Explore · Free

Where does your AI system stand?

Nine questions, three results, no score. See your system's EU AI Act risk tier with its reasoning, which Article 50 transparency paragraph falls to whom, and the articles you owe by role. No account is created; the result is computed in your browser and no answer leaves it.

Last reviewed 16 September 2026. A preliminary determination from your declarations; not legal advice.

Start the assessment
Nine questions

Describe the system

Tick what the system does, not what it is. If you are unsure whether an option fits, tick it; the result shows that as a grey zone rather than hiding it.

Your role towards this system

The test the Regulation applies: did you place it on the market under your own name (provider), or do you use it under your own authority (deployer)? If you bought it and put your name on it or substantially modified it, both (Art. 25).

Sector
Does the system do any of these? — Article 5, prohibited practices

Leave empty if none applies. If one does, the tier is "prohibited" and the other answers do not change it.

Does the system make or influence decisions about people in any of these areas? — Annex III

What decides is not the area's name but the outcome the system produces about a person in it. Tick every one that fits.

How the system interacts — Article 50

These are independent of the tier: a minimal-risk system can owe them too.

Model class

The result needs a role, a sector and a model class.

FAQ

About the self-assessment

How do I know whether my AI system is high-risk under the EU AI Act?

Two tests. If the system performs one of the prohibited practices in Article 5, the tier is "prohibited". Otherwise, if it makes or influences decisions about people in one of Annex III's eight areas (biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, justice), it is high-risk. This tool asks both from your declarations; the platform applies the same test to the system's description.

Who owes the Article 50 transparency duty?

It depends on the paragraph. 50(1), the notice of interaction, and 50(2), machine-readable marking of synthetic content, are the provider's; 50(3), the notice of emotion recognition or biometric categorisation, and 50(4), deepfake disclosure, are the deployer's. An organisation that is both provider and deployer owes all four.

Am I a provider or a deployer?

If you placed the system on the market under your own name or built it, you are the provider; if you use someone else's system under your own authority, the deployer. If you put your name on a purchased high-risk system, substantially modify it or change its intended purpose to high-risk, Article 25 makes you the provider.

Is this result a compliance score?

No. Atheros AI produces no scores. The result is three determinations: the risk tier with its reasoning, which Article 50 paragraph falls to whom, and the articles you owe by role. It rests on your declarations; it is not evidence.

Where do my answers go?

Nowhere. The assessment runs in your browser; no request is sent to a server. If you choose "Email me the result", the answers are written into the email body and only then sent to info@atherosai.com.

This tool is not an assessment instrument, produces no score and gives no legal advice. Atheros AI does not issue certificates, affix CE marking or sign declarations of conformity.