Do you use ChatGPT, Copilot or other AI in your company?

Find out in just a few minutes what you need to document and where concrete action is required.

The free AI obligations check classifies your AI usage against the EU AI Act and shows you clearly which obligations apply to you and what needs to be documented – without legal expertise.

Free · For SMEs · Result with concrete next steps · No payment details required

Legal status: 01/06/2026
Business customers only (B2B)

Who is affected?

All companies that develop, offer or use AI systems – regardless of size.

Which risk class?

The EU AI Act distinguishes four levels: prohibited, high, limited and minimal – depending on the area of use.

Which obligations apply?

Documentation, risk analysis, transparency obligations and if applicable conformity assessment – depending on risk class.

What is the next step?

Start the free EU AI Act Compliance Check and receive your individual action recommendation.

Can you answer these five questions?

In many companies AI is already used daily – often across different tools and departments, without a central overview. But the EU AI Act requires exactly that overview. Test yourself:

1

Which AI systems do you use in your company?

2

What exactly do you use these systems for?

3

What data do your employees enter there?

4

Who reviews the AI results?

5

What of this have you documented?

If you cannot confidently answer one of these questions, action is probably required. The free check helps you find out exactly that.

The EU AI Act does not start only with self-developed AI

Even everyday use of common tools can trigger obligations. Four typical examples from SME daily life:

ChatGPT in marketing

Texts, images and campaigns are created with generative AI – often without labelling and without documented approval.

Microsoft Copilot in the office

AI assists with emails, documents and analyses – frequently with personal or confidential data.

AI in recruiting

If applications are pre-sorted or evaluated with AI, a high-risk use case can quickly arise.

Chatbot on the website

Automated assistants in customer contact are subject to transparency obligations – users must know they are talking to AI.

What matters is not only which tool you use, but what you use it for.

What you know after the free check

At the end of the check you receive an understandable initial assessment with clear statements on:

Which role you take on under the EU AI Act (e.g. deployer).

In which areas there is a risk or need for action for you.

Which obligations are relevant for your specific AI usage.

Which next steps make concrete sense.

Whether and what you should document.

How the check works

In four simple steps from the first question to a concrete action plan.

1

Describe your AI usage

You answer simple questions about which AI you use and for what – no jargon, no prior knowledge.

2

Identify the need for action

The check classifies your usage and shows where obligations and risks exist.

3

Receive a concrete action plan

You get an understandable assessment with prioritised next steps.

4

Implement together if you wish

If needed, we support you with the portal and personal guidance during implementation.

Duration: about 7–10 minutesStart the free AI obligations check

Who is this suitable for?

The EU AI Act does not only concern tech corporations. It is especially relevant for companies that use AI in everyday work.

Particularly useful for

  • Small and medium-sized companies using AI tools such as ChatGPT or Copilot.
  • Agencies and service providers using AI in client projects.
  • Companies with several departments using AI without a central overview.
  • Management and responsible persons who need traceability and certainty.

The free check is enough for now if …

  • you want to get a first overview of your obligations.
  • you use few AI applications and want to assess the need for action.
  • you are still deciding whether and how you need to document.
Start the free AI obligations check

The premium portal makes sense if …

  • you want to document your AI usage permanently and keep it up to date.
  • several people or departments are involved in AI governance.
  • you want to store evidence and decisions centrally and traceably.
Discover Premium Toolkit

No pig in a poke: this is what an assessment looks like

No general promises: see, based on a transparently labelled sample case, how the EU AI Act Check classifies a typical AI application and which next steps result from it.

The sample case shown uses exclusively fictitious company data and is not a customer reference.

Fictitious practical example for illustration – not a customer reference

Sample case: ChatGPT in marketing

Initial situation

A small service company uses ChatGPT for blog articles, social media posts and customer emails. There is no central documentation, no policy and no defined approval process.

What is checked?

