AI Act Risk Classification in 10 Minutes — A Practical Self-Check for Companies
In our previous article we reviewed what the EU AI Act is and which companies it affects. Now let's look at how you can determine, as a first step, which risk category your company's AI system falls into.
The classification determines what obligations you face: documentation, human oversight, conformity assessment, registration, or CE marking. The exact legal qualification requires separate examination in more complex cases — but for a first self-check, it's enough to go through a few basic questions.
Three things to clarify before classification
1. Are we even talking about an AI system?
According to Article 3 of the AI Act, an AI system is a machine-based system based on machine learning or logic, which operates autonomously and generates outputs — predictions, recommendations, decisions, or content — from input data. A simple Excel formula or traditional business software is not AI.
2. What is it used for, and how?
What matters for classification is not the technology but the purpose and the way it's used. The same chatbot can be low-risk if it provides information, and high-risk if it evaluates candidates during a job interview.
3. Who is the user, and who is affected?
If the system makes decisions about or influences people — employees, customers, citizens — that is a different consideration than supporting a purely technical process (e.g. server monitoring).
Once you've clarified these three, you can move on to the actual decision.
Step 1: Is your system prohibited?
We rarely encounter this category, but it's the first one to rule out. Article 5 of the AI Act expressly prohibits certain AI practices, for example:
- Calculating a general "trustworthiness score" based on social behaviour (social scoring)
- Subliminal manipulation of people's behaviour against their will
- Emotion recognition in workplaces or schools (in certain contexts)
- Real-time biometric identification in public spaces for law enforcement (with limited exceptions)
If your system falls into any of these, it's not a documentation question — you simply cannot operate it.
Step 2: Is it high-risk?
A system can become high-risk in two ways.
A) It is part of a regulated product or a safety component. If the AI system is part of a product that already falls under EU harmonization legislation — e.g. medical devices, motor vehicles, machinery, toys, and other harmonized products — and a third-party conformity assessment is required, then it is automatically high-risk. This mainly affects industrial, healthcare, and automotive companies — if you don't operate in such a sector, you can safely skip this point.
B) It falls into one of the 8 areas of Annex III. The regulation lists 8 areas where AI systems are automatically considered high-risk (unless an exemption applies — more on that in step 3):
- Biometrics — remote biometric identification, emotion recognition, biometric categorisation
- Critical infrastructure — safety components for transport, water, gas, heating, electricity, digital infrastructure
- Education and vocational training — admission decisions, exam evaluation, access to education, plagiarism detection
- Employment and workforce management — recruitment, screening, promotion, workplace monitoring, task allocation
- Essential private and public services — credit scoring, insurance risk, benefits decisions, emergency service prioritisation
- Law enforcement — crime risk prediction, profiling, evidence evaluation
- Migration and border control — visa decisions, asylum decision support
- Justice and democratic processes — judicial decision support, electoral interference detection
If your AI system falls into any of these, it is high-risk by default. But there is an exemption option.
Step 3: Can it be exempted from high-risk status? (Article 6(3))
Annex III is not a verdict — there is a way out. A system does not qualify as high-risk if at least one of the following (a)–(d) conditions is met:
- (a) it performs only a narrow procedural task (e.g. document formatting)
- (b) it improves the result of human work without replacing the decision
- (c) it detects decision-making patterns without replacing human evaluation
- (d) it performs a preparatory task for human decision-making
AND in addition, the system:
- does not profile natural persons, AND
- does not pose a significant risk to people's health, safety, or fundamental rights
If the system meets all of these, you're still not entirely off the hook: you must document the assessment, and in certain cases register the system in the EU AI Act public database (Article 71). This is an EU-level electronic register where Annex III systems must be entered even if they ultimately do not qualify as high-risk under an exemption — but you are exempted from full high-risk compliance.
Step 4: Limited or minimal risk?
If you've ruled out prohibited and high-risk, only two options remain:
- Limited risk — this includes chatbots, generative AI systems, and deepfakes. Transparency obligations apply here: users must be informed that they are interacting with AI or viewing AI-generated content.
- Minimal risk — everything else. Most enterprise AI applications fall here (spam filtering, AI-supported search, product recommenders). There are no specific obligations — but a short internal inventory of the AI tools used, an internal AI usage policy, and basic AI literacy for the team are all good practice.
Summary
In a first approximation, risk classification can be done in 10 minutes. The main question is always the same: what do you use the system for, who is affected, and to what extent does it influence human decisions.
For more complex systems, however, it's worth being cautious. Misclassification leads to either missed obligations or unnecessarily over-engineered compliance processes — neither of which is cheap.
Looking for a more detailed assessment?
If your company's AI systems are borderline, or you'd like an independent review of your risk categories, we offer two options:
- Try our AI Act risk self-check webapp — it walks you through 19 questions with a live dashboard, and you'll get a PDF result at the end.
- Or request a free AI auditor consultation — in a 30-minute call we'll go through your system's classification and the next steps.
Try the self-check tool Request a consultation
In our next article we'll look at how a simple customer service chatbot can become a serious legal risk — through 5 real-world scenarios.
Related resources
Try the AI Act risk classifier
Find out in 5 minutes which risk category your AI system falls into — free, 100% private, with a detailed PDF result.