---
title: "EU AI Act applicability test: scope, role, and risk classification"
canonical_url: "https://www.sorena.io/artifacts/eu/artificial-intelligence-act/applicability-test"
source_url: "https://www.sorena.io/artifacts/eu/artificial-intelligence-act/applicability-test"
author: "Sorena AI"
description: "Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "EU AI Act"
  - "AI Act applicability"
  - "AI system definition"
  - "territorial scope"
  - "provider"
  - "deployer"
  - "high-risk AI"
  - "GPAI"
  - "Article 50 transparency"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU AI Act applicability test: scope, role, and risk classification

Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.

*Applicability Test* *EU AI Act*

## EU AI Act Applicability Test

Classify an AI feature, model, supplier tool, or business workflow before assigning EU AI Act obligations.

Use the test to separate excluded activity from in-scope AI, identify the operator role, route prohibited, high-risk, GPAI, and transparency categories, and preserve the evidence behind the decision.

The EU AI Act applicability test should answer a narrow sequence of questions: is the item an AI system or a general-purpose AI model, is the activity excluded, is there an EU market, use, or output link, which operator role applies, and which risk or transparency category controls the next obligation. Keep the answer as a classification record, not as a broad policy memo.

## Step 1: decide whether the item is an AI system, a GPAI model, or excluded software

Begin with the object being classified. The AI Act defines an AI system as a machine-based system designed to operate with varying autonomy that may adapt after deployment and infers, for explicit or implicit objectives, outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

Do not treat every automated workflow as an AI system. Recital 12 explains that the definition should not cover systems based only on rules defined by natural persons to automatically execute operations, and that inference is what distinguishes AI systems from simpler traditional software or basic data processing. A general-purpose AI model is different again: the Act treats models as components that need further elements, such as a user interface, to become AI systems.

- Record the object: deployed AI system, embedded AI safety component, standalone GPAI model, integrated GPAI model, traditional rules-based software, or manual activity.
- Describe the input, objective, autonomy level, inference method, output, and who or what the output can influence.
- If the item is rules-only software, document the human-authored rules and why the system does not infer predictions, content, recommendations, or decisions from inputs.
- If the item is a GPAI model, record whether it is only used internally, placed on the market, exposed through an API, directly downloaded, or integrated into an AI system.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) - Supports the AI system definition in Article 3(1), Recital 12's distinction from simpler software, and Recital 97's distinction between GPAI models and AI systems.
- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Explains the Commission's risk-based categories and notes that GPAI models can become the basis for AI systems in the EU.

## Step 2: test exclusions before assigning obligations

After the object is described, screen for exclusions. The sources identify exemptions for research, development, and prototyping before market release, and for AI systems exclusively designed for military, defence, or national security purposes.

The exclusion should be written narrowly. If a system built for an excluded purpose is later placed on the market, put into service, or used for a civilian, law-enforcement, public-security, or other non-excluded purpose, the applicability record should be reopened instead of carrying the old exclusion forward.

- Mark excluded only when the facts match the exclusion and the current or planned use does not cross into a non-excluded purpose.
- Separate pre-market research, development, or prototyping from market release, customer pilot, production use, and post-release modification.
- For military, defence, or national-security facts, record the purpose, user, contractual scope, and any dual-use or civilian pathway.
- If the exclusion is uncertain, continue the classification and flag the legal question instead of stopping the test.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) - Supports exclusions for military, defence, national-security, and certain scientific research and development contexts, including limits when systems are later used for non-excluded purposes.
- [European Commission - Navigating the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act?ref=sorena.io) - Commission Q&A confirms that research, development, and prototyping before market release and systems exclusively designed for military, defence, or national security purposes are exempt.

## Step 3: confirm territorial scope and operator role

The AI Act can apply to public and private actors inside and outside the EU when they place an AI system or GPAI model on the EU market, put an AI system into service, use it in the EU, or generate AI output used in the EU. The applicability record should state the exact EU link, not just whether the company is established in the Union.

Then assign the operator role for the same fact pattern. A product team may be a provider for one system, a deployer of a vendor system in another workflow, and a downstream provider if it integrates a GPAI model into its own AI system. Role drives the next evidence request.

- Record EU market placement, EU putting into service, EU use, EU users, EU customers, EU output use, and non-EU provider facts separately.
- Identify provider, deployer, importer, distributor, authorised representative, product manufacturer, GPAI model provider, and downstream integrator roles where applicable.
- For non-EU GPAI model providers, check whether an EU authorised representative is required before placing the model on the Union market.
- Do not rely on vendor marketing labels; attach contract terms, integration diagrams, deployment controls, and intended-purpose statements to the role decision.

