Skip to main content
AI Regulation

How to Classify Your AI System Under the EU AI Act

Learn the four risk tiers of the EU AI Act, see real-world classification examples, and follow our step-by-step process to determine where your AI systems fall.

AROG AI Team
March 25, 2026
10 min read
Key Takeaways
  • 1The EU AI Act classifies AI systems into 4 risk tiers with different compliance obligations
  • 2Most business AI systems fall into limited or minimal risk — but some common tools are high-risk
  • 3Classification depends on the USE CASE, not the technology — the same model can be different risk levels
  • 4Start with a full AI systems inventory before attempting classification

If you operate AI systems within the European Union, one question should be at the top of your compliance agenda: what risk level does each of your AI systems carry under the EU AI Act? Getting this classification right determines everything — your compliance obligations, documentation requirements, and potential penalties of up to 35 million EUR or 7% of global turnover.

The good news: the classification framework is logical, based on use cases rather than underlying technology. The challenge: many businesses underestimate where their systems fall. This guide walks you through the four risk tiers, gives you concrete examples, and shows you how to classify your own AI systems step by step.

Why Classification Matters

Under the EU AI Act (Regulation 2024/1689), every AI system that operates within the EU must be classified into one of four risk tiers. This classification is not optional — it is the foundation of your entire compliance strategy. The risk tier determines:

  • Obligations: What documentation, testing, and oversight you must implement
  • Timeline: When your compliance deadline hits (prohibited practices already banned since Feb 2025; high-risk obligations by Aug 2026)
  • Cost: Whether compliance requires near-zero effort or significant investment
  • Penalties: Fines scale with risk tier — up to 35M EUR for banned AI, up to 15M EUR for high-risk violations

The critical insight is that classification depends on the use case, not the technology. The same GPT-4 model used as a customer FAQ chatbot is limited risk, but used to screen job applicants it becomes high risk. This is why you cannot simply classify "your AI" — you must classify each specific deployment.

The Four Risk Tiers Explained

The AI Act establishes a risk-based pyramid. Here is each tier, from most to least regulated:

Tier 1: Unacceptable Risk — Banned Outright

These AI systems are prohibited under Article 5 of the AI Act. If you operate any of these, you must discontinue immediately.

  • Social scoring systems that evaluate people based on behavior or personality
  • AI that exploits vulnerabilities of specific groups (children, elderly, disabled)
  • Real-time remote biometric identification in public spaces (with narrow law enforcement exceptions)
  • Emotion recognition in workplace and educational settings
  • Untargeted scraping of facial images to build recognition databases

Tier 2: High Risk — Strict Compliance Required

Defined in Article 6 and Annex III, these systems require comprehensive compliance measures including risk management, data governance, technical documentation, human oversight, and conformity assessment.

  • AI in recruitment: CV screening, candidate ranking, interview analysis
  • Credit scoring and loan approval systems
  • AI in education: exam scoring, student assessment, admissions
  • Medical diagnostic AI and clinical decision support
  • AI managing critical infrastructure (energy, water, transport)
  • Biometric identification and categorization systems

Tier 3: Limited Risk — Transparency Obligations

Under Article 50, these systems must clearly inform users they are interacting with AI. This is where most customer-facing business AI falls.

  • Customer service chatbots and virtual assistants
  • AI-generated content (text, images, audio, video)
  • Emotion recognition systems (where not banned)
  • Deepfake and synthetic media generation

Tier 4: Minimal Risk — No Specific Requirements

The vast majority of AI systems fall here. No mandatory compliance requirements, though voluntary codes of conduct are encouraged.

  • Spam filters and email categorization
  • Product recommendation engines
  • AI-powered search optimization
  • Video game AI and entertainment systems
  • Inventory management and demand forecasting

Step-by-Step Classification Process

Follow this systematic approach to classify every AI system in your organization:

1

Build Your AI Systems Inventory

List every AI-powered tool, service, and model your organization uses. Include third-party SaaS tools with embedded AI — many companies forget that their CRM's predictive scoring, their HR platform's CV parser, or their marketing tool's audience segmentation all count as AI systems under the Act.

2

Identify the Use Case for Each System

For each system, document its specific purpose. Be precise: "AI chatbot for customer FAQ" is different from "AI chatbot for medical symptom checking." The use case — not the underlying model — determines the risk tier.

