New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

EU AI Act

Risk classification

The EU AI Act does not regulate AI uniformly. It regulates it in proportion to risk, which makes classification the hinge the entire Act turns on. A system's classification determines its obligations, its documentation, its deadlines and its penalty exposure.

Transcript

Risk classification is the hinge the entire AI Act turns on. The Act regulates AI in proportion to risk, so this outcome determines which obligations you carry.

There are four outcomes. Prohibited practices under the AI Act's Article 5 cannot be deployed at all, and the platform enforces that: a Prohibited classification blocks that system's deployment status from ever becoming production. High-risk systems carry the full obligation set. Limited-risk systems carry transparency duties. Minimal-risk systems carry none.

Opening a registered system, we start its risk assessment directly from the system workspace.

The assessment walks the AI Act's Article 6 and Annex 3 criteria as structured questions: intended purpose, the people affected, the system's autonomy, and the potential for harm to health, safety or fundamental rights.

The AI Act's Annex 3 lists eight high-risk areas: biometrics, critical infrastructure, education, employment, essential services including credit scoring, law enforcement, migration, and the administration of justice.

Here is the computed classification, with a score and the reasoning recorded against it. This system lands in one of the AI Act's Annex 3 areas, so it is high-risk.

The recorded reasoning is the point. Most high-risk systems are self-assessed under the AI Act's Annex 6 internal control, so the regulator reviews your assessment after the fact. A classification you cannot justify is not a defence.

A high-risk result automatically generates the full obligation set: risk management, data governance, documentation, logging, transparency, human oversight and cybersecurity.

Why this is required

There are four outcomes, and they are not a spectrum of severity so much as four different legal regimes.

Prohibited practices under Article 5 cannot be deployed at all, at any level of care. These include social scoring by public authorities, untargeted scraping of facial images, emotion recognition in workplaces and educational institutions, exploitation of vulnerabilities of specific groups, and certain predictive policing based solely on profiling. These provisions have applied since 2 February 2025.

High-risk systems are defined by Article 6. A system is high-risk if it is a safety component of a product covered by the Annex I legislation, or if it falls within one of the eight areas in Annex III: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services including credit scoring, law enforcement, migration and border control, and the administration of justice.

Limited-risk systems carry transparency duties under Article 50: people must be told they are interacting with an AI, and synthetic audio, image, video or text content must be marked as artificially generated. Minimal-risk systems carry no specific obligations beyond voluntary codes.

Article 6(3) provides a narrow derogation: a system in an Annex III area is not high-risk if it does not pose a significant risk of harm, for instance because it performs a narrow procedural task. Relying on that derogation requires you to document your assessment, which is precisely why the platform records reasoning rather than just outcomes.

What EuroCompliant does

The assessment presents the Annex III criteria as structured questions covering intended purpose, the people affected, the system's autonomy, and the potential for harm to health, safety or fundamental rights.

It produces a classification with the answers retained alongside it, so the result is traceable to the reasoning that produced it.

You can override the outcome where you have grounds. The override, its author and its justification are all recorded. An override is a defensible judgement only if it is documented as one.

Classifying a system as high-risk automatically generates its full obligation set: the AI Act's Articles 9 through 15, plus registration, conformity assessment and post-market monitoring.

A Prohibited outcome is enforced, not just recorded: the platform automatically raises a critical compliance action naming the system, and blocks that system's deployment status from being set to production anywhere in the platform until the classification changes.

Deadlines

2 February 2025Article 5 prohibitions are already in force and enforceable.
2 December 2027High-risk obligations apply to Annex III systems: risk management, data governance, documentation, logging, oversight and accuracy must all be in place. (Postponed from 2 August 2026 by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026.)

Walking through it

1

Confirm the system is not prohibited

The assessment screens for the AI Act's Article 5 practices first. This is a stop condition, not a risk rating: a prohibited practice cannot be mitigated into permissibility.

Open /compliance-docs →
2

Answer the classification questions

Purpose, affected persons, autonomy and potential harm. Answer against how the system is actually used, not how it was marketed internally.

3

Review the classification and its reasoning

Check that the recorded rationale matches your understanding of the system before accepting it.

4

Document any override

If you override the outcome, including relying on the AI Act's Article 6(3) derogation, record why. An undocumented override is indistinguishable from an error.

5

Work the generated obligations

A high-risk classification produces the full checklist. That is the beginning of the work, not the end of it.

Open /compliance-docs →

The law

Penalties for non-compliance

Article 99 sets penalties of up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for deploying a prohibited practice. Breaching other obligations attracts up to €15 million or 3%. Supplying incorrect or misleading information to authorities attracts up to €7.5 million or 1%.

Frequently asked

Our system is in an Annex III area but only assists a human decision. Is it still high-risk?

Probably yes. Article 6(3) exempts systems performing narrow procedural tasks or purely preparatory work, but a system that materially influences a human decision is generally still high-risk. Notably, any system that profiles natural persons is always high-risk if it falls in an Annex III area; the derogation is not available.

Who decides the classification: us, or a regulator?

You do, in the first instance. The Act is a self-assessment regime for most high-risk systems, with conformity assessment via internal control under Annex VI. That is exactly why the reasoning must be documented: the regulator reviews your assessment after the fact.

What if a system's purpose changes later?

Reclassify it. Classification follows intended purpose, so a change of purpose can move a system between categories, and a substantial modification can make you a provider of it under Article 25.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial