Verified Digital Agents → C2MD → Assess agent risk
Assess Agent Risk
Describe an agent in plain language. Get back its risk position under the EU AI Act and the GDPR at the same time — because in practice they are not separate questions, and answering them separately is how obligations get missed.
Live · free tier
What it determines
| Output | Why it matters |
|---|---|
| Risk category, including Annex III classification where it applies | High-risk classification is what turns Articles 9–15 from good practice into mandatory obligations, and may trigger Article 49 registration. |
| Provider vs deployer role | The same system carries different duties depending which you are. Organisations routinely assume "deployer" and are in fact a provider — most often by putting their own name on a system, or by substantially modifying one. |
| Lawful-basis analysis | GDPR Article 6. An agent that cannot name its lawful basis is not ready to process, whatever its AI Act position. |
| Special-category data flags | Article 9 data pulls in a materially stricter regime — and it is often reached by inference rather than by field, which is exactly what a description-level review catches. |
| DPIA / FRIA triggers | Tells you whether GDPR Article 35 and EU AI Act Article 27 assessments are required, before you find out during review. |
Why both regimes at once
A CV-screening agent is Annex III high-risk and processes personal data on a lawful basis that has to hold up and may infer special-category data it was never given. Run those as three reviews and the interactions fall between them. This runs them as one, so the DPIA trigger is visible in the same output as the Annex III classification that helps cause it.
Worked example
Northwind Bank — credit-decision agent risk assessment Demo data
Ask for it in plain language
- "Assess the risk position of an agent that screens CVs and ranks candidates for interview."
- "Is our credit-decision agent Annex III high-risk, and are we the provider or the deployer?"
- "Does this agent trigger a DPIA, a FRIA, or both?"
What happens next
The assessment is the on-ramp. From it you can generate the governance bundle the agent will actually follow, scaffold the DPIA or FRIA it triggered, and hand the whole set to ACP to version, review and sign.