Do you use ChatGPT, Copilot or other AI in your company?
Find out in just a few minutes what you need to document and where concrete action is required.
The free AI obligations check classifies your AI usage against the EU AI Act and shows you clearly which obligations apply to you and what needs to be documented – without legal expertise.
Free · For SMEs · Result with concrete next steps · No payment details required
Who is affected?
All companies that develop, offer or use AI systems – regardless of size.
Which risk class?
The EU AI Act distinguishes four levels: prohibited, high, limited and minimal – depending on the area of use.
Which obligations apply?
Documentation, risk analysis, transparency obligations and if applicable conformity assessment – depending on risk class.
What is the next step?
Start the free EU AI Act Compliance Check and receive your individual action recommendation.
Can you answer these five questions?
In many companies AI is already used daily – often across different tools and departments, without a central overview. But the EU AI Act requires exactly that overview. Test yourself:
Which AI systems do you use in your company?
What exactly do you use these systems for?
What data do your employees enter there?
Who reviews the AI results?
What of this have you documented?
If you cannot confidently answer one of these questions, action is probably required. The free check helps you find out exactly that.
The EU AI Act does not start only with self-developed AI
Even everyday use of common tools can trigger obligations. Four typical examples from SME daily life:
ChatGPT in marketing
Texts, images and campaigns are created with generative AI – often without labelling and without documented approval.
Microsoft Copilot in the office
AI assists with emails, documents and analyses – frequently with personal or confidential data.
AI in recruiting
If applications are pre-sorted or evaluated with AI, a high-risk use case can quickly arise.
Chatbot on the website
Automated assistants in customer contact are subject to transparency obligations – users must know they are talking to AI.
What matters is not only which tool you use, but what you use it for.
What you know after the free check
At the end of the check you receive an understandable initial assessment with clear statements on:
Which role you take on under the EU AI Act (e.g. deployer).
In which areas there is a risk or need for action for you.
Which obligations are relevant for your specific AI usage.
Which next steps make concrete sense.
Whether and what you should document.
How the check works
In four simple steps from the first question to a concrete action plan.
Describe your AI usage
You answer simple questions about which AI you use and for what – no jargon, no prior knowledge.
Identify the need for action
The check classifies your usage and shows where obligations and risks exist.
Receive a concrete action plan
You get an understandable assessment with prioritised next steps.
Implement together if you wish
If needed, we support you with the portal and personal guidance during implementation.
Who is this suitable for?
The EU AI Act does not only concern tech corporations. It is especially relevant for companies that use AI in everyday work.
Particularly useful for
- Small and medium-sized companies using AI tools such as ChatGPT or Copilot.
- Agencies and service providers using AI in client projects.
- Companies with several departments using AI without a central overview.
- Management and responsible persons who need traceability and certainty.
The free check is enough for now if …
- you want to get a first overview of your obligations.
- you use few AI applications and want to assess the need for action.
- you are still deciding whether and how you need to document.
The premium portal makes sense if …
- you want to document your AI usage permanently and keep it up to date.
- several people or departments are involved in AI governance.
- you want to store evidence and decisions centrally and traceably.
No pig in a poke: this is what an assessment looks like
No general promises: see, based on a transparently labelled sample case, how the EU AI Act Check classifies a typical AI application and which next steps result from it.
The sample case shown uses exclusively fictitious company data and is not a customer reference.
Sample case: ChatGPT in marketing
Initial situation
A small service company uses ChatGPT for blog articles, social media posts and customer emails. There is no central documentation, no policy and no defined approval process.
What is checked?
Possible outcome
Sample report
Overall risk: Limited risk
Transparency obligations – no high risk in the described use.
Initial situation
ChatGPT use in marketing without central documentation.
Identified role
Deployer of an AI system under the EU AI Act.
Risk classification
Limited riskMostly limited risk with transparency obligations; no high risk in the described use.
Need for action
AI inventory, usage policy, approval process and labelling are missing.
Recommended measures
Name responsible persons, document usage, train employees, label content.
Sources / legal status
Regulation (EU) 2024/1689; legal status 1 June 2026.
Sample report with fictitious company data. It was created with the EU AI Act Check and shows, by way of example, the structure and scope of a possible assessment. The individual result depends on the information provided and the specific purpose of use.
What you can rely on
Experience since 2018
Webutissimo S.L. has been active as a service provider since 2018. The EU AI Act portal is a more recent offering built on this foundation.
Clear legal status
All content refers to a stated legal status (1 June 2026).
Official sources
The basis is Regulation (EU) 2024/1689 and publications of the EU Commission.
