Evaluate use case

Start your evaluation

Answer the questions step by step. Based on your input, the follow-up questions will adapt. Your risk level under the EU AI Act will update as you progress and provide an indication. You can bookmark your results, copy the URL or reset your evaluation at any time. 

Please note: this evaluation is optional and does not replace the mandatory DEA/PSA procedure.

Let's get started ...
Keep going – you’re almost there!
Well done! Your evaluation is complete.
Sector of application
01
My AI system is a product or part of a product that requires a third-party conformity assessment.

If you are unsure whether your product requires a third-party conformity assessment, please follow the steps below:

Determine whether the product is intended for use in one or more of the safety-relevant sectors or use cases listed below. If you're uncertain, consult with relevant stakeholders (e.g., the product owner, customer, etc.) to obtain this information.

If your product’s use case or sector does not exactly match any in the list but is clearly related, you should assume that it is covered.

If steps 1 and 2 do not lead to a clear outcome – even after consulting relevant stakeholders and reviewing the reference list – and doubts remain, please reach out to the FMB Digital Ethics.

If any sector or use case requires such an assessment, answer “yes”; otherwise, answer “no”.

In many of the listed sectors, a third-party conformity assessment must be conducted by a notified body (such as DEKRA, TÜV, or similar). This independent procedure ensures that the product complies with applicable EU legislation and is a prerequisite for affixing the CE marking, which signifies conformity with EU health, safety, and environmental protection standards.

Safety-relevant sectors and use cases:

  • machinery
  • toy safety
  • recreational craft & personal watercraft
  • lifts
  • equipment for explosive atmospheres
  • radio equipment
  • pressure equipment
  • cableway installations
  • personal protective equipment
  • gas-burning appliances
  • medical devices
  • in vitro diagnostic medical devices
  • civil aviation
  • two- or three-wheel vehicles & quadricycles
  • agricultural and forestry vehicles
  • marine equipment
  • rail systems
  • motor vehicles in general
  • motor vehicles safety
  • unmanned aircraft (drones)


This list is based on the Union harmonisation legislation referred to in Annex I of the AI Act.

02
In which of the following areas is your AI system intended to be used?

Biometric identification and categorization

  1. Remote biometric identification
    Exception: The AI system is intended solely for biometric verification to confirm that a specific natural person is who they claim to be.
  2. Biometric categorization based on sensitive or protected attributes (e.g., race, gender, political beliefs)?
  3. Emotion recognition?

AI systems using biometrics rely on physical or behavioral traits, such as fingerprints, facial features, or voice patterns, to identify, group, or analyze individuals.

The following are regarded as high-risk categories:

  • Biometric identification (Art. 3(35)): Automated recognition by comparing an individual’s biometric data to a database to establish identity.
  • Remote biometric identification (Art. 3(41)): Identifying individuals at a distance, without their active involvement, by comparing biometric data to a reference database.
  • Biometric categorization (Art. 3(40)):
    Assigning individuals to specific categories based on their biometric data.
  • Emotion Recognition (Art. 3(39)): Inferring emotions or intentions from biometric data. Sensitive biometric data revealing protected attributes, such as racial origin, health, or sexual orientation, is subject to strict protections per Recital 54 of the EU AI Act and Art. 9(1) GDPR.

Critical infrastructure

Is the system intended to be used as a safety component in the management or operation of critical infrastructure, including any of the following areas:

  1. Critical digital infrastructure?
  2. Road traffic management or operation?
  3. Supply of water, gas, heating, or electricity?

AI systems used in critical infrastructure, such as digital networks, road traffic management, and utilities, are considered high-risk under the EU AI Act. These systems often act as safety components (Art. 3(14) AIA), meaning their failure or malfunction could pose serious risks to public health, safety, or the reliability of essential services.

Key applications include:

  • Digital infrastructure: Ensuring secure and reliable IT operations.
  • Road traffic management: Supporting safe and efficient transportation systems.
  • Utilities: overseeing the supply of water, gas, heating, or electricity.

