Is Your AI System High-Risk? Classify It Under the EU AI Act in 20 Minutes
Frenkie
· 7 min read

You classify an AI system under the EU AI Act by checking four risk tiers in order: prohibited practice, high-risk (via two routes), limited-risk transparency duties, and minimal risk. Most systems land in minimal risk, but the check itself is now mandatory homework.
Look, classification is the single decision that sets your entire compliance bill. Get it wrong in one direction and you build conformity documentation nobody asked for. Get it wrong in the other and you ship an unregistered high-risk system.
Run this self-check first. Twenty minutes, five questions:
Does the system do anything on the banned list? Social scoring, untargeted facial scraping, emotion recognition at work or school, manipulation causing harm, plus the new ban on AI that generates non-consensual intimate imagery or CSAM. If yes, stop. It cannot be placed on the EU market at all.
Is it a product, or a safety component of a product, covered by EU product law in Annex I? Think medical devices, machinery, lifts, radio equipment, requiring third-party conformity assessment. If yes: high-risk via Article 6(1).
Does its intended purpose fall in an Annex III use case? Biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, justice. If yes: presumed high-risk via Article 6(2).
If you hit Annex III, does the Article 6(3) filter apply? Four escape conditions exist, and meeting any single one is enough. Profiling of people cancels the filter every time.
If none of the above: does it talk to humans or generate content? Then Article 50 transparency duties apply: disclose the chatbot, label the deepfake, and mark generated content machine-readably by 2 December 2026.
Now the detail behind each door.
What are the four risk tiers of the EU AI Act?
The AI Act sorts systems into prohibited practices (banned), high-risk (heavy obligations), limited-risk (transparency duties), and minimal risk (no specific obligations), based on intended purpose rather than technology.
That last clause is the part teams miss. The same model can sit in different tiers depending on what you say it is for. Your instructions for use, marketing pages, and technical documentation define the "intended purpose" regulators will read. Write them like evidence, because they are.
When is an AI system high-risk?
An AI system is high-risk through one of two routes: it is a regulated product or its safety component under Annex I, or its intended purpose matches a use case listed in Annex III.
The two routes now carry different deadlines after the Digital Omnibus, which we covered in our timeline breakdown:
Annex III standalone systems (hiring screeners, credit scoring, exam proctoring, and similar): obligations apply from 2 December 2027.
Annex I embedded systems (AI inside medical devices, machinery, vehicles): obligations apply from 2 August 2028.
Two Omnibus refinements matter for borderline cases. The "safety component" definition was narrowed: an AI component that merely assists users or optimizes performance, without creating health or safety risk, is out of scope. And the deadlines are now fixed dates, not conditions tied to standards availability.
Can you escape high-risk with the Article 6(3) filter?
Yes, an Annex III system avoids high-risk classification if it meets any one of four conditions: it performs a narrow procedural task, improves a previously completed human activity, detects decision patterns without replacing human assessment, or does preparatory work only.
Two warnings before you celebrate:
Profiling kills the filter. If the system profiles natural persons, it stays high-risk regardless of the four conditions.
The filter is not free. You must document your Article 6(3) assessment before placing the system on the market and register the system in the EU database. Legal commentators reading the new draft guidelines warn the filter is narrower than many providers assume.
Our practical read: treat the filter as a documented legal position, not a checkbox. If your answer depends on a generous interpretation of "narrow procedural task," get counsel involved.
What do the new draft guidelines change, and why does 23 July matter?
On 19 May 2026 the European Commission published draft guidelines interpreting Article 6, with worked examples of systems that are and are not high-risk, and the stakeholder consultation on them closes 23 July 2026.
Three things you should know about them:
They come in three documents. General principles, the Annex I route, and the Annex III route, each downloadable separately from the Commission's AI Act Single Information Platform.
They are non-binding but heavy. Only the Court of Justice can interpret the Act authoritatively, yet market surveillance authorities are expected to use these guidelines as their benchmark.
They read the Annex I route broadly. Early legal analysis says more AI in regulated products gets captured than businesses assumed. If you build embedded AI, read that section this week.
Final adoption lands by end of 2026. Feedback submitted before 23 July can still shape the wording. After that, you live with it.
If a grey zone in the draft affects your product, submitting consultation feedback is the cheapest lobbying you will ever do. The window closes in days.
What should you do once you know your tier?
Match your tooling to your tier: high-risk systems need documented risk management and testing evidence now, limited-risk systems need marking and disclosure by December 2026, and minimal-risk systems still belong in your AI inventory.
Presumed high-risk: stand up risk management on NIST AI RMF, start the management system on ISO/IEC 42001, and generate testing evidence with DeepEval, Giskard, or Promptfoo plus adversarial runs from Garak or PyRIT. December 2027 is far only if you start now.
Using the 6(3) filter: write the assessment memo, register the system, and keep monitoring outputs with guardrails like Lakera Guard so drift does not quietly change your classification.
Limited-risk: put Article 50 marking on the roadmap for 2 December 2026 and document your disclosure UX.
Every tier, including minimal: log the system in your AI inventory. Our Shadow AI playbook covers how to build one in 90 days.
Governance platforms industrialize this. Credo AI, Holistic AI, OneTrust AI Governance, Modulos, FairNow, and IBM watsonx.governance all ship EU AI Act classification workflows. Compare them in the directory, where 6 of our 32 tracked tools sit in the governance and risk category.
Your Action Plan
Run the 5-question check on every system in your inventory this week. No inventory yet? Start with the 90-day Shadow AI plan.
Read the draft guidelines section that matches your route (Annex I or Annex III) on the Commission's platform.
Submit consultation feedback before 23 July 2026 if any grey zone touches your product. Days remain, not weeks.
Write the intended-purpose statement like a legal document. It decides your tier more than your architecture does.
For anything presumed high-risk, open a workstream now with an owner, a framework, and a testing tool. The final guidelines arrive by end of 2026; your evidence trail should predate them.
The next milestone: final classification guidelines adopted by the end of 2026, followed by Annex III obligations on 2 December 2027. Classify first. Everything else in your compliance program inherits from that answer.
FAQs
What makes an AI system high-risk under the EU AI Act?
Two routes: the system is a regulated product or safety component under Annex I requiring third-party conformity assessment, or its intended purpose matches an Annex III use case such as hiring, credit scoring, education, or law enforcement.
Is my chatbot high-risk under the EU AI Act?
Usually no. A general customer-service chatbot is typically limited-risk, carrying Article 50 transparency duties: users must know they are talking to AI, and generated content must be machine-readably marked by 2 December 2026. It becomes high-risk only if its intended purpose matches an Annex III use case, such as screening job candidates.
Are the Commission's classification guidelines legally binding?
No. They are interpretive, and only the Court of Justice of the EU can rule authoritatively. In practice, market surveillance authorities are expected to treat them as the benchmark, so ignoring them is a bad litigation strategy.