Transparent scope
We disclose what is checked, how it is checked, which data is processed and when a specialist lawyer should be consulted.
Insight into the portal
The structure and functions of the portal are presented transparently – no anonymous black-box tool.
Personal contacts
For questions, real contacts are personally available to you.
Prefer to discuss it personally?
Not sure about the classification? In a personal 20-minute conversation we go through your result together and answer your questions about the concrete need for action.
Book a personal evaluationYour contact
Dirk Schumacher
Webutissimo S.L.
Thomas Bahr
Webutissimo S.L.
AI Compliance Software: From Check to Full Documentation
The free check shows you where you stand. The Premium Toolkit supports your EU AI Act implementation: document AI systems, perform conformity assessments, build AI governance and maintain a complete audit trail.
AI System Inventory
Know which AI is used for what: capture all AI systems in use centrally – with purpose, provider and responsibility in one place.
Complete Audit Trail
Trace changes and decisions: a complete history shows who changed what and when – as a basis for structured and traceable documentation to prepare for internal and external reviews.
Progress Comparison (Snapshots)
Make progress visible: capture your compliance status at any point as a snapshot and show development over time.
Content Archive with Search & Filter
Policies and evidence in one place: upload documents, policies and evidence and keep everything collected and findable.
Multi-Framework References
Capture risks systematically: assess and document the risks of your AI systems in a structured way instead of by gut feeling.
Team Approval Workflow
Clear who creates, reviews and approves: distribute tasks and roles across the team so responsibilities are traceable.
AI Labeling Checklist (Art. 50)
Check labelling reliably: use a guided checklist to clarify where you must label AI content under Art. 50.
AI Compliance Chatbot
Clarify questions directly in the portal: an integrated assistant answers your EU AI Act questions in the context of your documentation.
Who is subject to documentation obligations?
The documentation obligation does not only apply to AI developers. Companies that merely deploy AI systems also have extensive obligations depending on the risk class.
Providers of high-risk AI
Companies that develop or market high-risk AI systems under their own name – full technical documentation per Annex IV.
Deployers of high-risk AI
Companies using high-risk AI in their own operations (e.g. HR, credit scoring, education) – documentation of deployment and monitoring.
All users of generative AI
Any company publishing AI-generated content (text, images, video) – labelling and documentation obligation under Art. 50.
Importers & distributors
Anyone importing AI systems from non-EU countries or making them available on the EU market – ensuring all documentation requirements are met.
The training obligation under Art. 4 (AI literacy) applies to all companies using AI – regardless of risk class. Even with minimal risk, maintaining an AI inventory is recommended.
Frequently Asked Questions about the AI Regulation
What is the AI Regulation (EU AI Act)?
Who qualifies as a provider and who as a deployer?
What obligations apply to high-risk AI systems?
What does Art. 50 EU AI Act mean?
When do the different deadlines apply?
What penalties apply for violations?
What must be considered for generative AI?
What is the AI Omnibus?
As of: June 2026 · Last updated: 1 June 2026
Changelog – As of 2026
- Obligations by risk class clarified
- Checklist supplemented with documentation requirements
- Deadlines and transitional periods updated
EU AI Act: What Companies Need to Know
The EU AI Act requires companies to ensure transparency, documentation and risk management depending on their role (provider, deployer, importer, distributor). Whether and which obligations apply depends on the AI risk class and the use case.
Our Compliance Check assesses:
- What role does your company play?
- What AI risk class applies?
- Which obligations already apply in 2026?
The 3 key results
- Which AI risk class your application falls into (prohibited, high, limited, minimal)
- Which provider and deployer obligations apply to you
- Which EU AI Act implementation measures to prioritise
Fully effective from August
Risk Categories
Articles in the EU AI Act
Max. Fine
Is Your System a High-Risk AI System?
Annex III of the EU AI Act defines specific use cases. Check if your AI deployment falls under them.
| Use Case | Annex III Category | Immediate Action |
|---|---|---|
| AI-based applicant screening | 4. Employment & personnel management | Set up conformity assessment + risk management |
| Automated creditworthiness assessment | 5b. Access to financial services | Ensure transparency obligations + human oversight |
| Biometric access control at workplace | 1. Biometrics (identification) | Conduct DPIA + verify consent |
| AI-based exam grading (school/university) | 3. General & vocational education | Set up documentation + quality management |
| AI in medical diagnostics | (EU product law: MDR/IVDR) | Verify CE conformity under EU harmonisation law |
| AI-controlled traffic management systems | 2. Critical infrastructure | Ensure robustness testing + cybersecurity |
What is the EU AI Act (AI Regulation)?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It defines provider and deployer obligations for AI systems, establishes AI risk categories and sets transparency requirements. It entered into force on 1 August 2024 and will be fully applied in stages by 2027.
Social scoring, real-time biometric identification in public spaces, manipulative AI – fully banned
AI in HR, credit scoring, education, critical infrastructure – conformity assessment and fundamental rights impact assessment required
Chatbots, deepfakes, generative AI – labelling obligation for AI content under Art. 50 EU AI Act
Spam filters, AI-powered games, general productivity tools
EU AI Act Timeline 2024–2028
Key milestones of the AI Regulation at a glance – from adoption to full application.
AI Regulation enters into force
EU Regulation 2024/1689 officially enters into force. Staggered transition periods begin.
Prohibited AI practices (Art. 5)
Ban on social scoring, manipulative AI and real-time biometric identification in public spaces.
GPAI obligations & governance
Obligations for General-Purpose AI models (Art. 51–56) take effect. National supervisory authorities must be designated.
High-risk AI fully applicable
Transparency obligations (Art. 50) in effect since August 2026. High-risk AI obligations (Annex III) postponed to 2 December 2027 by AI Omnibus. AI in regulated products (Annex I) postponed to 2 August 2028.
AI in Regulated Products (Annex I)
Obligations for AI systems as safety components in regulated products (e.g. medical devices, machinery). Deadline postponed by AI Omnibus (originally August 2027).
Fines & Sanctions for Violations
The EU AI Act provides graduated sanctions depending on the severity of the violation (Art. 99).
| Sanction Level | Maximum Fine | Typical Violation | Practical Impact |
|---|---|---|---|
| Level 1 – Prohibited AI | Up to €35M or 7% annual turnover | Use of prohibited AI practices (e.g. social scoring, manipulative systems) | Existentially threatening for SMEs |
| Level 2 – High-Risk Violations | Up to €15M or 3% annual turnover | Missing conformity assessment, insufficient documentation for high-risk AI | Significant financial burden |
| Level 3 – Information Obligations | Up to €7.5M or 1% annual turnover | False/incomplete information to authorities, missing labelling | Noticeable penalty |
| SME Provision | The lower amount applies | For SMEs and start-ups, the lower of the two amounts always applies (absolute vs. turnover) | Proportionality preserved |
Note: Enforcement is carried out by national market surveillance authorities. In Germany, BNetzA is responsible (Art. 70).
Proportionality principle: Lower caps apply for SMEs and startups (Art. 99). Economic survival of the company is considered when assessing penalties. Signing the Code of Practice (CoP) further reduces risk.
ChatGPT, Copilot & Co. – Keep Using Them?
Generative AI falls under special transparency rules. Here's how to classify its use in your company.
| Area of Use | Allowed | Prohibited / Restricted | EU AI Act Obligation |
|---|---|---|---|
| Marketing & Content | Text creation, image generation, translation | Subliminal manipulation, deceptive deepfakes | Label as AI-generated (Art. 50) |
| HR & Recruiting | Drafting job postings | Automated applicant selection without oversight | Observe high-risk obligations (Annex III No. 4) |
| IT & Support | Code assistance, FAQ chatbot | Unchecked AI decisions in critical systems | Ensure human oversight (Art. 14) |
| Internal Productivity | Summaries, minutes, research | Employee surveillance, emotion recognition at work | AI competence training (Art. 4) |
4-Point Check for Your AI Use
1. Is AI-generated output clearly labelled as such?
2. Is there human control before automated decisions?
3. Have employees been trained in safe AI use (Art. 4)?
4. Is it documented which AI systems are used for what?
EU AI Act vs. GDPR – What's the Difference?
Both regulations can apply simultaneously. Here's how they differ:
| Criterion | EU AI Act | GDPR |
|---|---|---|
| Subject matter | AI systems and their application | Personal data |
| Affected systems | Algorithms, machine learning, automated decisions | Any processing of personal data |
| Risk classification | 4 risk classes (prohibited to minimal) | Data Protection Impact Assessment (DPIA) |
| Typical obligations | Technical documentation, transparency, conformity assessment | Consent, right of access, right to erasure |
| When do both apply? | AI processes personal data | AI processes personal data |
Obligations Matrix by Role
Who must do what by when? Overview of obligations by role in the AI value chain.
| Role | Main Obligation | Deadline | Fine Risk |
|---|---|---|---|
| Provider | Conformity assessment, CE marking, technical documentation (Art. 16) | Aug 2026 | Up to €35M / 7% turnover |
| Deployer | Fundamental rights impact assessment, human oversight, logging (Art. 26) | Aug 2026 | Up to €15M / 3% turnover |
| Importer | Verify conformity, ensure CE marking (Art. 23) | Aug 2026 | Up to €15M / 3% turnover |
| Distributor | Verify conformity, secure storage & transport (Art. 24) | Aug 2026 | Up to €15M / 3% turnover |
| GPAI Provider | Technical documentation, copyright policy, assess systemic risk (Art. 51–56) | Aug 2025 | Up to €15M / 3% turnover |
EU AI Act Compliance – Which Obligations Apply to You?
