If you operate AI systems within the European Union, one question should be at the top of your compliance agenda: what risk level does each of your AI systems carry under the EU AI Act? Getting this classification right determines everything — your compliance obligations, documentation requirements, and potential penalties of up to 35 million EUR or 7% of global turnover.
The good news: the classification framework is logical, based on use cases rather than underlying technology. The challenge: many businesses underestimate where their systems fall. This guide walks you through the four risk tiers, gives you concrete examples, and shows you how to classify your own AI systems step by step.
Why Classification Matters
Under the EU AI Act (Regulation 2024/1689), every AI system that operates within the EU must be classified into one of four risk tiers. This classification is not optional — it is the foundation of your entire compliance strategy. The risk tier determines:
- Obligations: What documentation, testing, and oversight you must implement
- Timeline: When your compliance deadline hits (prohibited practices already banned since Feb 2025; high-risk obligations by Aug 2026)
- Cost: Whether compliance requires near-zero effort or significant investment
- Penalties: Fines scale with risk tier — up to 35M EUR for banned AI, up to 15M EUR for high-risk violations
The critical insight is that classification depends on the use case, not the technology. The same GPT-4 model used as a customer FAQ chatbot is limited risk, but used to screen job applicants it becomes high risk. This is why you cannot simply classify "your AI" — you must classify each specific deployment.
The Four Risk Tiers Explained
The AI Act establishes a risk-based pyramid. Here is each tier, from most to least regulated:
Tier 1: Unacceptable Risk — Banned Outright
These AI systems are prohibited under Article 5 of the AI Act. If you operate any of these, you must discontinue immediately.
- ✕ Social scoring systems that evaluate people based on behavior or personality
- ✕ AI that exploits vulnerabilities of specific groups (children, elderly, disabled)
- ✕ Real-time remote biometric identification in public spaces (with narrow law enforcement exceptions)
- ✕ Emotion recognition in workplace and educational settings
- ✕ Untargeted scraping of facial images to build recognition databases
Tier 2: High Risk — Strict Compliance Required
Defined in Article 6 and Annex III, these systems require comprehensive compliance measures including risk management, data governance, technical documentation, human oversight, and conformity assessment.
- ✓ AI in recruitment: CV screening, candidate ranking, interview analysis
- ✓ Credit scoring and loan approval systems
- ✓ AI in education: exam scoring, student assessment, admissions
- ✓ Medical diagnostic AI and clinical decision support
- ✓ AI managing critical infrastructure (energy, water, transport)
- ✓ Biometric identification and categorization systems
Tier 3: Limited Risk — Transparency Obligations
Under Article 50, these systems must clearly inform users they are interacting with AI. This is where most customer-facing business AI falls.
- ✓ Customer service chatbots and virtual assistants
- ✓ AI-generated content (text, images, audio, video)
- ✓ Emotion recognition systems (where not banned)
- ✓ Deepfake and synthetic media generation
Tier 4: Minimal Risk — No Specific Requirements
The vast majority of AI systems fall here. No mandatory compliance requirements, though voluntary codes of conduct are encouraged.
- ✓ Spam filters and email categorization
- ✓ Product recommendation engines
- ✓ AI-powered search optimization
- ✓ Video game AI and entertainment systems
- ✓ Inventory management and demand forecasting
Step-by-Step Classification Process
Follow this systematic approach to classify every AI system in your organization:
Build Your AI Systems Inventory
List every AI-powered tool, service, and model your organization uses. Include third-party SaaS tools with embedded AI — many companies forget that their CRM's predictive scoring, their HR platform's CV parser, or their marketing tool's audience segmentation all count as AI systems under the Act.
Identify the Use Case for Each System
For each system, document its specific purpose. Be precise: "AI chatbot for customer FAQ" is different from "AI chatbot for medical symptom checking." The use case — not the underlying model — determines the risk tier.
Check Against Annex III (High-Risk List)
Annex III of the AI Act lists specific use cases that are automatically classified as high risk. Cross-reference each of your AI systems against this list. Key areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.
Check for Transparency Triggers
If a system is not high risk, check if it interacts directly with people (chatbots), generates synthetic content (deepfakes, AI text), or performs emotion recognition. If yes, it is limited risk with transparency obligations under Article 50.
Document Your Classification Rationale
For each system, record your classification decision and the reasoning behind it. This documentation serves as evidence of your compliance effort and is essential if your classification is ever questioned by regulators.
Pro tip: You can automate this process. Our free AI Act Risk Classifier walks you through the classification in under 5 minutes per system — no signup required.
