Does your organisation develop, train or substantially modify an AI system (including its model, training data, intended purpose, or system architecture)? 1 / 6
Does your organisation develop, train or substantially modify an AI system (including its model, training data, intended purpose, or system architecture)?
Yes, we develop or substantially modify AI systems ourselves
Yes, we fine-tune or adapt third-party AI systems in a way that may materially affect their compliance, intended purpose, or performance
No
Does your organisation place an AI system on the market or put it into service under its own name or trademark (including white-label AI solutions)? 2 / 6
Does your organisation place an AI system on the market or put it into service under its own name or trademark (including white-label AI solutions)?
Yes
No
Does your organisation use an AI system developed by another party for internal purposes or in providing services to clients? 3 / 6
Does your organisation use an AI system developed by another party for internal purposes or in providing services to clients?
Yes
No
Does your organisation import or introduce into the EU market an AI system developed by a third country entity? 4 / 6
Does your organisation import or introduce into the EU market an AI system developed by a third country entity?
Yes
No
Does your organisation distribute, resell, or make available an AI system developed by another party without substantially modifying it? 5 / 6
Does your organisation distribute, resell, or make available an AI system developed by another party without substantially modifying it?
Yes
No
Does your organisation integrate a third-party AI system into your own products or services? 6 / 6
Does your organisation integrate a third-party AI system into your own products or services?
Yes, and the integrated AI system is offered or placed on the market under our own name or trademark
Yes, but we only use the third-party AI system as an internal or supporting tool and do not place it on the market under our own name
No
Is the AI system placed on the EU market or used within the EU? 1 / 3
Is the AI system placed on the EU market or used within the EU?
Yes
Planned for future EU use
No
Not sure
Which best describes what your AI system does or is intended to do? 2 / 3
Which best describes what your AI system does or is intended to do?
It generates content, performs tasks, or answers queries based on a large pre-trained model (e.g. LLM, image generation, multimodal)
It makes, supports, or materially influences decisions affecting individuals’ rights, opportunities, or access to essential services (e.g. recruitment, credit scoring, medical diagnosis, law enforcement)
It recommends, classifies, or filters content or products for individuals (e.g. recommender system, chatbot)
It performs a narrow automated task with no significant impact on individuals (e.g. spam filter, internal analytics)
Does the system interact with natural persons in a way that may not be obvious to them that they are dealing with an AI, or does it generate synthetic content (images, audio, video, or text) without disclosure? 3 / 3
Does the system interact with natural persons in a way that may not be obvious to them that they are dealing with an AI, or does it generate synthetic content (images, audio, video, or text) without disclosure?
Yes - it interacts with or generates content for individuals without clear AI disclosure at point of interaction
Yes - but users are clearly and prominently informed they are interacting with an AI at all times
No - the system does not interact with or generate content for individuals
Does the AI system use subliminal, manipulative, or deceptive techniques to influence behaviour in ways that harm users? 1 / 6
Does the AI system use subliminal, manipulative, or deceptive techniques to influence behaviour in ways that harm users?
Yes - the system is designed to influence behaviour through subliminal or deceptive means
Possibly - persuasive features exist but the system is not designed to deceive users
No
Does the system exploit the vulnerabilities of specific groups (age, disability, or socioeconomic situation) to distort their behaviour in a manner likely to cause harm? 2 / 6
Does the system exploit the vulnerabilities of specific groups (age, disability, or socioeconomic situation) to distort their behaviour in a manner likely to cause harm?
Yes - it targets and exploits vulnerabilities of specific protected groups
The system differentiates by user profile for legitimate personalisation but does not exploit vulnerabilities
No
Does the system perform social scoring of natural persons across unrelated social contexts or for generalised trustworthiness assessment? 3 / 6
Does the system perform social scoring of natural persons across unrelated social contexts or for generalised trustworthiness assessment?
Yes - it scores or classifies individuals across social domains
No - scoring is limited to a specific, lawful, and proportionate purpose
No
Does the system conduct real-time remote biometric identification in publicly accessible spaces? 4 / 6
Does the system conduct real-time remote biometric identification in publicly accessible spaces?
Yes - in real time, in public spaces, for law enforcement, without an applicable exception
Yes - but only post-hoc (not real-time) with prior judicial or supervisory authorisation
No
Does the system infer or recognise the emotions of natural persons in workplace or educational settings? 5 / 6
Does the system infer or recognise the emotions of natural persons in workplace or educational settings?