Sources for this answer:

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) - Supports Article 2 scope and the operator-role structure used to route provider, deployer, importer, distributor, and GPAI obligations.
- [European Commission - Navigating the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act?ref=sorena.io) - Explains that the framework applies to actors inside and outside the EU that place AI systems or GPAI models on the EU market, put AI systems into service, or use them in the EU.
- [AI Act Service Desk - Article 54 authorised representatives for GPAI model providers](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-54?ref=sorena.io) - Supports the check for third-country GPAI model providers appointing an EU authorised representative and maintaining technical documentation access.

## Step 4: route the system through prohibited, high-risk, transparency, GPAI, and minimal-risk categories

Classify in order. First screen for prohibited AI practices because a banned use should not proceed as a normal compliance backlog. Then test high-risk status under product-safety links and Annex III use areas. After that, check transparency obligations for specific interactive or generative AI systems, and GPAI model obligations for model providers.

Minimal or no-risk classification is a residual answer. It should be used only after the prohibited, high-risk, transparency, and GPAI checks have been documented.

- Prohibited screen: manipulation or deception, exploitation of vulnerabilities, social scoring, individual predictive policing based solely on profiling, untargeted facial-image scraping, workplace or education emotion recognition except medical or safety reasons, biometric categorisation to infer protected characteristics, and real-time remote biometric identification for law enforcement in publicly accessible spaces subject to narrow exceptions.
- High-risk screen: check whether the AI is a safety component or product subject to covered product legislation, then check Annex III areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, administration of justice, and democratic processes.
- Article 6(3) exception screen: if an Annex III system is treated as not high-risk because it performs a narrow procedural, preparatory, improvement, or review task, keep the assessment documentation and EU database registration basis.
- Transparency screen: identify chatbots or other systems where people must know they are interacting with AI, generated or manipulated content, deep fakes, and public-interest text generated by AI.
- GPAI screen: for model providers, record technical documentation, downstream information, copyright-policy evidence, training-content summary evidence, and systemic-risk assessment where applicable.

Sources for this answer:

- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Supports the four risk levels, examples of prohibited and high-risk uses, transparency requirements, and GPAI rule overview.
- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) - Primary support for Articles 5, 6, 50, 53, 55, and Annex III classification logic.
- [European Commission - Guidelines for providers of general-purpose AI models](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers?ref=sorena.io) - Supports scope checks for GPAI model providers and the Commission's interpretation of GPAI provider obligations.

## Step 5: preserve the evidence record and reassessment trigger

The output of the applicability test should be a record that another reviewer can repeat. It should include the product facts, classification answer, source citation, owner, role decision, risk route, excluded-facts analysis, and the evidence used to support each conclusion.

For high-risk systems, the record should point to the downstream compliance artifacts: technical documentation, risk management, data governance, logging, instructions for use, human oversight, accuracy, robustness, cybersecurity, conformity assessment, registration, post-market monitoring, incident reporting, and deployer monitoring where relevant. For GPAI models, preserve model documentation, downstream provider information, representative mandate where required, and systemic-risk material where applicable.

- Evidence fields: system or model name, version, intended purpose, EU link, operator role, excluded-purpose analysis, prohibited-use screen, high-risk basis, transparency basis, GPAI basis, source URL, reviewer, approver, and date of decision.
- Attachments: architecture diagram, model card or technical documentation, supplier contract, instructions for use, user-facing notice, human-oversight procedure, logs, FRIA or DPIA reference when applicable, EU database registration evidence, and change history.
- Reassessment triggers: new EU launch, new user group, new intended purpose, substantial modification, new supplier or model version, GPAI integration change, new biometric or employment use, public-authority deployment, new generated-content feature, or authority guidance that changes the classification.
- Negative conclusions still need evidence: a not-AI-system, excluded, not-high-risk, or no-Article-50 answer should state the facts and source-based reason for that conclusion.

**What is the first question in an EU AI Act applicability test?**

Ask what object is being classified: an AI system, a GPAI model, traditional rules-based software, or a manual activity. The AI system definition turns on machine-based inference of outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

**Can a system be in an Annex III area but still be treated as not high-risk?**

Yes, Article 6(3) allows a provider to classify certain Annex III systems as not high-risk where the system does not pose a significant risk of harm and meets the listed conditions, such as a narrow procedural task or preparatory task. The provider should document the assessment and register the system as required.

