Pre-assessment

In this section you can perform a pre-assessment of your AI system based on an initial risk approach that is based on the European legislation on artificial intelligence (AI Act). This determines different obligations taking into account a risk approach (meaning the greater or lesser likelihood of harm occurring and the severity of this harm) according to four categories:

Unacceptable risk:

This refers to a very limited set of uses of AI that are particularly harmful and contravene EU values, as they infringe fundamental rights and are therefore prohibited.

High risk

This refers to a limited number of AI systems that may have an adverse impact on the security of individuals or their fundamental rights under the EU Charter of Fundamental Rights and are therefore considered high risk.

Limited risk

This refers to the risks associated with a lack of transparency in the use of AI and therefore the need for specific transparency obligations to ensure that humans are informed when necessary, building trust.

Minimal risk

This refers to all other AI systems that can be developed and used in accordance with existing legislation without additional legal obligations. On a voluntary basis, providers of such systems may choose to apply ethical principles such as those of the PIO Model.

Establishment of unacceptable risk or prohibited uses

EU legislation on artificial intelligence includes in Article 5 a set of practices that are considered unacceptable risks because they impinge on fundamental rights and human security in such a serious way that their use cannot be allowed. For this reason, any AI system that matches any of these practices may not be placed on the market, developed or used within the territory of the EU.

Below is a list of unacceptable uses. If any of these apply to your system, it is not necessary to complete the questions in the Model, as the Model is designed to assess systems that may actually be used in accordance with the legislation.

Prohibited uses

Select risk

This table contains the practices considered as prohibited uses under Article 5 of Regulation 2024/1689 of the Parliament and of the Council on Artificial Intelligence (AI Act).

Systems that deploy subliminal, deceptive or manipulative techniques that alter the behaviour of a person or group of persons to make a decision that causes significant harm to themselves or others.

AI systems that exploit the vulnerabilities of an individual or group of individuals (e.g. age, social or economic status or mental capacity) by altering their behaviour in a way that causes significant harm to themselves or others.

?

AI systems that assess or classify individuals or groups of individuals over a given period of time on the basis of their social behaviour or personal or other known, inferred or expected characteristics with the following effects:

  1. Detrimental or unfavourable treatment of individuals or groups of individuals in social contexts that are unrelated to the contexts in which the data were originally collected or generated. 
  2. Detrimental or unfavourable treatment of certain individuals or groups of individuals that is unjustified or disproportionate to their social behaviour or seriousness.

AI systems that conduct risk assessments of natural persons for the purpose of assessing or predicting the risk of a person committing a crime based solely on profiling and assessment of their personality traits and characteristics.

?

AI systems that create or extend facial recognition databases by non-selectively dumping facial images from the internet or recordings from video surveillance cameras.

AI systems that influence the emotions of a natural person in the domains of the workplace and educational institutions.

?

Biometric categorisation systems that individually categorise natural persons on the basis of their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.

?

Real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes.

?

Establishment of high risk, limited risk or low risk

In this section you will find the questions that will allow you to know the level of risk associated with your system beyond unacceptable risk or prohibited uses. To complete the pre-assessment, please follow the circuit below:

High risk

Select risk

This table contains the practices considered high-risk by Article 6 of Regulation 2024/1689 of the Parliament and of the Council on Artificial Intelligence (AI Act). If you answer yes to one or more of the following questions, you can consider your system to be in this risk group.

Exceptions

Is your system used by or on behalf of judicial authorities to investigate, interpret facts and legal rules or apply the law; used similarly in alternative dispute resolution (e.g. in a mediation process); or to influence the outcomes of democratic processes or voting behaviour?

?

Is your AI system a product, or is it a safety component of a product, subject to the European regulations contained in Annex I of the AI Act?

Is your AI system a product, or is it a safety component of a product, which must undergo a third party conformity assessment before it can be placed on the market or put into service in accordance with the European regulations contained in Annex I of the IA Act?

Is your system used for biometric identification and categorisation of natural persons based on sensitive data or emotion recognition (not including systems that only confirm the identity of the natural person)?

Is your system used by public administrations to manage and operate critical infrastructures, real-time traffic, gas, water, heat or electricity supply?

Is your system used in education or vocational training to determine admission or access of learners; to assess outcomes, or the appropriate level of education; or to monitor and detect prohibited behaviour?

Is your system used in the field of access to employment, self-employment and employee management (e.g. recruitment, modification of employment relationships, performance appraisal)?

Is your system used by public or private entities that provide essential services (e.g. a system that determines which people will be eligible for public financial assistance or admission to private social programmes)?

Is your system used in the legal field by law enforcement authorities, agencies, administrations or institutions to assess a person’s risk of being a victim of criminal offences; in the use of polygraphs or similar tools; to assess evidence used during investigations; or to assess the likelihood of offending or re-offending, beyond profiling?

Is your system used in migration, asylum and border control as polygraphs or similar tools to assess risks (in security, health and irregular migration) of a person entering the territory of a state; to examine asylum, visa or residence permit applications, as well as complaints about the adjudication of such applications; or to detect, recognise or identify persons (except for travel document verification)?

Limited risk

Select risk

This table contains the practices considered to be of limited risk relating to generative AI systems and emotion recognition and biometric identification systems not included as prohibited or high-risk systems under Article 50 and the practices relating to general-purpose systems under Article 51 of Regulation 2024/1689 of the Parliament and of the Council on artificial intelligence (AI Act). If you answer yes to one or more of the following questions, then you may consider that your system is considered to be in this risk group.

