AITENCY — Custom AI Systems
Back to Blog
·9 min read

EU AI Act Risk Classification: Is Your AI System High-Risk?

S
EU AI ActAI ComplianceAI Risk Management

TL;DR

The EU AI Act sorts every AI system into four risk tiers — prohibited, high-risk, limited-risk, and minimal-risk — and the tier you land in decides whether you face millions in compliance obligations or almost none. Most businesses panic when they hear "AI Act" and assume they are high-risk; the reality is that the vast majority of internal AI tools (customer support bots, marketing copilots, internal search, content tools) sit in the limited-risk tier with transparency obligations only. High-risk is a narrowly defined list in Annex III: biometric ID, critical infrastructure, education access, employment decisions, essential services access, law enforcement, migration, justice. The hidden trap is "substantial modification" — when you fine-tune or repurpose someone else’s model deeply enough that you legally become the provider yourself and inherit their full obligations. This article gives you a five-question decision tree, an Annex III deep dive, the substantial-modification trap explained, and a self-assessment checklist so you can classify your system in 30 minutes.

Every business in Europe building or buying AI right now is asking the same question, usually three weeks too late: is this thing we just built classified as high-risk under the EU AI Act? The honest answer for most internal AI tools is no — but the cost of getting it wrong is now real, with fines up to €35M or 7% of global turnover and enforcement ramping through 2026.

This article walks through EU AI Act risk classification without the legal jargon. By the end you will be able to look at your own AI system and put it in one of four boxes with reasonable confidence — which is most of what you need to start a compliance conversation that does not waste everyone's time. For the broader regulatory context first, start with the 2026 EU AI Act overview and the full compliance guide.

Key Takeaways:

  • The EU AI Act defines four risk tiers: prohibited, high-risk, limited-risk, and minimal-risk. Your tier determines your entire compliance bill.
  • A high-risk AI system is one that falls into Annex III's 8 narrowly defined categories (biometric ID, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) — or is a safety component of a product already regulated under EU product law.
  • Most internal business AI (support bots, content tools, marketing copilots, internal search, predictive maintenance) sits in the limited-risk tier with transparency obligations only — typically a "you are talking to AI" disclosure.
  • "Substantial modification" is the trap: if you significantly fine-tune or repurpose a third-party model, you can legally become the provider and inherit their full obligations, including conformity assessment for high-risk uses.
  • General-purpose AI models (GPT-class, Claude-class) are regulated separately from how you use them — your application's risk tier is determined by your use case, not the underlying model.
  • A 30-minute self-assessment is enough to classify 90% of internal AI systems. The remaining 10% need a written legal opinion.
  • Misclassification penalties under the Act are not theoretical: declaring a high-risk system as limited-risk can trigger fines up to €15M or 3% of global turnover.

The Four Risk Tiers, with Business Examples

The EU AI Act risk classification framework is a pyramid: a tiny prohibited tier at the top, a narrow high-risk band below it, a wide limited-risk middle, and a vast minimal-risk base where most internal AI lives.

The four tiers are defined in Articles 5, 6, 50, and the general scope of the Act, and the obligations attached to each are radically different.

TierWhat it MeansExamplesYour Obligation
ProhibitedBanned outright under Article 5Social scoring by public authorities, real-time biometric ID in public spaces (with narrow exceptions), emotion recognition in workplaces/schools, predictive policing based on profiling, untargeted facial scrapingDo not deploy. Fines up to €35M / 7% global turnover.
High-RiskAnnex III list + safety components of EU-regulated productsCV-screening AI in HR, credit-scoring AI, AI in medical devices, AI controlling critical infrastructure, AI in essential services access decisions, biometric categorisationFull conformity assessment, risk management system, data governance, human oversight, technical documentation, post-market monitoring, registration in EU database. Fines up to €15M / 3%.
Limited RiskAI that interacts with humans, generates synthetic content, or uses emotion/biometric categorisation outside high-risk usesCustomer support chatbots, AI content generators, deepfake/synthetic-media tools, internal AI assistants, marketing copywritersTransparency obligations: tell users they are interacting with AI; label AI-generated content. Fines up to €15M / 3% for breach of transparency.
Minimal RiskEverything else — most business AISpam filters, predictive maintenance, inventory forecasting, AI-assisted analytics, internal search, recommendation engines, fraud detection (non-credit)No mandatory obligations. Voluntary codes of conduct encouraged.

The reason this matters: a high-risk classification adds a conformity-assessment process that typically costs €30K–€150K plus 6–18 months of work, plus ongoing post-market monitoring. A limited-risk classification adds a paragraph of disclosure text. The gap between the two is the entire compliance budget of most mid-sized companies.

Decision Tree: Classify Your AI System in Five Questions

This five-question sequence sorts 90% of internal AI systems correctly. Run it before you start writing compliance documentation.

