The rule set behind your result

Your screening is produced by a deterministic rules engine, not a model. This page states which version of that rule set is live, which law it was checked against, and what changed in each revision, so a result can be read against the rules that produced it.

Rule set version
v2.0
Law as at
27 Aug 2026
Review cadence
Every 3 months
Next review
27 Nov 2026

What it is built on

  • Regulation (EU) 2024/1689 (the EU AI Act), in force since 1 Aug 2024.
  • Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published in the Official Journal on 24 Jul 2026 and in force since 27 Jul 2026. Where the two differ, the amended text is the one applied.
  • The Annexes and Recitals as amended, and the Commission guidelines published to date. Draft guidance is treated as non-binding and is flagged where it is relied on.

What changed, and when

v2.0 27 Aug 2026

  • Ticking one of the two Digital Omnibus prohibitions no longer ends the screening by itself: a follow-up question decides the result. On the intimate-material row the only exits are the depicted person's five-way qualified consent or the material falling outside the definition (Art. 5(1b)); on the child sexual abuse row the only exception is a national-law defence that counsel has to confirm, so that path is held open rather than cleared.
  • A deployer-only respondent who ticks either row is asked the specific-use question rather than the provider tests, and is asked it even where the declared content forms would otherwise have skipped that block.
  • A product that needs third party conformity assessment only for reasons unrelated to health and safety (for example radio spectrum or electromagnetic interference) no longer opens the Annex I high-risk route: a follow-up question applies the new Art. 6(1c) carve-out, and the Annex III assessment continues in full.
  • The transitional bands now follow the route: the Chapter III date is 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, and answering Don't know applies the earliest band so deadlines are never understated.
  • The synthetic-content question now states the deep-fake disclosure duty correctly: audio is covered, and generated text carries the duty only where it is published to inform the public on matters of public interest, which a follow-up asks.
  • The two Annex I product groups that read across the Section A boundary are tightened to their instruments (marine equipment under Directive 2014/90/EU; machinery under Regulation (EU) 2023/1230), each with a line steering Section A products to None of these.

v1.9 26 Aug 2026

  • The content-form question is asked once, covers audio, and one answer now decides the Article 5 entry and both Article 50 transparency duties (the separate synthetic-content and deep-fake questions are retired).
  • The intimate-imagery and child sexual abuse prohibitions are asked as separate questions with their own legal tests; deployers are asked only the specific-use question, and a lawful-use answer (for example detection and removal work) raises a legal review instead of a prohibited result.
  • The prohibited-practices checklist now lists all ten Article 5 points: the two practices added by the Digital Omnibus appear as their own rows, applicable from 2 December 2026, and ticking one is a declaration handled with the same lawful-use review route.
  • Systems covered by Annex I Section B product legislation are now asked the question that decides their route: whether the product must undergo third party conformity assessment (Art. 6(1)(b)). Previously the screening ended at the Section B answer without asking it, so it could neither reach high-risk nor rule it out.
  • Answering No to that question no longer ends the classification: the Annex III use cases are assessed next, exactly as they are for every other system. Answering Don't know holds the result at its worst case and marks the question as open.
  • Every result now states a risk level (High risk, Limited risk, Minimal risk, Unacceptable risk, Outside the scope of the AI Act, or Risk level not yet determined) alongside the legal regime, instead of the regime label alone.
  • The three Article 25 questions (own name or trademark, substantial modification, changed intended purpose) are asked as one factual question. The deemed-provider rule is applied by the engine once the risk level is known: it engages only for a high-risk system, and the result names which act triggered it. Answering Don't know still applies the provider duties conservatively until confirmed.
  • The four Article 6(3) narrow-task conditions are asked as one question instead of four screens. Each claimed condition still requires the documented derogation assessment (Art. 6(4)), and answering Don't know is treated as claiming none, so it cannot lower the classification.
  • The general-purpose AI questions now establish their subject first: whether this is a general-purpose AI system built on a model is asked before the questions that refer to that model. The systemic-risk question asks Is this one of the largest AI models on the market, with the below-threshold answer first, the two classification routes (the training-compute presumption and Commission designation) as separate answers, a dedicated answer for a notified Art. 52 rebuttal, and a plain-language FLOP tooltip.
  • Facts already given are no longer re-asked: the emotion-recognition and biometric-categorisation transparency duty (Art. 50(3)) is applied from the biometrics answer for deployers, and the credit-scoring and insurance category of the fundamental-rights impact assessment (Art. 27) is applied from the Annex III answers. The impact-assessment question is asked only of deployers, the side the duty binds.
  • The open-source question asks only whether the system is released under a free and open-source licence. The Art. 2(12) exclusion is applied by the engine after the full assessment: it applies only where the system is not high-risk or prohibited and carries no Article 50 duties, and the result explains the outcome either way.
  • The territorial question is one multi-select covering each Article 2(1) connection to the EU as its own row, including use of the system's output in the Union. Outside the scope of the AI Act is reached only by answering None of these; answering Don't know keeps the system in scope until confirmed.
  • The three system-fact questions (AI literacy measures, when the system was first made available, and component supply into another high-risk system) moved from the scope section to the facts section at the end of the assessment, where they sit with the other questions that refine obligations rather than decide the classification.
  • A batch of question-wording corrections from the reviewer's copy sheet: the regulated-products question names the products rather than the legislation (with the machinery consequence note, and Not sure treated as none of these); the direct-interaction question asks about people, explains the obviousness carve-out, and its No names the alternative; the exclusions stem says exclusively for one or more; the AI-literacy panel states the amended duty of effort; the size-class question carries the thresholds inline and is saved for the organisation; the future placement band is removed in favour of an optional planned date on Not yet placed.
  • Every Don't know answer now states its treatment in a sub-line before you choose it (for example: treated as Yes, so it cannot lower your risk classification), and every answer that ends the screening says so and why. The rule is enforced structurally, so a future question cannot ship a silent Don't know or a silent terminal answer.
  • Every multiple-choice question now lists its answers in the same order: the substantive options first, then None of these, then Don't know. The Annex III screens previously placed Don't know before None, so the escape hatch sat in a different place from every other screen.