Education or vocational training

  1. Determining access or admission to educational or vocational training institutions
  2. Assigning natural persons to specific institutions Evaluating learning outcomes, including for the purpose of steering the further learning process
  3. Assessing the appropriate level of education or training that an individual will receive or can access
  4. Monitoring and detecting prohibited behavior during tests

AI systems used in education and vocational training are regarded as high-risk under the EU AI Act due to their significant impact on individuals' futures. These systems are applied in critical areas such as determining admission or placement, assessing learning outcomes to guide further education, deciding appropriate education levels, and monitoring for prohibited behavior during exams.
Their use requires strict adherence to fairness, accuracy, and ethical standards to ensure responsible implementation

Employment, worker management or access to self-employment

  1. Determining access or admission to educational or vocational training institutions
  2. Assigning natural persons to specific institutions, evaluating learning outcomes, including for the purpose of steering the further learning process
  3. Assessing the appropriate level of education or training that an individual will receive or can access
  4. Monitoring and detecting prohibited behavior during tests

AI systems used in education and vocational training are regarded as high-risk under the EU AI Act due to their significant impact on individuals' futures. These systems are applied in critical areas such as determining admission or placement, assessing learning outcomes to guide further education, deciding appropriate education levels, and monitoring for prohibited behavior during exams.
Their use requires strict adherence to fairness, accuracy, and ethical standards to ensure responsible implementation

Access to or enjoyment of essential public or private services and benefits

  1. Evaluating the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as granting, reducing, revoking, or reclaiming such benefits and services
  2. Evaluating the creditworthiness of natural persons or establishing their credit score
    Exception: The AI system is intended to be used only for the purpose of detecting financial fraud.

AI systems used in access to or enjoyment of essential services or benefits are regarded as high-risk under the EU AI Act because they directly affect individuals' access to critical resources and opportunities. These systems are applied in:

  • Public assistance and services: Evaluating eligibility for essential public benefits, such as healthcare or financial aid, and making decisions to grant, reduce, revoke, or reclaim such benefits. Misuse or errors can have severe consequences for vulnerable individuals.
  • Creditworthiness and credit scores: Assessing individuals' financial reliability or assigning credit scores, which determine access to loans, housing, or other financial services. These systems can amplify bias or limit opportunities if not carefully monitored.

Law enforcement

  1. Assessment of the risk of a natural person becoming the victim of criminal offences (by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices, or agencies in support of law enforcement authorities or on their behalf)
  2. Use as a polygraph or similar tools (by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices, or agencies in support of law enforcement authorities)
  3. Evaluation of the reliability of evidence in the course of the investigation or prosecution of criminal offences (by or on behalf of law enforcement authorities, or by Union institutions, bodies, offices, or agencies in support of law

AI systems used in law enforcement are regarded as high-risk under the EU AI Act due to their significant implications for individual rights, public trust, and justice. These systems are applied in:

Risk Assessment for Victimization: Evaluating the likelihood of a person becoming a victim of a criminal offense, which directly impacts resource allocation and protective measures.

  • Polygraph and similar tools: Supporting investigations by assessing truthfulness or detecting stress indicators, with potential risks of misuse or inaccuracies affecting outcomes.
  • Evidence reliability evaluation: Determining the reliability of evidence during investigations or prosecutions, where errors can undermine fair trials and justice.
  • Risk assessment for offending or re-offending: Evaluating the likelihood of criminal behavior, requiring safeguards to ensure decisions are not solely based on profiling.
  • Personality and behavior assessment: Analyzing traits, characteristics, or past criminal behavior of individuals or groups, which raises concerns about bias and fairness.
  • Profiling in criminal cases: Automating the analysis of personal data to predict behavior, interests, or movements during the detection, investigation, or prosecution of crimes.

Migration, asylum or border control management

1. Use as a polygraph or similar tools (by or on behalf of competent public authorities or by Union institutions, bodies, offices, or agencies) assessing a risk, including:

  • A security risk
  • A risk of irregular migration
  • A health risk (Posed by a natural person intending to enter or having entered the territory of an EU Member State assessed by or on behalf of competent public authorities or by Union institutions, bodies, offices, or agencies)

2. Examination of applications for asylum, visa, or residence permits, including: Associated complaints regarding the eligibility of the applicants

  • Assessments of the reliability of evidence (by or on behalf of competent public authorities or by Union institutions, bodies, offices, or agencies to assist competent public authorities)

3. Detecting, recognising, or identifying natural persons in the context of migration, asylum, or border control management (by or on behalf of competent public authorities or by Union institutions, bodies, offices, or agencies)
Exception: The AI system is intended solely for detecting, recognising, or identifying natural persons for the purpose of verifying travel documents.