Answer in order. Stop at the first "yes" — that is your tier.

  1. Does the system do anything listed in Article 5? Social scoring, untargeted biometric scraping, real-time public biometric ID, emotion recognition at work or school, manipulative/exploitative dark patterns, predictive policing by profiling. → Prohibited. Stop and redesign.
  2. Is the system a safety component of a product already regulated under EU product safety law (medical devices, machinery, toys, automotive, aviation, etc.) listed in Annex I?High-risk by default, governed by the existing product-safety regime plus AI Act requirements.
  3. Does the system make or materially assist decisions in one of the 8 Annex III categories? (Biometric ID/categorisation, critical infrastructure, education/training access, employment/HR, essential private and public services access, law enforcement, migration/asylum/border, administration of justice/democratic processes.) → High-risk.
  4. Does the system directly interact with humans, generate synthetic content, recognise emotions, or categorise biometric data?Limited risk (transparency obligations only).
  5. Everything else.Minimal risk (no mandatory obligations).

If you answered "no" to questions 1–3 and "yes" to question 4, you are in the same bucket as most chatbots and content tools. If you answered "no" to all of 1–4, you are in the minimal-risk bucket where most internal automation lives. We discussed why the chatbot label confuses this question in what business leaders get wrong about chatbots.

Annex III Deep Dive: The 8 High-Risk Categories

Annex III is the operative list — if your system is not on it (and not a regulated product safety component), it is not a high-risk AI system, full stop.

The Act's high-risk scope is defined narrowly and deliberately. Many businesses assume "AI making decisions about people" is automatically high-risk; it is not. It is high-risk only if the decision domain is one of these eight:

#CategoryPlain-English Examples
1Biometric identification & categorisationFace recognition systems, biometric categorisation by sensitive attributes
2Critical infrastructureAI managing water, gas, electricity, road traffic, digital infrastructure
3Education & vocational trainingAI deciding admission, grading high-stakes exams, monitoring exam cheating
4Employment, workers, self-employmentCV screening, candidate ranking, AI-driven hiring/firing/promotion decisions, task allocation, performance evaluation
5Essential private & public servicesCredit scoring, life/health insurance pricing, public benefits eligibility, emergency dispatch prioritisation
6Law enforcementPredictive risk assessment, evidence-evaluation AI, profiling for investigations
7Migration, asylum, border controlRisk assessment of migrants, document verification at borders, asylum eligibility
8Administration of justice & democratic processesAI assisting judicial decisions, electoral-process AI

Two things to notice. First, most of these are public-sector or heavily regulated industries — financial services, insurance, HR, public administration, law enforcement. Second, within those domains, only specific use cases are high-risk. An HR chatbot answering policy questions is not high-risk. An AI that ranks candidates and feeds the ranking into a hiring decision is.

The Act also includes a "narrow exception" mechanism in Article 6(3): if your system falls into one of the Annex III categories but is purely preparatory, narrow, or does not materially influence the decision, you can document that and exit high-risk classification. This is a real and useful escape hatch — but it requires written justification kept on file.

The Substantial Modification Trap

If you fine-tune or significantly modify a third-party model, you can legally become the "provider" and inherit their full high-risk obligations — including conformity assessment.

This is the part of the Act that catches sophisticated technical teams off-guard. The Act distinguishes between a provider (the entity that develops or has developed an AI system and places it on the market) and a deployer (the entity using it). Providers carry most of the regulatory weight; deployers have much lighter obligations, primarily around appropriate use and human oversight.

But Article 25 says: if you put your name on a high-risk AI system, substantially modify it, or modify its intended purpose so it becomes high-risk when it was not before, you are treated as the provider. You inherit the conformity assessment, the technical documentation, the post-market monitoring, the registration.

In practice, this affects:

  • Fine-tuning a GPT-class or Claude-class model on your proprietary data and deploying it for, say, employment screening. You are now the provider of a high-risk system.
  • Wrapping a third-party AI API in your own product, branding it, and using it in an Annex III context.
  • Repurposing a general-purpose tool the vendor sold as "limited risk" into a high-risk context (e.g., a generic chatbot used to make benefits-eligibility decisions).

The mitigation is contractual and architectural. Keep the high-risk decision logic clearly attributable to your supplier where possible. If you must modify, document the modification scope carefully. If you are using a custom-built system from a partner, make sure the contract clearly allocates provider responsibility. We covered the partner-selection angle in how to evaluate an AI implementation partner and the broader build-vs-modify question in AI automation vs. custom AI systems.

Limited Risk: What Most Businesses Actually Need to Worry About

For 80% of mid-market businesses, the entire EU AI Act compliance task is a transparency disclosure on chatbots and AI-generated content. That is it.

