Leave us your data and we will get in contact with you shortly.
Free tool
Answer plain language questions about how your company uses AI. It takes about 5 minutes.
Last updated: October 2026
Does the EU AI Act apply to my company?
The EU AI Act applies to any company that develops, uses, imports or distributes AI systems in the EU, and to companies outside the EU whose AI is used in the EU. What it asks of you depends on your role and on the risk level of each AI system: some uses are banned, high risk AI carries the strictest duties from 2 December 2027, and AI that talks with people or creates content has transparency duties since 2 August 2026. Every company whose staff use AI must also take steps to build basic AI skills. This free checker from Qalea works out where your company stands.
The checker asks plain language questions about how your company develops, uses or sells AI, and applies the rules of the EU AI Act as amended by the Digital Omnibus on AI. Your result covers:
Your company
Size, sector and location. These decide whether the AI Act reaches you and how fines are calculated.
Your AI and your role
Whether you develop, use, sell or represent AI, and how the AI works. You see your role before moving on.
Banned uses
Practices the EU has prohibited, such as social scoring or emotion recognition at work, and the narrow exceptions that exist.
Regulated products and high risk areas
AI inside products such as medical devices or machinery, and AI used in areas such as hiring, credit, education or public services.
Transparency
Chatbots, generated content and deepfakes, which require telling people they are dealing with AI.
Your starting point
Personal data, the frameworks you already have and who is responsible for AI compliance.
Questions only appear when they apply to you. A company that only uses tools like ChatGPT or Copilot answers about 17 questions. A company developing high risk AI answers around 25.
Prohibited
AI uses banned in the EU, such as manipulating people, social scoring or untargeted scraping of faces. Most bans have applied since February 2025, and fines reach €35 million or 7% of worldwide annual turnover.
High risk
AI used in sensitive areas such as hiring, credit scoring, education, critical infrastructure or law enforcement, and AI that is a safety component of regulated products. It carries the strictest duties: risk management, documentation, human oversight and registration.
Transparency
AI that talks with people or creates content. People must be told when they are dealing with AI, and generated content must be marked as made by AI.
Low risk
Most business uses of AI. There are few duties, but companies must take steps so that staff who use AI have basic AI skills.
General purpose AI models
Large models that can do many different tasks, such as language models. Their developers have documentation, copyright and transparency duties, with more for the largest models.
The Digital Omnibus on AI, in force since 27 July 2026, moved several deadlines of the AI Act. These are the dates the checker uses:
2 February 2025
Bans on prohibited practices and the AI literacy duty apply.
2 August 2025
Duties for providers of general purpose AI models apply.
2 August 2026
Transparency rules apply.
2 December 2026
The ban on sexual images created without consent and on child sexual abuse material applies. AI tools already on the market must mark the content they generate.
2 August 2027
Deadline for general purpose AI models already on the market before 2 August 2025.
2 December 2027
High risk rules apply to AI used in sensitive areas such as hiring, credit or education.
2 August 2028
High risk rules apply to AI in regulated products such as medical devices, toys or lifts.
Who it is for: CEOs, CTOs, IT and security leads, and legal and compliance owners at SMEs and midsize companies that use, build or sell AI and want a clear view of what the AI Act asks of them.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's law on artificial intelligence. It sorts AI by risk: it bans some uses, sets strict requirements for high risk AI, adds transparency duties for AI that talks with people or creates content, and sets rules for general purpose AI models. It was amended in 2026 by the Digital Omnibus on AI.
Does the AI Act apply if we only use tools like ChatGPT or Copilot?
Yes. Using AI made by others in your work makes you a deployer. For most everyday uses the risk is low, but you must take steps so staff have basic AI skills, and transparency duties apply if you publish content generated by AI or run a chatbot. If you use AI to make decisions in areas such as hiring or credit, stricter rules apply.
What counts as high risk AI?
AI used in the areas listed in the AI Act, such as biometrics, critical infrastructure, education, employment, access to essential services like credit or insurance, law enforcement, migration and justice, and AI that is a safety component of products that need an external safety check, such as medical devices. AI in these areas that only does a narrow supporting task may be exempt, but the exemption must be documented and registered.
When do the high risk rules apply?
After the Digital Omnibus, the high risk rules apply from 2 December 2027 for AI used in sensitive areas, and from 2 August 2028 for AI in regulated products. The bans, the AI literacy duty and the transparency rules already apply.
What are the fines under the AI Act?
Up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for breaching most other duties, whichever is higher. For SMEs and startups, the lower of the two amounts applies.
Does the AI Act apply to companies outside the EU?
Yes, when their AI is offered in the EU or its results are used in the EU. Providers outside the EU of high risk AI or general purpose AI models must also appoint an authorised representative in the EU.
Who supervises the AI Act in Spain?
In Spain, the main authority supervising the AI Act is AESIA, the Spanish Agency for the Supervision of Artificial Intelligence.
Is the result legal advice?
No. The checker gives an indicative result based on your answers and on the AI Act as it stood in October 2026. Where you answer “Not sure” or describe a case that needs a closer look, the result flags it for an expert review.
Want a wider view of your cybersecurity and compliance? A free risk assessment from Qalea reviews your gaps, attack surface and posture, and hands you a prioritised plan.