Paste your AI system description → get risk tier with article cites. Navigate the Act by use case. Drop in audit-trail JS for Article 12. Generate transparency badges. Built sovereign · runs offline · your data never leaves the browser.
RESEARCH ONLY · NOT LEGAL ADVICE · verify with counsel
UI only · article text stays in English with EUR-Lex links to all 24 official languages
Honest framing: this is a heuristic toolkit grounded in the AI Act text (Regulation 2024/1689). The risk classifier is a starting point, not a definitive judgment. For systems that materially affect anyone, get a qualified legal opinion. The Act's full text is at eur-lex.europa.eu/eli/reg/2024/1689/oj.
⚙Settings · BYOK deep classifier
T0 keyword classifier always runs (offline · no key). T2 adds LLM-powered deeper analysis using your own API key. Key stays in localStorage on your device · never sent anywhere except the provider you choose.
R0 ●Risk classifier
Paste a plain-English description of what your AI system does. The classifier matches against the Act's risk tiers and returns the most-likely category with the article cites you need to read.
R1 〜 Article navigator · search the Act by use case
Most common operational questions mapped to the articles you need. Click to expand. Text is summaries — read the Act text via the official link for legal weight.
Article 5 · Prohibited AI practices (don't deploy these)
Eight categories are flat-banned. If your system does any of these in the EU, you cannot deploy:
Subliminal/manipulative techniques that materially distort behaviour and cause harm
Exploitation of vulnerabilities (age, disability, social/economic situation) to materially distort behaviour
Social scoring by public authorities causing detrimental treatment
Predictive policing assessing risk of an individual committing a crime based solely on profiling
Untargeted scraping of facial images from internet/CCTV for facial recognition databases
Emotion recognition in workplaces and educational institutions (with narrow medical/safety carveouts)
Biometric categorisation by race, political opinion, sexual orientation, religion etc.
Real-time remote biometric identification in public spaces for law enforcement (with very narrow exceptions)
Enforcement: applies from 2 Feb 2025. Fines up to €35M or 7% global turnover.
Article 6 + Annex III · High-risk classification (the wedge)
Your system is high-risk if it falls into one of the 8 Annex III categories:
1 Biometrics (when not Article 5 prohibited)
2 Critical infrastructure (water · gas · electricity · road · rail · digital infra)
5 Access to essential services (credit scoring · health insurance pricing · emergency services dispatch · public benefits eligibility)
6 Law enforcement (evidence reliability · profiling · crime analytics)
7 Migration, asylum & border control
8 Administration of justice and democratic processes
Carveouts: if your system performs a narrow procedural task, or just improves a previously-completed human activity, OR is purely preparatory — you can argue it's NOT high-risk under Article 6(3). Document this assessment.
Enforcement: high-risk obligations apply from 2 Aug 2026 (for standalone systems) or 2 Aug 2027 (when AI is a safety component of a product covered by other EU regulation).
Article 9 · Risk management system (if high-risk)
You must establish, implement, document and maintain a risk management system across the entire system lifecycle. Specifically:
Identify and analyse known and foreseeable risks
Estimate and evaluate risks that may emerge in intended use AND foreseeable misuse
Adopt targeted risk-management measures
Test the system to identify the most appropriate risk-management measures
The system must be tested against established metrics throughout development and before placing on the market.
Article 10 · Data and data governance
Training, validation and testing datasets must:
Be relevant, sufficiently representative, and as far as possible free of errors and complete
Have the appropriate statistical properties for the intended purpose
Have data governance practices documented (collection · origin · annotation · curation)
Examine for possible biases that affect health, safety, fundamental rights, or could lead to discrimination
Sovereign-friendly: if your training data never leaves the user's device (your estate's pattern), this article is much easier to satisfy than for hosted services.
Article 11 + Annex IV · Technical documentation
Before placing a high-risk system on the market, you must compile technical documentation per Annex IV. This includes:
General description of the AI system (intended purpose · provider · version)
Detailed description of system elements (data · algorithms · architecture)
Detailed information on monitoring, functioning and control
Risk management documentation
Description of changes through lifecycle
List of harmonised standards applied (and where deviations exist, the technical solutions adopted)
EU declaration of conformity
Detailed description of the system for assessing post-market performance
High-risk systems must enable the automatic recording of events ("logs") over the system lifetime. Logs must allow:
Identification of situations that may result in the system presenting a risk
Identification of substantial modifications
Facilitation of post-market monitoring
Monitoring of operation for purposes of detecting bias
What to log: period of each use · reference database compared against · input data leading to a match · identification of natural persons involved in result verification.
Estate wedge: your Konomi prevHash + Ed25519 + cert chain already does this — better than most. See the "Drop-in audit shim" section below for the JS pattern.
Article 13 · Transparency to deployers
The system must come with instructions for use including:
Identity and contact details of provider
Intended purpose · including specific geographical/behavioural/functional setting
Level of accuracy, robustness and cybersecurity
Performance regarding specific persons or groups
Risks specific to the intended purpose
Human oversight measures (per Article 14)
Expected lifetime · maintenance · log access
Article 14 · Human oversight (the pause-before pattern)
High-risk systems must be designed so they can be effectively overseen by humans during use. The oversight must enable persons to:
Understand the system's capacities and limitations
Remain aware of "automation bias"
Correctly interpret the output
Decide not to use the output or override / reverse it
Intervene or interrupt the system via a "stop" button or similar
Estate match: every Fall* tool's pause-before-Save / pause-before-Post / pause-before-Submit gate is exactly this. You've been Article-14-compliant since v1.