Find your company situation and next step in the table:
| Company situation | Risk class | Obligation | Next step |
|---|---|---|---|
| Internal use of AI tools (e.g. ChatGPT) | Minimal | AI competence requirement (Art. 4) | Start Compliance Check |
| Provider of AI solutions | Limited | Transparency + labeling (Art. 50) | Check labeling requirements |
| AI in HR, credit, education | High | Tech. doc. + risk analysis + conformity | Perform full assessment |
| AI for social scoring, mass surveillance | Prohibited | Use prohibited (Art. 5) | Shut down system immediately |
What counts as an AI system?
The EU AI Act regulates AI systems based on their purpose and risk level – not by brand name or number of tools. Each AI system with an independent purpose requires separate compliance documentation.
One Tool = One Project
Your company uses ChatGPT for customer service? That's one AI system – one compliance project.
Example: ChatGPT for support → 1 project
Multiple Tools = Multiple Projects
Using ChatGPT, Midjourney, and a custom ML model? Each system with a different purpose needs its own project.
Example: ChatGPT + Midjourney + ML → 3 projects
Platform = It depends
A platform like Magica with multiple AI models can be one project – or several, if the use cases have different risk levels.
Example: Magica for marketing → 1 project, Magica for HR → separate project
What is a project in the Premium Toolkit?
A project refers to an AI system or AI application that requires its own compliance documentation – not every individual tool within a platform. For example, if you use a platform with multiple AI models for the same purpose, that is one project. But if you use the same platform for HR and marketing, those are two projects with different risk levels.
The key question
It's not the tool name that determines the obligations, but the purpose of use. An AI tool for marketing copy (limited risk) requires different measures than the same tool for applicant screening (high risk). Use our free questionnaire to find out how many projects you need.
EU AI Act Glossary
Key terms of the AI Regulation explained clearly.
Audit Trail
Complete, automatic logging of all AI decisions and data access for traceability.
Conformity Assessment
Procedure to demonstrate that a high-risk AI system meets the requirements of the AI Regulation.
Fundamental Rights Impact Assessment
Mandatory assessment by deployers whether a high-risk AI system may affect fundamental rights of affected persons (Art. 27).
AI Governance
Internal framework of processes, policies and responsibilities for compliant AI deployment.
High-Risk AI System
AI system used in areas such as employment, education, law enforcement or critical infrastructure (Annex III).
GPAI (General Purpose AI)
AI model with broad capability, e.g. large language models (LLMs). Subject to specific transparency and documentation obligations (Art. 51–56).
AI Regulatory Sandbox
Controlled testing environment supervised by an authority where AI systems can be tested under real conditions (Art. 57–62).
Transparency Obligation
Duty to inform users that they are interacting with an AI system – applies especially to chatbots and deepfakes (Art. 50).
Risk Class
Classification of an AI system as minimal, limited, high or unacceptable risk – determines the scope of regulatory obligations.
Deployer / Provider
Providers develop and market AI systems; deployers use them. Both carry different obligations under the AI Regulation.
AI Omnibus
An amendment regulation adopted by the EU in July 2026 that, among other things, postponed the deadlines for high-risk AI systems (Annex III) to 2 December 2027 and for AI in regulated products (Annex I) to 2 August 2028. The Omnibus also simplifies certain compliance requirements and clarifies definitions.
Official Sources
All information on this page is based on official legal texts and publications of the European Union.
Full text of the AI Regulation (EUR-Lex)
Regulation (EU) 2024/1689 – the complete legal text in the Official Journal of the EU.
EU Commission: AI Regulation
Official overview page of the EU Commission on the regulatory framework for Artificial Intelligence.
EU AI Act FAQ (EU Commission)
Frequently asked questions about the AI Regulation – directly from the European Commission.
Conclusion
Anyone deploying, developing, or distributing AI in the EU must act – regardless of company size. The AI Regulation defines clear obligations for providers and deployers of AI systems. The EU AI Act Compliance Check gives you a clear overview of your AI risk class, obligations and next implementation steps in just a few minutes.
Identify action items for your business