Yes - it infers emotional states to influence the treatment of individuals in work or education contexts
It analyses physiological or behavioural signals for occupational safety or medical purposes only
No
Does the system categorise individuals based on biometric data to infer or deduce their race, political opinions, trade union membership, religious or philosophical beliefs, or sexual orientation? 6 / 6
Does the system categorise individuals based on biometric data to infer or deduce their race, political opinions, trade union membership, religious or philosophical beliefs, or sexual orientation?
Yes - the system infers or deduces sensitive protected characteristics from biometric data
No
Is the system used as a safety component of, or is it itself, critical infrastructure (energy, water, transport, or digital infrastructure)? 1 / 8
Is the system used as a safety component of, or is it itself, critical infrastructure (energy, water, transport, or digital infrastructure)?
Yes - it is a safety-critical component of critical infrastructure
It supports operations of critical infrastructure but is not a safety component
No
Is the system used to determine access to educational or vocational training, to assess students, or to determine educational outcomes?` 2 / 8
Is the system used to determine access to educational or vocational training, to assess students, or to determine educational outcomes?`
Yes - it determines or materially influences access, assessment, or outcomes in education or training
It supports administrative tasks only (e.g. scheduling, communications)
No
Is the system used for recruitment, selection, promotion, termination, or performance monitoring of employees, or for task allocation? 3 / 8
Is the system used for recruitment, selection, promotion, termination, or performance monitoring of employees, or for task allocation?
Yes - it makes or materially influences employment decisions
It assists HR workflows but all final decisions are made by humans with full information
No
Is the system used to evaluate creditworthiness, determine access to financial products, or assess insurance premiums? 4 / 8
Is the system used to evaluate creditworthiness, determine access to financial products, or assess insurance premiums?
Yes - it evaluates creditworthiness or determines access to financial products
It generates analytical inputs but human agents make all final credit or insurance decisions
No
Is the system used in law enforcement to assess criminal risk, as a polygraph equivalent, to evaluate evidence reliability, or to predict criminal activity? 5 / 8
Is the system used in law enforcement to assess criminal risk, as a polygraph equivalent, to evaluate evidence reliability, or to predict criminal activity?
Yes - in a law enforcement or criminal justice context
No
Is the system used for migration management, border control, asylum or visa assessment, or detection of irregular migration? 6 / 8
Is the system used for migration management, border control, asylum or visa assessment, or detection of irregular migration?
Yes - in a migration, border, or asylum context
No
Is the system used to assist in judicial decision-making, alternative dispute resolution, or the interpretation of law and facts? 7 / 8
Is the system used to assist in judicial decision-making, alternative dispute resolution, or the interpretation of law and facts?
Yes - it assists in judicial or quasi-judicial decision-making processes
It provides legal research, document drafting, or litigation support only
No
Is the system a medical device, a safety component of a medical device, or does it perform AI-assisted diagnosis, triage, or clinical decision support? 8 / 8
Is the system a medical device, a safety component of a medical device, or does it perform AI-assisted diagnosis, triage, or clinical decision support?
Yes - it is a medical device, a safety component thereof, or performs clinical AI functions
It supports administrative healthcare workflows only (e.g. scheduling, billing, communications)
No
Is the model designed for general-purpose use across multiple downstream applications? 1 / 5
Is the model designed for general-purpose use across multiple downstream applications?
Yes
No
Is the model made available to third parties (via API, licensing, open-source, or integration into downstream products)? 2 / 5
Is the model made available to third parties (via API, licensing, open-source, or integration into downstream products)?
Yes
No
Internal use only
Does the model have, or is it expected to have, capabilities or scale that may create systemic risks, including broad downstream reliance, significant societal impact, or potential cross-sector disruption? 3 / 5
Does the model have, or is it expected to have, capabilities or scale that may create systemic risks, including broad downstream reliance, significant societal impact, or potential cross-sector disruption?
Yes
No
Not sure
Is the model capable of being integrated into, or used for, a broad range of high-risk or critical downstream applications (e.g. healthcare, employment, law enforcement, finance, education)? 4 / 5
Is the model capable of being integrated into, or used for, a broad range of high-risk or critical downstream applications (e.g. healthcare, employment, law enforcement, finance, education)?
Yes
No
Not sure
Has the model been trained using very large-scale computational resources (e.g. training compute exceeding 10^25 FLOPs or comparable scale)? 5 / 5
Has the model been trained using very large-scale computational resources (e.g. training compute exceeding 10^25 FLOPs or comparable scale)?
Yes
No
Not sure