Purpose of the AI use
Role under the EU AI Act
Processed data
Human oversight of the results
Transparency requirements
Responsibilities and evidence

Possible outcome

Create an AI inventory
Define usage types
Regulate data handling
Name a responsible person
Document the approval process
Demonstrate AI literacy
Check labelling obligations

Sample report

Overall risk: Limited risk

Transparency obligations – no high risk in the described use.

CompanyMuster GmbH
IndustryBusiness consulting
Employees12
AI areas1

Initial situation

ChatGPT use in marketing without central documentation.

Identified role

Deployer of an AI system under the EU AI Act.

Risk classification

Limited risk

Mostly limited risk with transparency obligations; no high risk in the described use.

Need for action

AI inventory, usage policy, approval process and labelling are missing.

Recommended measures

Name responsible persons, document usage, train employees, label content.

Sources / legal status

Regulation (EU) 2024/1689; legal status 1 June 2026.

Sample report with fictitious company data. It was created with the EU AI Act Check and shows, by way of example, the structure and scope of a possible assessment. The individual result depends on the information provided and the specific purpose of use.

What you can rely on

Experience since 2018

Webutissimo S.L. has been active as a service provider since 2018. The EU AI Act portal is a more recent offering built on this foundation.

Clear legal status

All content refers to a stated legal status (1 June 2026).

Official sources

The basis is Regulation (EU) 2024/1689 and publications of the EU Commission.

Transparent scope

We disclose what is checked, how it is checked, which data is processed and when a specialist lawyer should be consulted.

Insight into the portal

The structure and functions of the portal are presented transparently – no anonymous black-box tool.

Personal contacts

For questions, real contacts are personally available to you.

Prefer to discuss it personally?

Not sure about the classification? In a personal 20-minute conversation we go through your result together and answer your questions about the concrete need for action.

Book a personal evaluation

Your contact

Dirk Schumacher

Webutissimo S.L.

Thomas Bahr

Webutissimo S.L.

Premium Compliance Toolkit

AI Compliance Software: From Check to Full Documentation

The free check shows you where you stand. The Premium Toolkit supports your EU AI Act implementation: document AI systems, perform conformity assessments, build AI governance and maintain a complete audit trail.

USP

AI System Inventory

Know which AI is used for what: capture all AI systems in use centrally – with purpose, provider and responsibility in one place.

USP

Complete Audit Trail

Trace changes and decisions: a complete history shows who changed what and when – as a basis for structured and traceable documentation to prepare for internal and external reviews.

Progress Comparison (Snapshots)

Make progress visible: capture your compliance status at any point as a snapshot and show development over time.

Content Archive with Search & Filter

Policies and evidence in one place: upload documents, policies and evidence and keep everything collected and findable.

Multi-Framework References

Capture risks systematically: assess and document the risks of your AI systems in a structured way instead of by gut feeling.

Team Approval Workflow

Clear who creates, reviews and approves: distribute tasks and roles across the team so responsibilities are traceable.

USP

AI Labeling Checklist (Art. 50)

Check labelling reliably: use a guided checklist to clarify where you must label AI content under Art. 50.

USP

AI Compliance Chatbot

Clarify questions directly in the portal: an integrated assistant answers your EU AI Act questions in the context of your documentation.

Frequently asked

Who is subject to documentation obligations?

The documentation obligation does not only apply to AI developers. Companies that merely deploy AI systems also have extensive obligations depending on the risk class.

Providers of high-risk AI

Companies that develop or market high-risk AI systems under their own name – full technical documentation per Annex IV.

Deployers of high-risk AI

Companies using high-risk AI in their own operations (e.g. HR, credit scoring, education) – documentation of deployment and monitoring.

All users of generative AI

Any company publishing AI-generated content (text, images, video) – labelling and documentation obligation under Art. 50.

Importers & distributors

Anyone importing AI systems from non-EU countries or making them available on the EU market – ensuring all documentation requirements are met.

The training obligation under Art. 4 (AI literacy) applies to all companies using AI – regardless of risk class. Even with minimal risk, maintaining an AI inventory is recommended.