**What evidence should teams keep for the EU AI Act applicability test?**

Keep the system or model description, intended purpose, EU scope facts, exclusion analysis, operator-role map, prohibited and high-risk screens, transparency and GPAI checks, source URLs, approvals, attached product evidence, and reassessment triggers.

Sources for this answer:

- [AI Act Service Desk - Article 49 registration](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-49?ref=sorena.io) - Supports evidence for registering high-risk AI systems and certain not-high-risk Article 6(3) classifications in the EU database.
- [AI Act Service Desk - Article 4 AI literacy](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4?ref=sorena.io) - Supports assigning trained staff or users to operate and use AI systems with sufficient AI literacy based on context and affected persons.
- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) - Primary support for keeping classification, technical, registration, monitoring, and GPAI documentation tied to the applicable obligation.

*Recommended next step*

*Placement: before sources*

## This EU AI Act guide helps classify scope, role, and risk category

Sorena can help turn the applicability steps on this page into cited intake questions, owner assignments, evidence requests, and reusable review logic for EU AI Act work.

- [Open Research Copilot for EU AI Act](/solutions/research-copilot.md): Ask questions tied to cited sources about AI Act scope, roles, high-risk routing, GPAI, transparency obligations, and evidence records using the cited sources on this page.
- [Talk through implementation](/contact.md): Review your AI Act applicability workflow, source gaps, and next implementation steps with Sorena.

## Primary sources

- [Regulation (EU) 2024/1689 (EU AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for AI system definition, scope, exclusions, operator roles, prohibited practices, high-risk classification, transparency duties, GPAI duties, registration, documentation, and evidence requirements.
  - Quote: "laying down harmonised rules on artificial intelligence"
- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission overview used for the risk-based framework, prohibited and high-risk examples, transparency category, and GPAI explanation.
  - Quote: "risk-based rules for AI developers and deployers"
- [European Commission - Navigating the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act?ref=sorena.io) - Commission Q&A used for territorial scope, actor coverage inside and outside the EU, exclusions, high-risk examples, transparency requirements, and GPAI summary.
  - Quote: "inside and outside the EU"
- [European Commission - Guidelines for providers of general-purpose AI models](https://digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers?ref=sorena.io) - Commission guidance page used for GPAI provider scope and obligations interpretation.
  - Quote: "general-purpose AI models"
- [AI Act Service Desk - Article 49 registration](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-49?ref=sorena.io) - Official AI Act Explorer page used for high-risk and Article 6(3) registration evidence.
  - Quote: "Before placing on the market"
- [AI Act Service Desk - Article 54 authorised representatives for GPAI model providers](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-54?ref=sorena.io) - Official AI Act Explorer page used for third-country GPAI model provider authorised-representative checks and document retention evidence.
  - Quote: "providers established in third countries"
- [AI Act Service Desk - Article 4 AI literacy](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-4?ref=sorena.io) - Official AI Act Explorer page used for AI literacy evidence where staff or other persons operate or use AI systems on behalf of providers or deployers.
  - Quote: "sufficient level of AI literacy"