AI systems used in migration, asylum, and border control management are regarded as high-risk under the EU AI Act due to their impact on fundamental rights, security, and access to critical legal protections. These systems are applied in:

  • Polygraph and Similar Tools: Supporting authorities in assessing truthfulness or detecting deception, which carries significant risks of inaccuracies impacting individuals' rights and outcomes.
  • Risk Assessment: Evaluating security, irregular migration, or health risks posed by individuals entering or within the EU, which requires careful monitoring to avoid bias or unjust discrimination.
  • Application Processing: Examining asylum, visa, or residence permit applications, including assessing the reliability of evidence and handling related complaints, where fairness and transparency are critical.
  • Person Detection and Identification: Detecting, recognizing, or identifying individuals in the context of migration and border control, raising concerns about surveillance, privacy, and potential misuse.

Administration of justice or democratic processes

Assisting a judicial authority in:
1. Researching and interpreting facts and the law?
1.1. Applying the law to a concrete set of facts?
1.2. Being used in a similar way to assist in alternative dispute resolution (by a judicial authority or on their behalf)

2. Influencing the outcome of an election or referendum or the voting behaviour of natural persons in the exercise of their vote in elections or referenda?
Exception: The AI system is not directly exposing natural persons to its output, such as tools used solely for organising, optimising, or structuring political campaigns from an administrative or logistical perspective.

AI systems used for administration of justice or democratic processes are regarded as high-risk under the EU AI Act due to their potential impact on fairness, trust, and democratic integrity. These systems may be applied in:

Judicial Assistance: Supporting judicial authorities by:

  • Researching and interpreting facts and laws.
  • Applying the law to specific cases.
  • Assisting alternative dispute resolution processes.

Influencing Elections or Referenda: Shaping the outcome of elections, referenda, or voters' behavior.

None of the above

Functional classification
03
Which of the following statements best describes the intended use of your AI system?

Perform a narrow procedural task.

Improve the result of a previously completed human activity.

Detect decision-making patterns or deviations from prior decision-making patterns without replacing or influencing the human review.

Perform a preparatory task for an assessment relevant to the listed use cases in the question before.

None of the above.

04
My AI system performs profiling of natural persons.

Profiling means the automated processing of personal data to evaluate, analyze, or predict certain aspects related to an individual, such as their performance at work, economic situation, health, preferences, interests, behavior, location, or movements.

Determination of roles under the EU AI Act​
05
What is your entity’s role in relation to the AI system based on the EU AI Act?

System provider

A provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.

An organization is considered as a provider if they:

  • Put name or trademark on: Apply your own name or trademark to an existing AI system developed by another entity.
  • Modify the intended purpose: Change the originally designed function or application of an AI system.
  • Perform substantial modifications (Finetuning): Make significant changes to a high-risk AI system after it has been placed on the market or put into service, affecting its compliance with the AI Act.

If any of these scenarios apply to your organization, you are classified as the provider of the AI system.

Deployer

Deployer: any natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.

Distributor

Distributor: any natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market.

Importer

Importer: any natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established outside the Union.

Authorized representative

Authorised representative: any natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation.

Product manufacturer

Product manufacturer: places on the market or puts into service an AI system together with their product and under their own name or trademark.

Multiple roles can apply.

Transparency-relevant characteristics
06
My AI system is authorized by law to detect, prevent, investigate or prosecute criminal offences.

This does not apply if the AI system is made available to the public for the purpose of reporting a criminal offence. In this case, please click 'no'.

The following example illustrates how an AI system’s purpose and functionality determine its classification under the EU AI Act:

Example: The AI system enables citizens to report criminal offenses through a mobile application. It collects incident details directly from users.

No, if: The system is designed for the reporting of criminal offenses and is not authorized to be used for criminal justice activity.

No, if: The system is explicitly authorized for criminal justice activities and is used for the reporting of criminal offenses.

Yes, if: An AI system is explicitly authorized for criminal justice activities and is not used for the reporting of criminal offenses.