Common Classification Mistakes SMEs Make
After helping dozens of businesses with AI Act compliance, we see the same mistakes repeatedly:
Mistake 1: Underclassifying to Avoid Compliance
Some businesses classify their HR screening AI as "limited risk" hoping to avoid high-risk obligations. Regulators will look at the actual use case, not your classification label. A misclassified high-risk system carries penalties of up to 15 million EUR.
Mistake 2: Ignoring Embedded AI in Third-Party Tools
Your organization likely uses AI through SaaS platforms without realizing it. If your CRM uses AI to score leads, your HR platform uses AI to rank candidates, or your accounting software uses AI for fraud detection — those are your AI systems to classify. The Act applies to deployers, not just developers.
Mistake 3: Confusing Provider vs. Deployer Roles
The AI Act distinguishes between providers (who develop the AI system) and deployers (who use it). As a deployer, you still have obligations — particularly for high-risk systems. You must ensure human oversight, maintain logs, and monitor performance, even if you did not build the AI yourself.
Mistake 4: Classifying the Technology Instead of the Use Case
A large language model is not inherently high or low risk. A GPT model powering a customer FAQ chatbot is limited risk. The same GPT model evaluating employee performance is high risk. Always classify the specific deployment, not the underlying technology.
Industry-Specific Classification Examples
Here are real-world scenarios that illustrate how classification works across industries:
Employee trustworthiness scoring
An AI system that scores employee reliability based on social media activity and personal behavior patterns. This constitutes social scoring and is banned outright.
AI-powered CV screening for recruitment
An HR platform that automatically filters and ranks job applicants. Falls under Annex III, area 4 (employment) — requires full compliance including risk management system, data governance, and human oversight.
AI credit scoring for loan applications
A fintech tool that assesses creditworthiness of individuals. Falls under Annex III, area 5 (access to essential services) — strict requirements apply.
Customer service chatbot on your website
A chatbot answering product questions. Must disclose that users are interacting with AI (transparency obligation under Article 50), but no further compliance requirements.
AI-generated marketing copy
Using AI to write product descriptions or ad copy. Must be labeled as AI-generated content, but no further compliance burden.
AI-powered spam filter
Email filtering using machine learning. No specific compliance requirements under the AI Act.
Inventory demand forecasting
AI predicting stock levels and reorder points. Internal operational tool with no direct impact on individuals — minimal risk, no obligations.
What to Do After Classification
Once you have classified all your AI systems, your next steps depend on what you found:
- If all minimal risk: Document your classification decisions and monitor for any changes in usage that could shift the risk level. You have minimal compliance burden but should still maintain awareness.
- If limited risk: Implement transparency measures (disclosure notices, AI labeling) and document your compliance approach. Read our full compliance guide for specific steps.
- If high risk: Begin compliance planning immediately. You need a risk management system, data governance framework, technical documentation, human oversight protocols, and conformity assessment. The August 2026 deadline is closer than you think.
- If unacceptable: Discontinue the system immediately. Prohibited practices have been banned since February 2025.
Classify Your AI Systems in 5 Minutes
Not sure where your AI systems fall? Our free risk classifier walks you through the process step by step — answer a few questions about each system and get an instant risk assessment with tailored compliance recommendations.
Ready to remove manual work?
Tell us which workflow slows the team down. We will map the automation path and the ROI case.
Book a Strategy CallAlso Read
- AROG AI at Infoshare 2026 in Gdansk: What We Took from the Innovation Stage
- AI Agent Readiness Assessment: A 2026 Scoring Framework for Business Processes
- EU AI Act Article 50 for Chatbots and AI Assistants: 2026 Transparency Checklist
- n8n Consultant: How to Scope, Hire, and Get Real ROI from Workflow Automation
- AI Automation Consulting: What It Includes, What It Costs, and How to Choose a Firm
- AI Automation ROI: How to Calculate and Prove Value to Your Board
- EU AI Act August 2026: Your 90-Day Compliance Action Plan
- The Complete Guide to Business Process Automation with AI
- AI Agents vs Traditional RPA: Which Automation Approach Fits Your Business?
- 5 Free AI Tools to Assess Your Business Automation Potential
- AI Act Compliance Checklist for SMEs
- How Much Does AI Act Compliance Cost?
- EU AI Act 2025: What Every Business Needs to Know
- 5 Business Processes You Should Automate With AI Today
- AI Audit vs AI Consultation: Which Does Your Business Need?




