF, and ISO/IEC 42001.