07
My AI system is intended to interact directly with natural persons.

A human-machine interaction occurs when there is a purposeful, reciprocal communication relationship between a human and an interactive system, in which the human provides at least one input or receives an output that could influence their behavior.

The core elements of this interaction are:

  1. Reciprocity (Interactivity): There must be a feedback loop between the human and the system (human ↔ system).
  2. Purposefulness: The human engages with the system in pursuit of a specific goal (e.g., obtaining information, exerting control).
  3. Perceptibility: The human consciously perceives the system’s response and is able to react to it.
08
My AI system generates synthetic audio, image, video or text content.
09
My AI system substantially alters input data or its meaning.

In this context, a 'deployer' is the user or organization operating the AI system, while a 'provider' is the one who developed it.

What does substantial alteration mean?
Substantial alteration refers to significant changes made by the AI system to the input data or its meaning (semantics). This could involve modifying the data in a way that affects its interpretation or intended use.

Examples of substantial alteration:

  • Semantic Changes: The AI system translates natural language input into symbolic logic or a different language, altering the meaning or intent of the data.
  • Transformation of input: A system that converts raw sensor data into a predictive risk score, thereby creating new meaning from the input data.
  • Filtering or distortion: Adjusting video footage to highlight certain features (e.g., blurring unrelated objects) in a way thatchanges how the input is understood.

Non-substantial alterations:

  • Basic data formatting, such as converting text to lowercase.
  • Aggregating input data without altering its meaning (e.g., summarizing without changing intent).
10
My AI system only assists standard editing.

No, if the content has been substantially altered or manipulated, e.g., through summarization, additions, rewording, creative text generation, or translations.

Yes, if the AI only supports standard editing, e.g., spelling correction, formatting suggestions, or autocomplete without changes in terms of content or creative generation.

11
Which of the following categories does your AI system fall into?

Emotion recognition system

Emotion recognition system (Art. 3(39) AIA):
An AI system designed to detect or infer the emotions or intentionsof individuals based on their biometric data.

Emotion recognition systems in the AI Act (Recital 18)
Definition and scope:
An emotion recognition system is defined as an AI system designed to:

  • Identify or infer the emotions or intentions of natural persons.
  • Use biometric data as the basis for analysis.

This means the system actively attempts to interpret emotional or intentional states such as:

  • Happiness, sadness, anger, surprise, disgust, embarrassment, excitement, shame, contempt, satisfaction, or amusement.

Exclusions:
The following systems are not considered emotion recognition systems under this definition:

  • Physical states: Systems that detect physical conditions such as fatigue or pain (e.g., systems used to monitor the alertness of pilots or drivers to prevent accidents) are explicitly excluded.
  • Readily apparent expressions: Systems that detect obvious visible expressions (e.g., smiles or frowns) or gestures (e.g., hand or head movements) are excluded unless the data is processed to detect or infer emotions.

Biometric categorization system

Emotion Recognition System (Art 3(39) AIA):
An AI system designed to detect or infer emotions or intentions of individuals based on their biometric data.

Biometric Categorization System (Art 3(40) AIA):
An AI system that assigns individuals to specific categories based on their biometric data, provided this categorization is ancillary to a commercial service and strictly necessary for technical purposes.

None of the above

12
My AI system generates or manipulates image, audio or video content that constitutes a deepfake.

A deepfake refers to AI-generated or manipulated image, audio, or video content that resembles real persons, objects, places, entities, or events. This content is crafted to falsely appear authentic or truthful, potentially misleading individuals into believing it is genuine (Art 3(60) AIA).

13
My AI system generates or manipulates text published on matters of public interest.
14
My AI-generated content undergoes human review or editorial control. A natural or legal person hast editorial responsibility for its publication.
Risk level indication
Not yet evaluated

Answer a few more questions to get a result.

Limited risk
High risk
No risk
Please consider this:
System provider obligations
Related question: 05
Deployer obligations
Related question: 05
Distributor obligations
Related question: 05
Importer obligations
Related question: 05
Authorized representative obligations
Related question: 05
Product manufacturer obligations
Related question: 05
Exception regulations
Related question: 06, 09, 10, 14,
Transparency obligations
Related question: 07, 09, 10, 11, 12, 14,