EUAICheck is an educational simulator. We are not a law firm and have no affiliation with any official body.
EUAICheck is an independent educational simulator. These examples are provided for informational purposes and do not constitute legal advice. Classifications may evolve according to official guidelines.

20 concrete examples of the EU AI Act in practice

Updated: September 2026 ยท Based on Regulation (EU) 2024/1689 and Commission guidelines (May 2026)
01 Human resources High risk Annexe III ยง4
CV screening software
An ATS automatically analyses applications and assigns a relevance score to each CV before recruiters see them.
Why this classification? The system directly influences access to employment by automatically eliminating candidates. Explicitly cited in Annex III, point 4.
Training data documentation (Art. 10) Mandatory bias testing Human oversight of decisions (Art. 14) Candidate notification (Art. 13) Decision logging (Art. 12)
02 Human resources Prohibited Art. 5
Emotion analysis in video interviews
An online interview tool analyses candidates' facial expressions, voice tone and body language to generate a personality score.
Why this classification? Emotion recognition in professional and recruitment contexts is explicitly prohibited since 2 February 2025 (Article 5, ยง1(f)).
Practice prohibited since Feb. 2025 Fine up to โ‚ฌ35M or 7% of turnover Immediate cessation required
03 Healthcare High risk Annexe III ยง1
AI medical diagnosis from imaging
An AI system analyses X-rays or MRIs to detect pathologies (cancer, fractures) and proposes a diagnosis to the doctor.
Why this classification? Safety component of a medical device or medical device itself. High-risk by definition (Annex III, point 1).
Medical device certification (MDR) Complete technical documentation (Annex IV) Continuous risk management (Art. 9) EU AI Office registration (Art. 49)
04 Financial services High risk Annexe III ยง5
Automated credit scoring
An algorithm evaluates the creditworthiness of a loan applicant and automatically decides to grant or refuse credit.
Why this classification? Access to essential financial services is directly affected. Explicitly cited in Annex III, point 5(b).
Transparency on decision criteria (Art. 13) Right of recourse for refusals (Art. 13) Bias audit on data (Art. 10) Human oversight (Art. 14)
05 Education High risk Annexe III ยง3
AI automated exam grading
An AI system evaluates exam papers or student written work and assigns a grade automatically.
Why this classification? Directly determines access to education and training pathways. Cited in Annex III, point 3.
Human validation of final grades required Student notification of AI use Grading system documentation Right of challenge (Art. 13)
06 Public services High risk Annexe III ยง5
Automated social benefit allocation
A public algorithm evaluates eligibility for social benefits (welfare, housing, allowances) and automatically decides to grant them or not.
Why this classification? Directly affects access to essential public services. Cited in Annex III, point 5(a).
Full transparency on criteria Right to explanation of decisions Mandatory human oversight Fundamental rights impact assessment
07 Justice High risk Annexe III ยง8
Judicial decision support tool
Software analyses legal precedents and case data to recommend a sentence or decision to a judge.
Why this classification? Directly influences judicial decisions affecting fundamental freedoms. Cited in Annex III, point 8(a).
Exhaustive system documentation Final decision always belongs to the judge Full explainability of recommendations EU AI Office registration
08 Critical infrastructure High risk Annexe III ยง2
AI management of electrical grid
An AI system manages the distribution and balancing of the national electricity grid in real time, preventing outages.
Why this classification? Safety component of critical infrastructure (water, energy, transport). Cited in Annex III, point 2.
Robustness and resilience to cyberattacks Human takeover procedures Continuous robustness testing Specific security certification
09 Marketing / E-commerce Limited risk Art. 50
Customer service chatbot
An LLM-based chatbot (ChatGPT, Claude, etc.) answers customer questions on an e-commerce site, simulating a human conversation.
Why this classification? Direct interaction with humans who may not know they are talking to an AI. Disclosure obligation since August 2026 (Article 50).
Clearly inform the user they are interacting with AI Visible "AI" mention or equivalent Must not impersonate a human
10 Marketing / E-commerce Limited risk Art. 50
Marketing content generator
A tool automatically generates blog articles, LinkedIn posts or product descriptions from a prompt.
Why this classification? Synthetic content distributed publicly. AI-generated labelling obligation since August 2026 (Article 50ยง2). Compliance deadline for existing content: December 2026.
Label content as AI-generated Retain metadata of origin Deadline: December 2026 for existing content
