Risk classes
Prohibited, high risk, transparency-bound or free: how a system is classified, with a decision aid and twenty examples.
The decision aid
- 01
Is it a prohibited practice?
Social scoring, emotion recognition in the workplace and in education, biometric categorisation by sensitive attributes, untargeted scraping of facial images, exploitation of vulnerability, predictive policing based solely on personality traits.
- 02
Is it a safety component of a regulated product?
Then Annex I and therefore high risk.
- 03
Does the purpose fall under Annex III?
Biometrics, critical infrastructure, education, employment, essential private and public services, law enforcement, migration, justice.
- 04
Does a transparency duty apply?
Dialogue systems, generated content, emotion recognition outside the prohibitions, deepfakes.
Twenty examples
| Task | Class |
|---|---|
| Spell checking | free |
| Triaging and routing tickets | free |
| Summarising a meeting note | free |
| Generating product copy | transparency duty on publication |
| Customer service chatbot | transparency duty |
| Generated advertising image | transparency duty |
| Deepfake of a real person | transparency duty, possibly further prohibitions |
| Pre-sorting applications | high risk, Annex III |
| Proposing promotions | high risk |
| Assessing work performance | high risk |
| Creditworthiness of natural persons | high risk |
| Payment fraud detection | expressly excluded |
| Risk assessment in life and health insurance | high risk |
| Marking exam performance | high risk |
| Camera-based exam invigilation | high risk |
| Access to educational institutions | high risk |
| Assessing entitlement to social benefits | high risk |
| Prioritising emergency calls | high risk |
| Safety component of a machine | high risk, Annex I |
| Emotion recognition in the workplace | prohibited |
The exception within Annex III
A system falling under Annex III exceptionally does not count as high risk where it poses no significant risk to health, safety or fundamental rights, because it
- performs a narrow procedural task,
- improves the result of a previously completed human activity,
- detects decision patterns without replacing human assessment, or
- performs a preparatory task for an assessment.
The exception does not apply where the system profiles natural persons. And it must be documented: anyone relying on it must record the assessment in writing and produce it on request. In practice this is the most overestimated escape route.
Documenting the classification
| Item | Content |
|---|---|
| System and version | What exactly was classified |
| Purpose description | What it is used for, and expressly not for |
| Categories assessed | Prohibition, Annex I, Annex III, transparency duty |
| Result with reasoning | Why this class and no other |
| Where an exception applies | Which ground, with reasoning |
| Date and responsible person | By name |
| Trigger for re-assessment | New purpose, new version, new data |
The last row is routinely forgotten and is practically the most important: a classification is not a one-off act but has a review cycle.
Classification worksheet
FREE ACCOUNT
Classification worksheet for a task
A worksheet that assigns a task to a class in four steps, with reasoning and a review date.
Worksheet3 items
Related courses and sources
AI Act Explorer
A searchable, cross-linked edition of the EU AI Act. Jumps from an article straight to its recitals.
Far more pleasant than the PDF, but not the official version. When in doubt, use the full text.
EU AI Act, the official full text
Regulation (EU) 2024/1689 in full, in every official language. The primary source for any legal question.
Our governance articles summarise and contextualise. Where the exact wording matters, this text governs.
NIST AI Risk Management Framework
A structured frame for your own risk assessment, independent of the AI Act. Useful as an outline when none exists internally yet.
For building your own risk assessment, independent of the AI Act.