Most AI Act tools give you an answer. This page shows you how Reglynn reaches one — the exact sequence of legal questions, in the order they're checked, with the Articles each step rests on. If you disagree with a step, you can see precisely where and why.
We publish this for the same reason we publish our own self-assessment: a compliance tool that won't show its reasoning is asking you to take exactly the kind of undocumented position it warns you about.
The four-step classification
Every Reglynn assessment runs the same sequence. Order matters — each step either removes obligations or narrows them, which is why the report never assigns another party's duties to you.
Step 1 — Role in the value chain
Provider, deployer, distributor or importer (Articles 3, 16, 23–26). Determined first, because it decides which obligation set can even apply. The report checks for the two traps: teams assuming "provider" because they built something (when the AI system itself is licensed, they're deployers), and substantial modification silently converting a deployer into a provider. Full reasoning.
Step 2 — GPAI check (Article 53)
Whether the team's use of a foundation model keeps them downstream (API calls, prompting, light in-domain fine-tuning) or crosses into GPAI-provider territory (substantial retraining, new task domain). Checked before risk tier, because Article 53 duties attach regardless of tier. The threshold in detail.
Step 3 — Risk tier, worked top-down
Article 5 prohibited practices first; then Annex III / Annex I high-risk; then the Article 6(3) exemption — checked every time a system lands in an Annex III area, with the profiling condition treated as absolute, because it is; then Article 50 limited-risk transparency; then minimal risk. The 6(3) test.
Step 4 — Obligations, deadlines and priorities
Each applicable obligation mapped to its post-Omnibus date — not the pre-June 2026 dates still circulating. Fines are stated under the Article 99(6) SME rule: for SMEs the applicable fine is the lower of the fixed amount and the turnover percentage — the inverse of the large-company rule. A report that quotes €15M at a ten-person company is wrong, and we treat it as a correctness bug.
The decision tree
| Order | Question | If yes | If no |
|---|---|---|---|
| 1 | Is it an AI system (Art 3(1)) with an EU nexus (Art 2)? | Continue | Out of scope — document why, stop |
| 2 | Do you place it on the market under your name? | Provider duties | Deployer / distributor path (Arts 23–26) |
| 3 | Did you substantially modify a third-party system? | Provider duties inherited | Role stands |
| 4 | Substantial retrain of a general-purpose model? | GPAI provider — Art 53 attaches | Downstream — Art 53 is your model vendor's |
| 5 | Article 5 prohibited practice? | Unacceptable — product decision, not compliance | Continue |
| 6 | Annex III or Annex I area? | Check 6(3) ↓ | Skip to 8 |
| 7 | Art 6(3): narrow/preparatory/procedural AND no profiling of persons? | Exempt — document + register | High Risk — Chapter III by Dec 2027 |
| 8 | Interacts with people or generates content? | Limited Risk — Art 50, live now | Minimal Risk — Art 4 literacy |
What the engine will not do
- Assign another party's duties. Deployers are never given conformity-assessment obligations; downstream fine-tuners are never given Article 53.
- Quote the wrong fine. Article 99(6) is applied to every SME-sized company.
- Use pre-Omnibus dates. Every deadline is the current one, and the report carries a regulation-version stamp.
- Certify anything. The output is a self-assessment position with reasons — the thing a procurement questionnaire actually asks for — not a certificate.
Sources and review
The methodology is built directly on Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus — Articles 2–6, 16, 23–26, 50, 53, 99 and Annexes I, III, XI, XII — read alongside published Commission guidance. Reports are generated by an AI system against this question set and risk logic, and reviewed before delivery (how we classify ourselves).
When the regulation moves, the methodology moves, and the change is logged publicly in the regulatory changelog. Paid reports include a 12-month re-issue: if the rules materially change, we re-run your assessment once, free.
Versions
| Version | Date | Change |
|---|---|---|
| v1.1 | August 2026 | Methodology published. Reflects June 2026 Omnibus deadlines and enforcement live since 2 Aug 2026. |
| v1.0 | July 2026 | Initial four-step engine: role → GPAI → tier (with 6(3)) → obligations. Art 99(6) SME fine rule enforced in output. |
Run it on your system
The same four-step logic, applied to your answers. Free tier in two minutes; the full report when you need the documented version.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.