Article 15 · Accuracy, robustness and cybersecurity
High-risk systems must achieve an appropriate level of:
Cybersecurity · resilient against attempts to alter use, outputs or performance · including data-poisoning and adversarial examples
Article 50 · Transparency to end-users (the "this is AI" disclosure)
Four categories trigger user-facing transparency obligations:
AI systems interacting with humans (chatbots) → inform the user they're talking to AI, unless obvious
Emotion recognition / biometric categorisation → inform users when exposed
Deepfakes / manipulated content → disclose that content is AI-generated/manipulated
AI-generated text on matters of public interest → disclose AI generation (carveouts exist)
Generate a transparency badge: see the badge section below.
Enforcement: applies from 2 Aug 2026.
Article 26 · Obligations of deployers (the customer)
If you're the deployer (the one putting a high-risk system into service in the EU, even if you didn't build it), you have to:
Use the system in accordance with instructions
Assign human oversight to natural persons with the necessary competence, training, authority, and support
Monitor operation and inform the provider of risks or serious incidents
Keep the logs (Article 12) for at least 6 months
If you make decisions about natural persons using the system → inform them they're subject to a high-risk AI system
For workplace use → inform workers' representatives and the affected workers before deployment
Articles 51-55 · General Purpose AI (GPAI) obligations
If you're a provider of a general-purpose AI model (foundation model):
Technical documentation (Annex XI)
Information for downstream providers (Annex XII)
Copyright policy for training data
Public summary of training content
If the model presents systemic risk (huge compute thresholds), additional obligations: model evaluations, adversarial testing, incident tracking, cybersecurity protection.
Enforcement: applies from 2 Aug 2025 for new models; existing models had until 2 Aug 2027.
Penalties · what non-compliance costs
Maximum fines (whichever is higher):
Prohibited AI (Article 5): €35M or 7% of global annual turnover
Non-compliance with high-risk obligations: €15M or 3%
Supplying incorrect information to authorities: €7.5M or 1%
SMEs and startups: lower of the two amounts (capped not floored).
Member state authorities enforce. The European AI Office coordinates and is the sole authority for GPAI.
R6 ◯ Drop-in audit shim · Article 12 ready
Vanilla JS · zero dependencies · drop into any HTML tool to add Article-12-compliant logging. Stores in IndexedDB · cryptographically chained via SHA-256 prevHash. Export to JSON for the 6-month retention requirement.
// ◊ Article 12 audit shim · drop into any sovereign tool
const EU_AUDIT = (() => {
const DB_NAME = 'eu-aiact-audit';
let db = null;
let prevHash = '0'.repeat(64);
async function open() {
if (db) return db;
return new Promise((res, rej) => {
const r = indexedDB.open(DB_NAME, 1);
r.onupgradeneeded = e => {
const d = e.target.result;
if (!d.objectStoreNames.contains('log')) d.createObjectStore('log', { keyPath: 'id', autoIncrement: true });
};
r.onsuccess = e => { db = e.target.result; res(db); };
r.onerror = e => rej(e.target.error);
});
}
async function sha256(s) {
const buf = new TextEncoder().encode(s);
const h = await crypto.subtle.digest('SHA-256', buf);
return Array.from(new Uint8Array(h)).map(b => b.toString(16).padStart(2,'0')).join('');
}
async function log(event) {
await open();
const entry = {
ts: new Date().toISOString(),
event_type: event.type || 'unknown',
input_summary: event.input?.slice(0, 200) || null,
output_summary: event.output?.slice(0, 200) || null,
operator_id: event.operator || null,
prev_hash: prevHash,
};
entry.hash = await sha256(JSON.stringify(entry));
prevHash = entry.hash;
const tx = db.transaction('log', 'readwrite');
tx.objectStore('log').add(entry);
return entry;
}
async function exportAll() {
await open();
const tx = db.transaction('log', 'readonly');
return new Promise((res, rej) => {
const r = tx.objectStore('log').getAll();
r.onsuccess = () => res(r.result);
r.onerror = e => rej(e.target.error);
});
}
return { log, exportAll };
})();
// ─── usage ─────────────────────────────────────────────
// At every Article-12-relevant event:
EU_AUDIT.log({
type: 'inference', // or 'model_update' · 'human_review' · 'override' · 'error'
input: 'user query text',
output: 'system response',
operator: 'user-id-or-anon'
});
// At export time (Article 26 · 6-month retention):
const allLogs = await EU_AUDIT.exportAll();
console.log(JSON.stringify(allLogs, null, 2));
Composes with Konomi's prevHash + Ed25519 chain already running in your estate. The cryptographic chain means logs are tamper-evident · which goes beyond Article 12's literal text but matches the spirit (and is what auditors will actually want to see).
R3 ♡ Article 50 · transparency badge generator
Generate a small visible badge for your AI-using interface. Covers chatbots, emotion recognition systems, biometric categorisation, deepfakes, and AI-generated public-interest text.
R5 ◐ High-risk checklist · Annex IV documentation
If your classifier verdict came back HIGH RISK, tick each item once documentation exists. Aim for 100% before going live in the EU. Status persists in IndexedDB.
0 / 14 documented
R2 ┃Annex IV documentation generator
Fill in each field. Output is a downloadable Markdown document structured per Annex IV. Use as the starting draft for your technical documentation file. Inputs persist locally so you can come back. Nothing is sent anywhere.
R4 △ Classification log
Every classification you run is logged locally (IndexedDB · never leaves device). Use this as your own Article 11 evidence of due-diligence assessments.
No classifications yet · paste a description above to start