v1.8 4 Aug 2026

  • The biometrics question now asks whether the system recognises or infers people's emotions (Annex III point 1(c)). It was missing, so a system inferring emotions outside the workplace and education could be told it was not high-risk when the Act says it is.

v1.7 2 Aug 2026

  • When determinative questions are still unanswered, your result now says so plainly: the class is named at its worst case rather than stated as settled, and the next steps are held back until you close them.
  • Your obligations are never hidden while a result is provisional. They are relabelled as what would apply if the open questions resolve the worst way, and answering can only narrow the list.
  • Every open question, and every follow-up task, now links straight to the question that raised it.
  • You can re-assess a system without deleting it. Your previous answers are carried over, you are asked to confirm before the stored assessment is replaced, and the old one stays in the system's history.
  • The downloadable report no longer states a verdict as settled when the screen has declined to.
  • Fixed: un-checking a prohibited practice you had ticked no longer records that none of them apply.

v1.6 2 Aug 2026

  • The eight prohibited practices (Art. 5) are now one screen instead of eight, and you can mark any of them 'not sure' rather than having to answer yes or no.
  • The scope question split in two: whether the system is placed on the EU market, and whether its OUTPUT is used in the EU. A system built outside the EU whose output lands here stays in scope.
  • The NCII question split into intent, reproducibility and safeguards, so a 'no' now says which of the three you are relying on.
  • The Annex I question split into three, separating the product legislation, the safety-component test and the third-party conformity assessment.
  • The Annex III high-risk areas are now asked by sub-limb, so your result names the specific point of Annex III that applies rather than the area.
  • The Art. 25 substantial-modification question separates the change itself from whether it was foreseen in the original design.
  • Every question about the AI-Act role you hold now asks it once, and the questions that follow are the ones that bind that role.

v1.5 2 Aug 2026

  • You can now hold several operator roles at once, and your result shows every one of them with the duties attached to each.
  • A substantial modification (Art. 25) now ADDS the provider's duties to the ones you already held, instead of replacing them.
  • The four Art. 50 transparency questions are asked by role: providers are asked about 50(1) and 50(2), deployers about 50(3) and 50(4).
  • Added a 'not sure which role we hold' answer. It raises the question for legal review and, until it is resolved, applies both the provider and the deployer duties.

v1.4 2 Aug 2026

  • Added the AI-literacy question (Art. 4) and the training follow-up it raises.
  • Added the Art. 111 transitional band, so a system already on the market before general application is told which timeline binds it.
  • Added the Art. 25(4) component-supply question, which raises the provider's information duty to a downstream integrator.
  • Added the Art. 54 authorised-representative question and the Art. 53 systemic-risk follow-up for GPAI-model providers.
  • Added the Art. 6(1c) carve-out to the Annex I question: a product whose only third-party conformity trigger is a non-health-and-safety risk is no longer routed as high-risk on that basis alone. It requires supporting evidence.
  • Your result and its export now state the intended purpose they were assessed against.

v1.3 1 Aug 2026

  • A result now says how much of the determinative questionnaire it rests on, and which questions were left as Don't know.
  • S-03 (the Art. 2 carve-outs) gained a Don't-know, and a Don't-know there no longer takes the system out of scope.
  • Corrected the safety-component definition to the narrowed Omnibus test, and added the provider, deployer, intended-purpose and substantial-modification terms.
  • Dropped the projected question total, which shrank as the walk narrowed, and labelled stages the walk skipped.
  • Added the Annex I equivalence note, the SME penalty cap on prohibited results, and a Don't-know note carried onto the follow-up task and the export.

v1.2 1 Aug 2026

  • Rewrote the question stems in plain language and separated our reading of a provision from the statute itself.
  • Reframed every result headline as an indicative classification, stating the answers it rests on.
  • Added the Art. 27(2) FRIA timing, the Annex VIII Section B filing, and the SME/SMC definitions and reliefs.

v1.1 1 Aug 2026

  • Put Regulation (EU) 2026/1744 (Digital Omnibus on AI) in force: the amended dates below are now the binding ones.
  • Relabelled the timeline columns so the binding column and the superseded 2024/1689 column are unambiguous.

v1.0 12 Jul 2026

  • First published rule set: the post-Omnibus screening engine and its nine result nodes.

What this page is not

This is a screening aid, not legal advice, and it is not an audit. Member States may adopt stricter national rules, and a determination can change on facts you have not given us. Where a question was left as Don't know, the result says so.