11 HR / Monitoring Prohibited Art. 5 ยง1(g)
Scraped facial recognition database
A system creates or extends a facial image database by scraping the internet or surveillance cameras to identify people.
Why this classification? Building facial recognition databases from open sources or CCTV cameras is explicitly prohibited (Article 5, ยง1(g)).
Practice prohibited since Feb. 2025 Fine up to โ‚ฌ35M or 7% of turnover Cessation and data destruction
12 E-commerce / Recommendation Minimal risk No specific obligation
Product recommendation engine
An algorithm analyses a user's purchase history and clicks to recommend products they might be interested in.
Why this classification? No significant impact on fundamental rights. No automated decision significantly affecting persons. Minimal risk.
No specific EU AI Act obligation GDPR applies if personal data used Good practices recommended
13 Cybersecurity Minimal risk No specific obligation
AI spam filter
A machine learning model detects and filters unwanted emails in a professional messaging system.
Why this classification? Purely operational tool with no direct impact on fundamental rights. No decision significantly affecting persons.
No specific EU AI Act obligation GDPR if personal data processing Security best practices
14 Transport High risk Annexe III ยง2
Advanced driver assistance system (ADAS)
A system embedded in a vehicle analyses the environment and makes safety decisions (emergency braking, lane keeping, pedestrian detection).
Why this classification? Safety component of a regulated product (vehicle). Inherently high-risk. Extended deadline: August 2028 for embedded products.
EU type-approval homologation Complete technical documentation Robustness and safety testing Deadline: August 2028
15 Insurance High risk Annexe III ยง5
AI pricing in health insurance
An algorithm calculates a policyholder's health insurance premium by analysing their health data, claims history and behavioural factors.
Why this classification? Affects access to essential services (health insurance) and can lead to discrimination. Cited in Annex III, point 5.
Non-discrimination of decisions (Art. 10) Transparency on pricing criteria Right to explanation (Art. 13) Mandatory bias testing
16 Police / Security Prohibited (with exceptions) Art. 5 ยง1(h)
Real-time facial recognition in public space
Surveillance cameras connected to a facial recognition system identify people in real time in a public area.
Why this classification? Prohibited in principle since Feb. 2025 with very limited exceptions (terrorism, missing children, imminent threats) subject to prior judicial authorisation.
Prohibited except strict legal exceptions Prior judicial authorisation required Notification to national supervisory authority Fine: up to โ‚ฌ35M
17 HR / Work High risk Annexe III ยง4
Remote worker productivity monitoring
Software monitors remote employees' activity (screenshots, keystroke counting, application tracking) and generates productivity scores.
Why this classification? Affects working conditions and can lead to hiring/dismissal decisions. Cited in Annex III, point 4. Biometric monitoring is also prohibited.
Mandatory employee notification (Art. 13) Works council agreement required (national law) Human oversight of decisions (Art. 14) Right of access to collected data
18 SaaS Software Limited risk Art. 50
AI assistant integrated in a CRM
A CRM like Salesforce or HubSpot integrates an AI assistant that drafts emails, summarises calls and predicts conversion probabilities.
Why this classification? Productivity tool with no direct impact on fundamental rights. Transparency obligations if generated content is sent to clients (Art. 50).
Inform recipients if emails are AI-generated No specific documentation obligation GDPR if customer data processed
19 Agriculture / AgriTech Minimal risk No specific obligation
AI plant disease detection
An image analysis system detects crop diseases from photos taken by a farmer with their smartphone.
Why this classification? Decision support tool with no impact on fundamental rights. No Annex III category applies. Minimal risk.
No specific EU AI Act obligation Good practices for result validation GDPR if user data collected
20 Mental health / Wellbeing Limited risk (to monitor) Art. 50
AI mental health support application
A mobile application offers conversations with an AI chatbot to help users manage their stress, anxiety or emotional wellbeing.
Why this classification? Interaction with vulnerable people. Transparency obligation (Art. 50). If the application claims to diagnose or treat, it potentially becomes a medical device subject to MDR.
Clearly inform it is an AI (Art. 50) Never claim to replace a health professional If diagnostic: medical device certification required GDPR vigilance on health data

Does your system look like one of these examples?

Answer 17 questions to get a personalised analysis of your situation. Free educational simulator.

Start the free simulator