Clef · Try the live demo →
EU AI Act · classification

The use case is classified, not the technology

The same language model is minimal risk when it summarises internal documents and high risk when it screens job applicants. Which means the question "is this product high risk" has no answer, and the question that does — "what are we using it for" — is one only you can answer.

The four tiers

01

Unacceptable risk

Article 5prohibited since 2 February 2025

Eight practices banned outright, regardless of safeguards, consent or documentation. Seven are theoretical for ordinary businesses. One is not: inferring emotions in the workplace, which turns up as a side feature in call analytics, recruiting software and video interview platforms — usually under a name like sentiment analysis or engagement score.

02

High risk

Article 6 with Annexes I and IIIAnnex III from 2 December 2027, Annex I from 2 August 2028

The substantive obligations: risk management as a continuous process, data governance, technical documentation, logging, human oversight, conformity assessment. Annex III was originally due on 2 August 2026; Regulation (EU) 2026/1744 moved both dates, which is why older tables still show 2026.

03

Transparency risk

Article 50in force since 2 August 2026

No prohibition and no conformity assessment — disclosure. People must be able to tell they are dealing with a machine, and generated content must be detectable as such. This tier was not postponed, which makes it the only one that newly bound deployers in 2026.

04

Minimal risk

no specific obligations

Everything else, and by volume that is almost everything: spell-checking, spam filtering, search, summarising for internal use, translation. Voluntary codes of conduct are envisaged; binding requirements are not.

The eight areas of Annex III

High risk under Annex III means a standalone system used in one of these areas. The list is closed and the Commission may amend it — but it is not a general principle to be reasoned from, which is what makes classification tractable.

  • 01Biometrics — remote identification, categorisation, emotion inference outside prohibited contexts
  • 02Critical infrastructure — safety components in traffic, water, gas, heating, electricity
  • 03Education — admission, assignment, assessment, and monitoring of prohibited behaviour during tests
  • 04Employment — recruitment, selection, promotion, termination, task allocation, monitoring
  • 05Essential services — creditworthiness, health and life insurance pricing, emergency dispatch, public benefits
  • 06Law enforcement — risk assessment, evidence evaluation, profiling
  • 07Migration and border control — risk assessment, application examination, document verification
  • 08Justice and democratic processes — assisting in legal research and interpretation, influencing elections

The list is given in abbreviated form; the Regulation text governs. Note that Annex I is a separate route: AI as a safety component in products already covered by Union harmonisation law, which reaches manufacturers rather than deployers.

Why general-purpose models are not a fifth tier

Because they are governed by a different chapter with a different addressee. Obligations for providers of general-purpose AI models have applied since 2 August 2025, with additional requirements where a model presents systemic risk. That is a regime for model providers, not a rung on the risk ladder.

Two consequences follow for a deployer, and both are practical. First: the fact that your supplier uses a regulated model says nothing about your classification. Second: your classification does not change when the model underneath changes — a document assistant is the same use case whether GPT, Claude or an open-weight model on your own hardware sits behind it.

Which is a good argument for doing the classification carefully once. It survives the technology change, and the technology will change more than once before the Annex III deadline arrives.

Frequently asked

What risk categories does the EU AI Act define?+

Four: unacceptable risk (prohibited practices under Article 5), high risk (Annexes I and III), transparency risk (Article 50) and minimal risk with no specific obligations. Classification follows the use case rather than the technology — the same language model is minimal risk when summarising internal documents and high risk when screening job applicants.

How do we classify our own use case?+

Two questions cover the ordinary case. Does the purpose fall inside one of the eight areas of Annex III, or is the system a safety component of a product already covered by Union harmonisation law? And does the system interact with people or generate content that gets published? The first question decides high risk; the second decides transparency obligations, and it is the one more often overlooked because attention goes to the high-risk regime that does not apply to most deployers.

Who performs the classification — us or the vendor?+

The provider classifies when placing the system on the market, but that does not bind you. If you deploy a system for a purpose the provider did not intend, it may classify differently in your hands — and under Article 25 you can become a provider yourself by doing so. A short written classification with reasons belongs in your own records even when the conclusion is "minimal".

Are general-purpose models a fifth category?+

No, and this is the most common misreading. Models with general purpose are governed by their own chapter addressed to model providers, not by the risk pyramid; their obligations have applied since 2 August 2025, with additional ones for models presenting systemic risk. For a deployer, what determines classification is the use case, not the model underneath it.

Did the postponement change the categories?+

Only the dates. Annex III moved from 2 August 2026 to 2 December 2027 and Annex I from 2 August 2027 to 2 August 2028. The criteria are unchanged, and the classification should be done well before the deadline anyway: it determines what you buy and what you write into supplier contracts, and those run for years.

What if we classify too low and are wrong?+

A documented and reasoned classification that later proves too low is a materially different position from an absent one. In the first case diligence is evidenced and the classification gets corrected; in the second there is no record that the question was ever asked. Article 99 requires authorities to weigh the measures taken, and this is exactly where that weighing bites.

Is there an official classification tool?+

Several unofficial questionnaires circulate and some are useful for orientation. None of them is a conformity route, and a printout from one is not a classification — what is expected is a reasoned judgement about your specific purpose, which a generic questionnaire cannot produce because it does not know what you do.