hello@datascale.de+49 89 921 35 623tracked cookie-free · /openDEEN

Search services, integrations and blog posts.

DatascaleResourcesEU AI Act Quick Check

Free · no login · nothing gets sent

EU AI Act Quick Check

Five questions about your AI use case, then you know which risk class it falls into and which duties follow. Runs entirely in your browser.

Question 1 of 5

What does the system do with people?

The biggest lever in the AI Act: what a system reads off people, or produces about them.

Your answers

Nothing answered yet. The check takes about three minutes.

The four classes

Prohibited
High-risk
Transparency duty
Minimal risk

Deadlines, as of August 2026

2 August 2026: Article 50 transparency obligations apply. German authority: Bundesnetzagentur.

2 December 2026: marking of AI-generated content extends to systems already running.

2 December 2027: high-risk obligations under Annex III, deferred from August 2026.

What the Digital Omnibus changed →

What does the tool check?

Five questions about your use case, enough for a first placement in one of the four EU AI Act risk classes:

  1. Does the system score people, infer emotions, recognise biometrics, generate content, or analyse data with no personal reference?
  2. What does the outcome help decide: credit, education and insurance, employment, marketing outreach, or none of those?
  3. Which role are you in, provider or deployer?
  4. Do users notice that AI is involved?
  5. How binding is the decision?

You get the likely class (prohibited, high risk, transparency duty, minimal risk) and the obligations that follow from it.

Most marketing and e-commerce setups land in transparency duty or minimal risk. High risk means Annex III territory (employment, credit, biometric identification, critical infrastructure) and a much longer compliance list.

What decides it is the subject of the decision, not your industry and not the volume of data. A lead score that sets the order of the sales queue is not in Annex III. The same score feeding a credit limit is.

Legal status, August 2026

The Article 50 transparency obligations have applied since 2 August 2026. Run a chatbot or publish AI-generated content, and you have to say so, enforced by the national market surveillance authorities, in Germany the Bundesnetzagentur, with fines up to €15M or 3% of global annual turnover. For systems already running before that date, machine-readable marking becomes mandatory on 2 December 2026. That one is next.

The Digital Omnibus deferred the high-risk obligations: conformity assessment, risk management, data governance and human oversight from 2 December 2027 (Annex III), and from 2 August 2028 for AI embedded in regulated products. The legal basis is Regulation (EU) 2026/1744, in force since 27 July 2026.

The long version of both topics is on the blog: what the Digital Omnibus changes and what marketing analytics has to learn from the AI Act.

Not a legal assessment

This is a technical classifier based on patterns of use. A full compliance review for a concrete system requires legal counsel and, for high-risk, a formal conformity assessment under Article 43. The output here is a starting point, not a verdict.

Last updated:

Frequently asked

When does the EU AI Act apply?

The EU AI Act entered into force in 2024 with staged application. Prohibitions for Unacceptable-Risk systems have applied since February 2025, GPAI obligations since August 2025, and the Article 50 transparency obligations since 2 August 2026. For systems already running before that date, machine-readable marking of AI-generated content becomes mandatory on 2 December 2026. The high-risk obligations were deferred by the Digital Omnibus: Annex III from 2 December 2027, product-embedded systems under Annex I from 2 August 2028.

Which marketing tools fall under the EU AI Act?

Smart Bidding (Google Ads), Advantage+ (Meta), lookalike audiences, ML-based lead scoring, automated content personalisation, and recommendation engines all meet the definition. Most land as Limited Risk and need transparency disclosures, not as High Risk.

What's the difference between Limited Risk and High Risk?

Limited Risk means users must know they're interacting with AI (Art. 50). That duty has applied since 2 August 2026, enforced by national market surveillance authorities (in Germany the Bundesnetzagentur), with fines up to €15M or 3% of global annual turnover. Example: a chatbot, a personalisation engine. High Risk (Annex III) means a formal conformity assessment under Art. 43, risk management, data governance, and human oversight, all documented, from 2 December 2027. Example: AI for hiring decisions, credit scoring, biometric identification.

Does the tool replace a legal assessment?

No. It's a technical indicator based on common usage patterns, a starting point for the conversation with the DPO or legal team. The formal classification of a concrete system requires legal review and, for High-Risk, a conformity assessment with a Notified Body.

Data readiness first

Most AI initiatives do not fail on the AI Act; they fail on the data underneath. We examine both in one pass.

AI Strategy & Data Readiness →