Limited-risk obligations under Article 50 are narrow:

  • AI systems that directly interact with humans must inform users they are interacting with AI, unless it is obvious from context.
  • AI-generated audio, image, video, and text intended to inform the public must be labelled as AI-generated (with narrow exceptions for clearly artistic or satirical work).
  • Emotion-recognition and biometric-categorisation systems must inform people they are being subjected to them.
  • Deepfakes must be labelled as artificial.

That is the full list. In practice it usually translates into:

  • A "you are chatting with an AI assistant" line on your support chatbot.
  • An "AI-generated content" disclosure on marketing material produced by AI.
  • A short paragraph in your privacy notice.
  • A documented internal policy saying these disclosures exist.

Total compliance cost: a paragraph of legal text and a few UI changes. Compared with high-risk obligations, it is trivial. The temptation is to over-engineer — to treat every AI system as if it were high-risk "to be safe." Resist that temptation. Misclassifying as high-risk costs you 100× more than classifying correctly and documenting the rationale.

Self-Assessment Checklist

Run through this checklist for each AI system. If you answer it honestly in 30 minutes, you have enough to start a compliance conversation that is not a fishing trip.

For every AI system in your business, document the following:

  • [ ] System name and one-line purpose. What does it do, in one sentence?
  • [ ] Provider vs. deployer. Are you the provider (built or substantially modified) or deployer (using a third-party as intended)?
  • [ ] Article 5 check. Does the system do anything prohibited? Answer with a Yes/No and a one-line rationale.
  • [ ] Annex I / Annex III check. Is it a safety component of a regulated product, or does it operate in one of the 8 Annex III categories? Cite the specific category if yes.
  • [ ] Article 6(3) exception. If Annex III applies, is the system narrowly preparatory or non-influential enough to qualify for the exception? Document the rationale.
  • [ ] Human interaction check. Does it talk to humans, generate synthetic content, recognise emotion, or categorise biometric data?
  • [ ] Final classification. Prohibited / High-Risk / Limited Risk / Minimal Risk — with a one-paragraph justification.
  • [ ] Owner. Who in your business is accountable for keeping this classification current?
  • [ ] Review date. When will you re-check this? (At least annually, or whenever the system is materially modified.)

For limited-risk and minimal-risk systems, that document is your entire compliance file. For high-risk systems, it is the cover page of a much larger one. Either way, EU AI Act risk classification starts with this 30-minute exercise, and almost every common compliance mistake we see comes from skipping it.

FAQ

What makes an AI system high-risk under the EU AI Act?

A high-risk AI system is one that either acts as a safety component of a product regulated under existing EU product-safety law (Annex I), or operates in one of eight specific decision domains listed in Annex III: biometric ID, critical infrastructure, education access, employment, essential services access, law enforcement, migration/borders, and administration of justice. If your system is outside those lists, it is not high-risk, regardless of how sophisticated it is.

Is my customer support chatbot high-risk?

Almost certainly not. A support chatbot answering product questions falls into the limited-risk tier — your obligation is to disclose that users are interacting with AI. It only becomes high-risk if the chatbot is making decisions in an Annex III category, e.g., determining eligibility for credit or social benefits.

What is the substantial modification trap?

If you fine-tune or significantly repurpose a third-party AI model — for example, taking a general-purpose language model and tuning it for HR screening — you can legally become the provider of that system and inherit the original provider's full high-risk obligations. The trap is that this happens automatically once the modification is "substantial," and there is no bright line in the text. Document modifications carefully and review with counsel before deployment in any Annex III context.

Do small businesses have to comply with the EU AI Act risk classification rules?

Yes. The Act applies regardless of company size — though there are accommodations for SMEs in the form of fee reductions, simplified documentation, and access to regulatory sandboxes. For most SMEs operating in limited-risk or minimal-risk tiers, the practical burden is small. SMEs deploying high-risk systems still need the full conformity assessment.

How often do I need to re-check my classification?

At minimum annually, and whenever the system is materially modified, repurposed, or expanded into a new decision domain. The classification is not a one-time exercise — your tier can change if you change what the system does.

Get Your Risk Assessment

EU AI Act risk classification is a 30-minute job for most internal AI systems and a much larger one for high-risk applications. Either way, the cheapest moment to do it is before deployment, not after the first enforcement letter arrives.

If you want a structured review of your current and planned AI systems — provider vs. deployer status, tier classification per system, the documentation you actually need (and the documentation you do not) — book a free 30-minute call. We will walk through your stack, classify the systems in real time, and leave you with a written assessment template you can keep using internally. No commitment beyond the call.

Ready to Explore Automation for Your Business?

Start with a free process audit — we'll identify the highest-value automation opportunities in your operations.

Book a Discovery Call