Frequently Asked Questions about the AI Regulation

What is the AI Regulation (EU AI Act)?
The AI Regulation is the EU's legal framework for AI systems. It establishes obligations based on risk classes and governs transparency, documentation and accountability.
Who qualifies as a provider and who as a deployer?
Providers develop or place an AI system on the market. Deployers use an AI system within their own organisation and must fulfil their own obligations depending on the case.
What obligations apply to high-risk AI systems?
High-risk AI requires enhanced risk management, technical documentation, logging, human oversight and conformity assessment.
What does Art. 50 EU AI Act mean?
Art. 50 regulates transparency obligations, such as when users interact with AI systems or when AI-generated content must be labelled. The specific obligation depends on the use case.
When do the different deadlines apply?
Prohibitions on certain AI practices have applied since 2 February 2025. The AI literacy obligation also applies since February 2025. Transparency obligations have been in effect since 2 August 2026. The AI Omnibus (July 2026) postponed the deadlines for high-risk AI: Annex III use cases until 2 December 2027, AI in regulated products until 2 August 2028.
What penalties apply for violations?
Depending on the severity, fines of up to €35 million or 7% of worldwide annual turnover may apply. Proportionate caps apply for SMEs.
What must be considered for generative AI?
Generative AI systems (e.g. chatbots, image generators) are subject to labelling obligations under Art. 50. AI-generated content must be identifiable as such by users.
What is the AI Omnibus?
The AI Omnibus is an amendment regulation adopted by the EU at the end of July 2026. It postpones the deadlines for high-risk AI (Annex III) to 2 December 2027 and for AI in regulated products (Annex I) to 2 August 2028. Transparency obligations under Art. 50 remain in effect since August 2026.
Table of Contents

Changelog – As of 2026

  • Obligations by risk class clarified
  • Checklist supplemented with documentation requirements
  • Deadlines and transitional periods updated

EU AI Act: What Companies Need to Know

The EU AI Act requires companies to ensure transparency, documentation and risk management depending on their role (provider, deployer, importer, distributor). Whether and which obligations apply depends on the AI risk class and the use case.

Our Compliance Check assesses:

  • What role does your company play?
  • What AI risk class applies?
  • Which obligations already apply in 2026?

The 3 key results

  • Which AI risk class your application falls into (prohibited, high, limited, minimal)
  • Which provider and deployer obligations apply to you
  • Which EU AI Act implementation measures to prioritise
2026

Fully effective from August

0

Risk Categories

0+

Articles in the EU AI Act

0M €

Max. Fine

Is Your System a High-Risk AI System?

Annex III of the EU AI Act defines specific use cases. Check if your AI deployment falls under them.

Use CaseAnnex III CategoryImmediate Action
AI-based applicant screening4. Employment & personnel managementSet up conformity assessment + risk management
Automated creditworthiness assessment5b. Access to financial servicesEnsure transparency obligations + human oversight
Biometric access control at workplace1. Biometrics (identification)Conduct DPIA + verify consent
AI-based exam grading (school/university)3. General & vocational educationSet up documentation + quality management
AI in medical diagnostics(EU product law: MDR/IVDR)Verify CE conformity under EU harmonisation law
AI-controlled traffic management systems2. Critical infrastructureEnsure robustness testing + cybersecurity

What is the EU AI Act (AI Regulation)?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive AI regulation. It defines provider and deployer obligations for AI systems, establishes AI risk categories and sets transparency requirements. It entered into force on 1 August 2024 and will be fully applied in stages by 2027.

Prohibited AI Systems

Social scoring, real-time biometric identification in public spaces, manipulative AI – fully banned

High-Risk AI Systems

AI in HR, credit scoring, education, critical infrastructure – conformity assessment and fundamental rights impact assessment required

Limited Risk (Transparency)

Chatbots, deepfakes, generative AI – labelling obligation for AI content under Art. 50 EU AI Act

Minimal Risk

Spam filters, AI-powered games, general productivity tools

EU AI Act Timeline 2024–2028

Key milestones of the AI Regulation at a glance – from adoption to full application.

