SimpleAct Logo

EU AI Act · Art. 2, 5, 50 · Annex III

Are you affected by the EU AI Act?

Six questions, one reasoned first assessment: whether you fall within scope, which risk class is likely, and which obligations and deadlines follow from it.

Takes about 2 minutes · No sign-up, no email · Result right here on this page

Question 1 of 6

Does your organisation use or offer AI systems?

Bought-in tools count – ChatGPT, Copilot, chatbots, applicant screening or AI features inside your industry software.

What the check covers

The check follows the same order an auditor would take: scope first, then role, then risk class.

Art. 2
Scope

Do you use AI – and is there an EU link? The market-location principle also captures providers outside the EU as soon as the output is used in the EU.

Art. 3 & 25
Your role

Provider or deployer? Substantially modifying a bought-in system or offering it under your own name makes you the provider – with considerably more obligations.

Annex III
High-risk areas

HR, credit, education, critical infrastructure, biometrics, law enforcement, essential services and safety components of regulated products.

Art. 5
Prohibited practices

Social scoring, emotion recognition at work, biometric categorisation and manipulative systems – prohibited since February 2025 with no transition period.

Art. 50
Transparency obligations

Chatbots, voice assistants and generated content must be recognisable as AI and marked in machine-readable form.

Art. 4
AI literacy

The baseline duty that applies to every organisation using AI regardless of risk class – and it already applies.

Who falls within scope?

Providers

Anyone developing an AI system and placing it on the EU market or putting it into service under their own name or trademark – whether paid or free, and regardless of where the company is based.

Deployers

Anyone using an AI system under their own authority in a professional context. That covers most companies: applicant screening, chatbots, text generation or AI features inside bought-in standard software.

Also outside the EU

Providers and deployers from third countries fall within scope as soon as a system is placed on the EU market or its output is used in the EU (Art. 2(1)(c)).

Not covered

Purely private, non-professional use, AI used exclusively for research and development prior to market placement, and military or national security purposes – those follow their own regimes.

Frequently asked questions

Am I affected by the EU AI Act if I only use ChatGPT?

Yes. Anyone using an AI system professionally under their own authority is a deployer under the AI Act. At minimum, AI literacy under Art. 4 applies, plus the transparency obligations in Art. 50 where there is direct interaction or generated content. The extent depends on what you use the system for: applicant screening with ChatGPT can already fall into the high-risk category under Annex III.

Does the AI Act apply to small companies too?

Yes. The EU AI Act has no general exemption for SMEs. It differentiates by the risk of the application, not by company size. Some requirements are simplified for micro-enterprises (for example the form of the technical documentation), but the obligations themselves remain.

How binding is the result of this check?

The check is structured guidance based on your answers and does not replace legal advice. The binding classification has to be made, documented and justified per AI system – which is exactly what market surveillance authorities and auditors examine.

What happens if I skip the classification?

A missing or unverifiable classification is a compliance risk in itself: without a documented inventory you can demonstrate to neither authorities nor customers that no high-risk system is in use. Depending on the breach, fines reach up to €35m or 7% of global annual turnover.

By when do I have to act?

The prohibitions in Art. 5 and AI literacy under Art. 4 have applied since 2 February 2025. Transparency obligations, governance and the penalty framework take effect on 2 August 2026. The main deadline for high-risk AI under Annex III was postponed to 2 December 2027 by the Digital Omnibus; product-embedded AI under Annex I has until 2 August 2028.

Document the assessment instead of re-estimating it every year

SimpleAct links AI inventory, risk classification and evidence in one record. Every change lands in the audit history – so the classification stays provable even as systems or deadlines change.

Book a demo

Related topics

EU AI Act Check: Are You Affected? | SimpleAct