## Related Topic Guides

- [Are industry AI use cases high-risk under EU AI Act Annex III?](/artifacts/eu/artificial-intelligence-act/faq/annex-iii-industry-use-cases.md): FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
- [EU AI Act AI System Classification Edge Cases FAQ](/artifacts/eu/artificial-intelligence-act/faq/ai-system-classification-edge-cases.md): Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
- [EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence](/artifacts/eu/artificial-intelligence-act/applicability-and-roles.md): Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
- [EU AI Act Article 5 Prohibited AI Practices Screening Guide](/artifacts/eu/artificial-intelligence-act/prohibited-ai-practices.md): Screen AI systems against the EU AI Act Article 5 prohibitions, including manipulation, exploitation, social scoring, biometric and law-enforcement exceptions.
- [EU AI Act Article 50 transparency disclosures FAQ](/artifacts/eu/artificial-intelligence-act/faq/article-50-transparency-disclosures.md): Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
- [EU AI Act Article 50 transparency, labeling, and user disclosures](/artifacts/eu/artificial-intelligence-act/transparency-labeling-and-user-disclosures.md): Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
- [EU AI Act Article 73 serious incident FAQ](/artifacts/eu/artificial-intelligence-act/faq/serious-incidents.md): FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
- [EU AI Act Compliance Checklist by Risk Class](/artifacts/eu/artificial-intelligence-act/checklist.md): A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
- [EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents](/artifacts/eu/artificial-intelligence-act/compliance.md): Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
- [EU AI Act conformity assessment and notified bodies for high-risk AI](/artifacts/eu/artificial-intelligence-act/conformity-assessment-and-notified-bodies.md): Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
- [EU AI Act deadlines and compliance calendar | Article 113 dates](/artifacts/eu/artificial-intelligence-act/deadlines-and-compliance-calendar.md): EU AI Act compliance calendar for Article 113 staged application dates, Article 111 transitions, GPAI, prohibited practices, AI literacy, and high-risk AI planning.
- [EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates](/artifacts/eu/artificial-intelligence-act/faq.md): Source-backed EU AI Act FAQ covering scope, provider and deployer roles, prohibited practices, high-risk classification, GPAI duties, transparency notices, FRIAs, EU database registration, serious incidents, and staged application dates.
- [EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification](/artifacts/eu/artificial-intelligence-act/faq/fria.md): Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
- [EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence](/artifacts/eu/artificial-intelligence-act/fria-and-high-risk-impact-assessments.md): Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
- [EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ](/artifacts/eu/artificial-intelligence-act/faq/gpai-and-systemic-risk-duties.md): FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
- [EU AI Act GPAI evidence pack checklist for Article 53 and 55](/artifacts/eu/artificial-intelligence-act/gpai-evidence-pack-workflow.md): Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
- [EU AI Act GPAI Provider Obligations: Articles 53 and 55](/artifacts/eu/artificial-intelligence-act/gpai-and-foundation-model-obligations.md): Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
- [EU AI Act High-Risk AI Requirements: Articles 8-16 and 26](/artifacts/eu/artificial-intelligence-act/requirements.md): Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
- [EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide](/artifacts/eu/artificial-intelligence-act/high-risk-ai-use-cases-by-industry.md): Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
- [EU AI Act high-risk conformity assessment route selector](/artifacts/eu/artificial-intelligence-act/high-risk-conformity-route-selector-workflow.md): Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
- [EU AI Act high-risk requirements checklist: Articles 8-15](/artifacts/eu/artificial-intelligence-act/high-risk-requirements-checklist.md): Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
- [EU AI Act penalties and fines: Article 99 tiers and GPAI exposure](/artifacts/eu/artificial-intelligence-act/penalties-and-fines.md): EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
- [EU AI Act post-market monitoring and serious incident reporting](/artifacts/eu/artificial-intelligence-act/post-market-monitoring-and-serious-incidents.md): Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
- [EU AI Act post-market monitoring FAQ for high-risk AI systems](/artifacts/eu/artificial-intelligence-act/faq/post-market-monitoring.md): Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
- [EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ](/artifacts/eu/artificial-intelligence-act/faq/provider-and-deployer-role-boundaries.md): FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
- [EU AI Act risk classification intake workflow](/artifacts/eu/artificial-intelligence-act/risk-classification-intake-workflow.md): A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
- [EU AI Act serious incident reporting triage workflow: Article 73 and Article 55](/artifacts/eu/artificial-intelligence-act/serious-incident-reporting-triage-workflow.md): Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
- [EU AI Act Technical Documentation and Provider Evidence Templates](/artifacts/eu/artificial-intelligence-act/technical-documentation-and-provider-evidence-templates.md): Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
- [EU AI Act technical documentation FAQ | Article 11 and Annex IV](/artifacts/eu/artificial-intelligence-act/faq/technical-documentation.md): What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
- [EU AI Act Timeline and Phasing Roadmap: practical obligations and evidence guide](/artifacts/eu/artificial-intelligence-act/timeline-and-phasing-roadmap.md): Practical EU AI Act guide to Timeline and Phasing Roadmap: scope, owners, evidence, edge cases, checklist steps, and external citations.
- [EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits](/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-iso-42001.md): Compare the EU AI Act and ISO/IEC 42001 across legal status, risk classification, high-risk AI, GPAI, transparency, conformity, evidence, and assurance limits.
- [EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries](/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-nist-ai-rmf.md): Compare the binding EU AI Act with the voluntary NIST AI RMF, including role classification, high-risk duties, GPAI, transparency, conformity evidence, and reuse limits.
- [FAQ: EU AI Act conformity assessment procedures and notified body selection](/artifacts/eu/artificial-intelligence-act/faq/conformity-assessment-and-notified-bodies.md): cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/artificial-intelligence-act/applicability-test