1 August 2024Already in effect

AI Regulation enters into force

EU Regulation 2024/1689 officially enters into force. Staggered transition periods begin.

2 February 2025Already in effect

Prohibited AI practices (Art. 5)

Ban on social scoring, manipulative AI and real-time biometric identification in public spaces.

2 August 2025Already in effect

GPAI obligations & governance

Obligations for General-Purpose AI models (Art. 51–56) take effect. National supervisory authorities must be designated.

2 August 2026 (Transparency) / 2 December 2027 (High-Risk)

High-risk AI fully applicable

Transparency obligations (Art. 50) in effect since August 2026. High-risk AI obligations (Annex III) postponed to 2 December 2027 by AI Omnibus. AI in regulated products (Annex I) postponed to 2 August 2028.

2 August 2028

AI in Regulated Products (Annex I)

Obligations for AI systems as safety components in regulated products (e.g. medical devices, machinery). Deadline postponed by AI Omnibus (originally August 2027).

Fines & Sanctions for Violations

The EU AI Act provides graduated sanctions depending on the severity of the violation (Art. 99).

Sanction LevelMaximum FineTypical ViolationPractical Impact
Level 1 – Prohibited AIUp to €35M or 7% annual turnoverUse of prohibited AI practices (e.g. social scoring, manipulative systems)Existentially threatening for SMEs
Level 2 – High-Risk ViolationsUp to €15M or 3% annual turnoverMissing conformity assessment, insufficient documentation for high-risk AISignificant financial burden
Level 3 – Information ObligationsUp to €7.5M or 1% annual turnoverFalse/incomplete information to authorities, missing labellingNoticeable penalty
SME ProvisionThe lower amount appliesFor SMEs and start-ups, the lower of the two amounts always applies (absolute vs. turnover)Proportionality preserved

Note: Enforcement is carried out by national market surveillance authorities. In Germany, BNetzA is responsible (Art. 70).

Proportionality principle: Lower caps apply for SMEs and startups (Art. 99). Economic survival of the company is considered when assessing penalties. Signing the Code of Practice (CoP) further reduces risk.

ChatGPT, Copilot & Co. – Keep Using Them?

Generative AI falls under special transparency rules. Here's how to classify its use in your company.

Area of UseAllowedProhibited / RestrictedEU AI Act Obligation
Marketing & ContentText creation, image generation, translationSubliminal manipulation, deceptive deepfakesLabel as AI-generated (Art. 50)
HR & RecruitingDrafting job postingsAutomated applicant selection without oversightObserve high-risk obligations (Annex III No. 4)
IT & SupportCode assistance, FAQ chatbotUnchecked AI decisions in critical systemsEnsure human oversight (Art. 14)
Internal ProductivitySummaries, minutes, researchEmployee surveillance, emotion recognition at workAI competence training (Art. 4)

4-Point Check for Your AI Use

1. Is AI-generated output clearly labelled as such?

2. Is there human control before automated decisions?

3. Have employees been trained in safe AI use (Art. 4)?

4. Is it documented which AI systems are used for what?

EU AI Act vs. GDPR – What's the Difference?

Both regulations can apply simultaneously. Here's how they differ:

CriterionEU AI ActGDPR
Subject matterAI systems and their applicationPersonal data
Affected systemsAlgorithms, machine learning, automated decisionsAny processing of personal data
Risk classification4 risk classes (prohibited to minimal)Data Protection Impact Assessment (DPIA)
Typical obligationsTechnical documentation, transparency, conformity assessmentConsent, right of access, right to erasure
When do both apply?AI processes personal dataAI processes personal data

Obligations Matrix by Role

Who must do what by when? Overview of obligations by role in the AI value chain.

