Dentons AI Act Assessor EU AI Act classification & obligation mapping · law current to 17 Sep 2026
What this is

A structured way to run an EU AI Act assessment on a client’s AI system, and to come out with a defensible classification, the obligations that attach to the right party, and a list of the documents you need to ask the client for.

It is built for the moment a client says “we’ve started using AI — are we allowed to?” and you need to get from a vague description to a structured answer without missing anything.

The five questions it works through

These are asked in order, because each one can end the analysis.

1
Is the Act engaged at all? Whether there is an EU nexus — the system is placed on the EU market, put into service or used in the Union, or its output is used here. If not, the analysis stops.
2
Is this actually an “AI system”? A great deal of what clients call AI is not, as a matter of law. Rule-based automation, ordinary statistics, optimisation and classical heuristics fall outside the definition. Getting this wrong in either direction wastes everyone’s time.
3
Is the practice prohibited? The eight banned practices, plus the new ban on tools generating intimate imagery or child sexual abuse material. These have applied since February 2025 and carry the highest penalties. The one that catches ordinary businesses is inferring employees’ emotions in the workplace.
4
Is it high-risk? Both routes: systems embedded in regulated products, and the eight listed areas — biometrics, critical infrastructure, education, employment, essential services such as credit scoring and insurance pricing, law enforcement, migration, and the administration of justice. Where a listed system genuinely does something narrow or merely preparatory, the tool also puts the derogation to you — and tells you what relying on it then costs in documentation and registration.
5
Does anything have to be disclosed? The transparency duties — telling people they are talking to a machine, marking AI-generated content, disclosing deepfakes and AI-written material published on matters of public interest. These have been in force since 2 August 2026, so they are live law today rather than a future deadline, and they apply whatever the risk classification.

Who owes what

Most of the difficulty in practice is not the risk class. It is working out whether your client is the provider of the system or merely its deployer — because almost every substantive obligation follows that distinction, and clients are routinely wrong about which one they are. The tool works it out from how the system was obtained and what the client did with it, and shows you the reasoning.

Four traps it is specifically built to catch:

Building something only for internal use still makes the client a provider. “Putting into service” expressly covers supply for the client’s own use. A tool a company built for its own staff, and never sold to anyone, still carries provider obligations. This is the single most commonly missed answer.
Repurposing a bought tool can flip the client into being its provider. Take a general-purpose tool, point it at something in the high-risk list — screening CVs is the classic — and the client becomes the provider of a high-risk system, with the whole provider regime attaching. The vendor’s compliance paperwork will not cover the client for that new purpose.
Buying a tool does not hand the client the vendor’s duties. Marking generated content and disclosing the AI interface are the provider’s obligations. A client that merely deploys the tool does not owe them, and putting them on the client’s action list is simply wrong. The tool separates these out and reframes them as a diligence point on the vendor.
Using a model through an API does not make the client a model provider. Prompting, retrieval and wrapping a third-party model in an interface stay far below the threshold at which someone becomes responsible for the model itself. Those obligations sit upstream.

What you get at the end

A classificationWith the reasoning that produced it and the date from which it bites, so you can see and challenge the logic rather than take it on trust.
An obligations tableEvery duty that attaches, against the Article it comes from, marked as the client’s duty as provider or as deployer, with its deadline.
An evidence listWhat to actually ask the client for, obligation by obligation — the documents, records and sign-offs that would have to exist.
The open pointsWhere the law is genuinely unsettled, and where the answer turns on a judgement that is yours to make rather than the tool’s.

The result can be printed or copied straight into a memo.

How it decides — and why that matters

The AI gathers the facts. Fixed rules decide the law. When you describe a client’s systems in your own words, the language model does one job: it turns your description into structured facts and asks the next useful question. It never decides the risk class, never chooses an obligation and never supplies a date. That is done by rules written against the Regulation. The same facts therefore always produce the same answer, every conclusion points at an Article, and the tool cannot invent a duty that does not exist.

Two consequences worth knowing. Anything you have not told it is shown as an open question rather than quietly assumed — so a thin description produces an openly incomplete assessment, not a confident wrong one. And questions that are pure legal judgement are marked “your call” and put to you directly; the model is not allowed to answer them.

You can also ignore the conversation entirely and simply click through the questions. The assessment is identical either way.

Where it stops

  • It covers the Regulation, not national law. Which authority supervises, how penalties are set and where notifications go differ by Member State, and several are still late. That needs local counsel in each jurisdiction.
  • It does not do the sectoral overlay — medical devices, financial services and the rest — or a data protection analysis beyond noting where the impact assessment hooks in.
  • It structures the analysis; it does not replace it. It is a prototype for internal discussion, and it is not legal advice.

Law stated as at 17 September 2026 — Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026.

Settings

A key is built into this file so the tool works the moment you open it — which also means anyone who has a copy of the file can read that key out of it. A key you enter here is kept in this browser only (localStorage) and takes precedence over the built-in one. Either way it is sent only to the Anthropic API.

A key is already built into this file, so nothing is needed to get started. Without one the tool still works — answer the questions on the right by clicking. Reloading restores the built-in key.