3

Check Against Annex III (High-Risk List)

Annex III of the AI Act lists specific use cases that are automatically classified as high risk. Cross-reference each of your AI systems against this list. Key areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.

4

Check for Transparency Triggers

If a system is not high risk, check if it interacts directly with people (chatbots), generates synthetic content (deepfakes, AI text), or performs emotion recognition. If yes, it is limited risk with transparency obligations under Article 50.

5

Document Your Classification Rationale

For each system, record your classification decision and the reasoning behind it. This documentation serves as evidence of your compliance effort and is essential if your classification is ever questioned by regulators.

Pro tip: You can automate this process. Our free AI Act Risk Classifier walks you through the classification in under 5 minutes per system — no signup required.

Common Classification Mistakes SMEs Make

After helping dozens of businesses with AI Act compliance, we see the same mistakes repeatedly:

Mistake 1: Underclassifying to Avoid Compliance

Some businesses classify their HR screening AI as "limited risk" hoping to avoid high-risk obligations. Regulators will look at the actual use case, not your classification label. A misclassified high-risk system carries penalties of up to 15 million EUR.

Mistake 2: Ignoring Embedded AI in Third-Party Tools

Your organization likely uses AI through SaaS platforms without realizing it. If your CRM uses AI to score leads, your HR platform uses AI to rank candidates, or your accounting software uses AI for fraud detection — those are your AI systems to classify. The Act applies to deployers, not just developers.

Mistake 3: Confusing Provider vs. Deployer Roles

The AI Act distinguishes between providers (who develop the AI system) and deployers (who use it). As a deployer, you still have obligations — particularly for high-risk systems. You must ensure human oversight, maintain logs, and monitor performance, even if you did not build the AI yourself.

Mistake 4: Classifying the Technology Instead of the Use Case

A large language model is not inherently high or low risk. A GPT model powering a customer FAQ chatbot is limited risk. The same GPT model evaluating employee performance is high risk. Always classify the specific deployment, not the underlying technology.

Industry-Specific Classification Examples

Here are real-world scenarios that illustrate how classification works across industries:

UNACCEPTABLE

Employee trustworthiness scoring

An AI system that scores employee reliability based on social media activity and personal behavior patterns. This constitutes social scoring and is banned outright.

HIGH RISK

AI-powered CV screening for recruitment

An HR platform that automatically filters and ranks job applicants. Falls under Annex III, area 4 (employment) — requires full compliance including risk management system, data governance, and human oversight.

HIGH RISK

AI credit scoring for loan applications

A fintech tool that assesses creditworthiness of individuals. Falls under Annex III, area 5 (access to essential services) — strict requirements apply.

LIMITED RISK

Customer service chatbot on your website

A chatbot answering product questions. Must disclose that users are interacting with AI (transparency obligation under Article 50), but no further compliance requirements.

LIMITED RISK

AI-generated marketing copy

Using AI to write product descriptions or ad copy. Must be labeled as AI-generated content, but no further compliance burden.

MINIMAL RISK

AI-powered spam filter

Email filtering using machine learning. No specific compliance requirements under the AI Act.

MINIMAL RISK

Inventory demand forecasting

AI predicting stock levels and reorder points. Internal operational tool with no direct impact on individuals — minimal risk, no obligations.

What to Do After Classification

Once you have classified all your AI systems, your next steps depend on what you found:

  • If all minimal risk: Document your classification decisions and monitor for any changes in usage that could shift the risk level. You have minimal compliance burden but should still maintain awareness.
  • If limited risk: Implement transparency measures (disclosure notices, AI labeling) and document your compliance approach. Read our full compliance guide for specific steps.
  • If high risk: Begin compliance planning immediately. You need a risk management system, data governance framework, technical documentation, human oversight protocols, and conformity assessment. The August 2026 deadline is closer than you think.
  • If unacceptable: Discontinue the system immediately. Prohibited practices have been banned since February 2025.

Classify Your AI Systems in 5 Minutes

Not sure where your AI systems fall? Our free risk classifier walks you through the process step by step — answer a few questions about each system and get an instant risk assessment with tailored compliance recommendations.

Keep Reading

Related Articles