RoleMain ObligationDeadlineFine Risk
ProviderConformity assessment, CE marking, technical documentation (Art. 16)Aug 2026Up to €35M / 7% turnover
DeployerFundamental rights impact assessment, human oversight, logging (Art. 26)Aug 2026Up to €15M / 3% turnover
ImporterVerify conformity, ensure CE marking (Art. 23)Aug 2026Up to €15M / 3% turnover
DistributorVerify conformity, secure storage & transport (Art. 24)Aug 2026Up to €15M / 3% turnover
GPAI ProviderTechnical documentation, copyright policy, assess systemic risk (Art. 51–56)Aug 2025Up to €15M / 3% turnover

EU AI Act Compliance – Which Obligations Apply to You?

Find your company situation and next step in the table:

Company situationRisk classObligationNext step
Internal use of AI tools (e.g. ChatGPT)MinimalAI competence requirement (Art. 4)Start Compliance Check
Provider of AI solutionsLimitedTransparency + labeling (Art. 50)Check labeling requirements
AI in HR, credit, educationHighTech. doc. + risk analysis + conformityPerform full assessment
AI for social scoring, mass surveillanceProhibitedUse prohibited (Art. 5)Shut down system immediately
Important to understand

What counts as an AI system?

The EU AI Act regulates AI systems based on their purpose and risk level – not by brand name or number of tools. Each AI system with an independent purpose requires separate compliance documentation.

One Tool = One Project

Your company uses ChatGPT for customer service? That's one AI system – one compliance project.

Example: ChatGPT for support → 1 project

Multiple Tools = Multiple Projects

Using ChatGPT, Midjourney, and a custom ML model? Each system with a different purpose needs its own project.

Example: ChatGPT + Midjourney + ML → 3 projects

Platform = It depends

A platform like Magica with multiple AI models can be one project – or several, if the use cases have different risk levels.

Example: Magica for marketing → 1 project, Magica for HR → separate project

What is a project in the Premium Toolkit?

A project refers to an AI system or AI application that requires its own compliance documentation – not every individual tool within a platform. For example, if you use a platform with multiple AI models for the same purpose, that is one project. But if you use the same platform for HR and marketing, those are two projects with different risk levels.

The key question

It's not the tool name that determines the obligations, but the purpose of use. An AI tool for marketing copy (limited risk) requires different measures than the same tool for applicant screening (high risk). Use our free questionnaire to find out how many projects you need.

EU AI Act Glossary

Key terms of the AI Regulation explained clearly.

Audit Trail

Complete, automatic logging of all AI decisions and data access for traceability.

Conformity Assessment

Procedure to demonstrate that a high-risk AI system meets the requirements of the AI Regulation.

Fundamental Rights Impact Assessment

Mandatory assessment by deployers whether a high-risk AI system may affect fundamental rights of affected persons (Art. 27).

AI Governance

Internal framework of processes, policies and responsibilities for compliant AI deployment.

High-Risk AI System

AI system used in areas such as employment, education, law enforcement or critical infrastructure (Annex III).

GPAI (General Purpose AI)

AI model with broad capability, e.g. large language models (LLMs). Subject to specific transparency and documentation obligations (Art. 51–56).

AI Regulatory Sandbox

Controlled testing environment supervised by an authority where AI systems can be tested under real conditions (Art. 57–62).

Transparency Obligation

Duty to inform users that they are interacting with an AI system – applies especially to chatbots and deepfakes (Art. 50).

Risk Class

Classification of an AI system as minimal, limited, high or unacceptable risk – determines the scope of regulatory obligations.

Deployer / Provider

Providers develop and market AI systems; deployers use them. Both carry different obligations under the AI Regulation.

AI Omnibus

An amendment regulation adopted by the EU in July 2026 that, among other things, postponed the deadlines for high-risk AI systems (Annex III) to 2 December 2027 and for AI in regulated products (Annex I) to 2 August 2028. The Omnibus also simplifies certain compliance requirements and clarifies definitions.

Conclusion

Anyone deploying, developing, or distributing AI in the EU must act – regardless of company size. The AI Regulation defines clear obligations for providers and deployers of AI systems. The EU AI Act Compliance Check gives you a clear overview of your AI risk class, obligations and next implementation steps in just a few minutes.

Identify action items for your business

Act now – before it's too late

Start Free Assessment