Verified Digital Agents → C2MD → Assess agent risk

Assess Agent Risk

Describe an agent in plain language. Get back its risk position under the EU AI Act and the GDPR at the same time — because in practice they are not separate questions, and answering them separately is how obligations get missed.

Live · free tier

What it determines

OutputWhy it matters
Risk category, including Annex III classification where it applies High-risk classification is what turns Articles 9–15 from good practice into mandatory obligations, and may trigger Article 49 registration.
Provider vs deployer role The same system carries different duties depending which you are. Organisations routinely assume "deployer" and are in fact a provider — most often by putting their own name on a system, or by substantially modifying one.
Lawful-basis analysis GDPR Article 6. An agent that cannot name its lawful basis is not ready to process, whatever its AI Act position.
Special-category data flags Article 9 data pulls in a materially stricter regime — and it is often reached by inference rather than by field, which is exactly what a description-level review catches.
DPIA / FRIA triggers Tells you whether GDPR Article 35 and EU AI Act Article 27 assessments are required, before you find out during review.
A classification is a reviewable position, not a determination. Where the answer is genuinely indeterminate the assessment says so rather than picking a side — an "indeterminate" system must not be relied upon until a Compliance Officer and legal determination resolve it. Confident output on an ambiguous classification would be the failure mode, not the feature.

Why both regimes at once

A CV-screening agent is Annex III high-risk and processes personal data on a lawful basis that has to hold up and may infer special-category data it was never given. Run those as three reviews and the interactions fall between them. This runs them as one, so the DPIA trigger is visible in the same output as the Annex III classification that helps cause it.

Worked example

Northwind Bank — credit-decision agent risk assessment Demo data

Ask for it in plain language

What happens next

The assessment is the on-ramp. From it you can generate the governance bundle the agent will actually follow, scaffold the DPIA or FRIA it triggered, and hand the whole set to ACP to version, review and sign.