El vostre sistema té la capacitat de servir per a una varietat de propòsits, tant per a l’ús directe
com per a la integració en altres sistemes d’IA?

El vostre sistema es utilitzat per a crear contingut de text, so, imatge o vídeo?

?

El vostre sistema és tracta d’una eina de reconeixement d’emocions o categorització biomètrica?

?

El vostre sistema d’IA està pensat per interactuar amb persones físiques?

?

Is your system a general-purpose model?

?

Minimal risk

Select risk

If your system does not fall into any of the above categories, it may be considered to be of minimal risk. While Regulation 2024/1689 of the Parliament and of the Council on Artificial Intelligence (AI Act) may require some transparency requirements for certain AI systems of this type, it does not impose additional obligations on systems considered as minimal risk, but invites you to commit to codes of conduct or an ethical assessment on a voluntary basis.

Once you know the risk category associated with your AI system, you can start the assessment questionnaire.

Start PIO Model

Practical examples of implementation of the IA Act

In case you are not sure whether the European legislation on artificial intelligence (AI Act) is applicable in your case, as well as the possible applicable risk category, we provide you with 50 practical examples of the application of the AI Act according to the level of risk. Obviously, these are indicative examples and, in all cases, they only serve as a reference guide and are therefore not exhaustive and should always be contextualised.

A company in the health sector uses an AI-powered application for patient triage.

A company implements a surveillance system with cameras equipped with facial recognition for the security of its facilities.

A public institution uses voice recognition technology to analyse the prioritisation of telephone calls.

An educational institution uses an AI system to track students’ academic performance and predict potential dropouts.

A hospital uses an AI system to analyse medical images to help diagnose diseases.

A health centre uses an AI system to manage appointments and organise waiting lists.

A social services office uses AI to identify families at risk of vulnerability and provide proactive support.

A company uses AI for recruitment, analysing candidates’ CVs and predicting their potential performance.

A bank uses AI to analyse credit applications and assess the creditworthiness of applicants.

An insurance company uses AI to assess the monthly premiums to be paid by a person taking out life insurance.

An energy company uses AI to predict potential power supply incidents.

A transport company has trucks with an automated driving system.

An AI system is used to identify the authenticity of documents used as evidence in the investigation of a crime.

The railway authorities in two bordering countries use an AI system to optimise train scheduling and manage cross-border traffic.

A transport company installs an AI system in its vehicles to optimise delivery routes and reduce transport times.

A university uses AI to analyse enrolment data and determine access criteria for the future academic year.

A legal services company uses ChatGPT or Copilot to draft documentation for its clients’ residency applications and analyse the likelihood of success.

A company uses a biometric system to control access to its offices based on fingerprints.

A humanitarian aid organisation engages a general-purpose AI model to analyse the needs of communities affected by natural disasters and plan aid distribution.

A company uses a general-purpose AI model to personalise online advertising based on users’ browsing behaviour.

A company provides its employees with a ChatGPT service to generate emails and other texts.

A company has developed a synthetic imaging tool based on an LLM and uses it to generate images for its work documents.

A company has a chatbot on its website to answer general queries about the company.

A public institution uses a general purpose model to predict crowds such as demonstrations or similar events based on social network data.

An e-commerce platform uses AI provided by a bigtech trained on massive datasets to recommend products to customers based on their shopping preferences.

A company uses an AI system that generates personalised contract proposals.

A logistics company uses general-purpose AI to predict bottlenecks in the supply chain and avoid delays.

A telecommunications company uses AI to optimise the network, improve quality of service and autonomously execute individual supply modifications for its customers.

A weather service uses AI to make weather forecasts and warn people about extreme weather events and produce reports.

A nationwide energy company uses AI to predict demand, optimise electricity distribution and analyse the consumption habits of dry customers.

An architectural firm uses AI to generate innovative designs based on customer preferences and market trends.

A general-purpose AI is installed in a crop irrigation system to determine the amount of water needed and the frequency of irrigation based on weather conditions and the season of the year.

A veterinary clinic commissions an AI trained with its own data to diagnose diseases in pets based on symptoms described by owners.

A company implements smart sensors in its factories and warehouse to control its stock.

A pharmacy uses AI to manage drug stocks and warn when there are only a few units of a drug left.

A supermarket uses AI to analyse customer buying patterns and optimise inventory.

A restaurant has acquired an AI trained on its historical data to analyse customer preferences and adjust the menu according to demand.

A library uses AI to manage the book catalogue and order the reading catalogue by putting the most requested books first.

A weather service uses AI to create a compilation of rainfall over the past century in a specific geographical area.

A company that manufactures notebooks uses AI to detect defects in production and improve product quality.

A food company uses AI to monitor product quality during the production process.

A restaurant has acquired an AI trained on its historical data to analyse customer preferences and adjust the menu according to demand.

A company uses an AI system to filter incoming mail to detect negative comments about its brand and make improvements.

A human resources company uses AI to analyse employee satisfaction data and improve the work environment.

A company uses an AI system that automatically organises its electronic files.

An AI system that corrects students’ mental arithmetic activities.

A municipal swimming pool uses an AI to regulate the chlorine level and water temperature.

An AI system is installed in a greenhouse that activates the irrigation ditch when it detects a drop in humidity.

A rural tourism house uses an AI system to regulate the indoor temperature in relation to the outdoor temperature as long as it is rented.

A hairdressing salon uses an AI system to supply the stock of dye colours according to the demand of its clientele on a monthly basis.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.