A rule base, not a model
The classification comes from a versioned, readable rule base, in the order imposed by
the regulation itself. No language model is involved: the same declaration always yields
the same result. The tool shows the rule applied, the article and the trace of triggered
rules — the part you copy into your file.
The regulation's order of assessment
- Article 5 — prohibited practices: they prevail, no measure saves them.
- Article 6(1) + Annex I — safety component of a harmonised product.
- Article 6(2) + Annex III — high-risk areas, subject to Article 6(3).
- Article 50 — transparency obligations.
- Otherwise — minimal risk.
The Article 6(3) trap
The derogation that lifts an Annex III system out of the high-risk regime
never applies where the system profiles natural persons. This is the
most common classification mistake: the tool applies the exception and says so, rather
than returning a milder category.
Ranked gaps
Every gap is weighted by the severity of the control point, then increased by context:
special category data, large scale, vulnerable people, AI Act category. The score gives a
P1, P2 or P3 priority, and the priority gives a target date. An action plan, not a list
of complaints.