Methodology v1.1 · versioned · auditable

How Reglynn classifies AI systems

The exact sequence of legal questions behind every assessment, in the order they're checked, with the Articles each step rests on. If you disagree with a step, you can see precisely where.

Last updated 8 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

Most AI Act tools give you an answer. This page shows you how Reglynn reaches one — the exact sequence of legal questions, in the order they're checked, with the Articles each step rests on. If you disagree with a step, you can see precisely where and why.

We publish this for the same reason we publish our own self-assessment: a compliance tool that won't show its reasoning is asking you to take exactly the kind of undocumented position it warns you about.

The four-step classification

Every Reglynn assessment runs the same sequence. Order matters — each step either removes obligations or narrows them, which is why the report never assigns another party's duties to you.

Step 1 — Role in the value chain

Provider, deployer, distributor or importer (Articles 3, 16, 23–26). Determined first, because it decides which obligation set can even apply. The report checks for the two traps: teams assuming "provider" because they built something (when the AI system itself is licensed, they're deployers), and substantial modification silently converting a deployer into a provider. Full reasoning.

Step 2 — GPAI check (Article 53)

Whether the team's use of a foundation model keeps them downstream (API calls, prompting, light in-domain fine-tuning) or crosses into GPAI-provider territory (substantial retraining, new task domain). Checked before risk tier, because Article 53 duties attach regardless of tier. The threshold in detail.

Step 3 — Risk tier, worked top-down

Article 5 prohibited practices first; then Annex III / Annex I high-risk; then the Article 6(3) exemption — checked every time a system lands in an Annex III area, with the profiling condition treated as absolute, because it is; then Article 50 limited-risk transparency; then minimal risk. The 6(3) test.

Step 4 — Obligations, deadlines and priorities

Each applicable obligation mapped to its post-Omnibus date — not the pre-June 2026 dates still circulating. Fines are stated under the Article 99(6) SME rule: for SMEs the applicable fine is the lower of the fixed amount and the turnover percentage — the inverse of the large-company rule. A report that quotes €15M at a ten-person company is wrong, and we treat it as a correctness bug.

The decision tree

OrderQuestionIf yesIf no
1Is it an AI system (Art 3(1)) with an EU nexus (Art 2)?ContinueOut of scope — document why, stop
2Do you place it on the market under your name?Provider dutiesDeployer / distributor path (Arts 23–26)
3Did you substantially modify a third-party system?Provider duties inheritedRole stands
4Substantial retrain of a general-purpose model?GPAI provider — Art 53 attachesDownstream — Art 53 is your model vendor's
5Article 5 prohibited practice?Unacceptable — product decision, not complianceContinue
6Annex III or Annex I area?Check 6(3) ↓Skip to 8
7Art 6(3): narrow/preparatory/procedural AND no profiling of persons?Exempt — document + registerHigh Risk — Chapter III by Dec 2027
8Interacts with people or generates content?Limited Risk — Art 50, live nowMinimal Risk — Art 4 literacy

What the engine will not do

Sources and review

The methodology is built directly on Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus — Articles 2–6, 16, 23–26, 50, 53, 99 and Annexes I, III, XI, XII — read alongside published Commission guidance. Reports are generated by an AI system against this question set and risk logic, and reviewed before delivery (how we classify ourselves).

When the regulation moves, the methodology moves, and the change is logged publicly in the regulatory changelog. Paid reports include a 12-month re-issue: if the rules materially change, we re-run your assessment once, free.

Versions

VersionDateChange
v1.1August 2026Methodology published. Reflects June 2026 Omnibus deadlines and enforcement live since 2 Aug 2026.
v1.0July 2026Initial four-step engine: role → GPAI → tier (with 6(3)) → obligations. Art 99(6) SME fine rule enforced in output.

Run it on your system

The same four-step logic, applied to your answers. Free tier in two minutes; the full report when you need the documented version.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.