The regulation governs use, not technology. So no tool has “a” risk class — the same language model can be unremarkable for drafting text and high-risk for pre-sorting job applications. This page sets out how to decide your case cleanly and how to write down why.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
The regulation takes a graduated approach. The higher the risk to fundamental rights, health and safety, the stricter the obligations.
| Tier | Legal basis | Consequence |
|---|---|---|
| Prohibited | Article 5 | Use is not permitted. Highest penalty range: up to 35 million euros or 7 per cent of total worldwide annual turnover |
| High-risk | Article 6 read with Annex I and Annex III | Extensive obligations for providers, a defined set for deployers. Applies from 2 December 2027 and 2 August 2028 |
| Transparency duty | Article 50 | Disclosure to users and to the public. Has applied since 2 August 2026 |
| Minimal risk | — | No specific obligations under the regulation. Data protection, copyright and contract law continue to apply |
An important point for classification: the tiers are not mutually exclusive. A high-risk system can carry transparency duties as well. And a system of minimal risk under the AI Act can be a serious matter in data protection terms.
Most of the prohibitions target state action or applications that do not arise in ordinary businesses: social scoring, subliminal manipulation, exploitation of vulnerability, biometric categorisation by sensitive characteristics, untargeted scraping of facial images, predictive policing.
Inferring emotions in the workplace and in educational institutions is prohibited, with narrow exceptions for medical and safety reasons. That covers more products than people expect: tone-of-voice analysis in telephony, evaluation of facial expressions in video interviews, “sentiment analysis” of employees inside collaboration tools.
If a provider offers you something along those lines as an added feature: do not switch it on, and record the refusal. This point carries the highest penalty range in the regulation.
Two routes lead into this tier.
Route A (Annex I): the AI is a safety component of a product subject to a conformity assessment under EU harmonisation law — machinery, medical devices, lifts, toys, pressure equipment and others. Manufacturers of such products should settle this route with their notified body.
Route B (Annex III): the more common one in practice. Annex III lists eight areas:
For small and mid-sized companies only numbers 4 and 5 are realistically relevant. The rest concerns public bodies, banks, insurers, educational institutions or operators of critical infrastructure.
It covers, among other things, systems for recruitment and selection — in particular for placing targeted job advertisements, analysing and filtering applications and evaluating candidates — and systems used for decisions on promotion and termination, for allocating tasks, and for monitoring and evaluating performance and conduct.
The most common objection is: “a human decides at the end, so it is unproblematic.” That does not hold. Reducing two hundred applications to twenty shapes the decision. That pre-sorting is exactly what the annex is about.
A system falling within Annex III is exceptionally not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, because it
An exception to the exception: where the system performs profiling of natural persons, it remains high-risk in every case. Anyone relying on one of the four grounds must also document the assessment — this is not a silent exemption.
Frankly: these exemptions are narrow and the boundaries are contested in individual cases. Recruitment software that ranks candidates by fit does not, in our view, fall within them, because it plainly does influence the human assessment. If you intend to rely on an exemption, have it checked by a lawyer.
This is the only tier that has reached ordinary deploying companies directly and visibly since 2 August 2026. It covers systems that interact with people, generate content or produce deepfakes. For deployers the relevant provision is Article 50(4), first sentence: the disclosure of deepfakes.
The detail — which paragraph binds whom, what a deepfake means under Article 3(60), and why ordinary marketing copy is not subject to a labelling duty — is on labelling under Article 50. Ready-made labels in three languages are free on our AI labels page.
This is where the large majority of everyday office tools land: spelling and grammar help, translation, summarising, idea generation, scheduling suggestions, image editing with no personal data. No specific obligations follow from the AI Act — apart from the general literacy duty in Article 4, which applies to any AI use.
That does not mean “unproblematic”. Data protection, copyright, trade secret protection and contractual duties apply regardless of the risk class.
For steps 3 to 5, the European Commission's AI Act Service Desk is a useful free reference point, and several national market surveillance authorities publish their own interactive classification aids. None of them replaces a legal assessment, but they are a good cross-check on your own conclusion.
The class is not the evidence. The reasoning is. Four lines is enough:
“Tool: [name]. Purpose: [one precise sentence]. Assessed on [date] against Article 5, Annex III and Article 50. Result: [class], because [reason in one sentence]. Next review: [date].”
A reviewer does not ask “which class?” They ask “how did you arrive at that?” Anyone with those four lines in their AI inventory answers in thirty seconds.
| Assumption | Why it does not hold |
|---|---|
| “ChatGPT is high-risk AI.” | No. A general-purpose language model is not high-risk as such. The application becomes high-risk where it falls in an Annex III area. General-purpose models carry their own rules, which bind providers rather than users. |
| “A human decides at the end, so it is fine.” | Pre-sorting shapes the decision. Annex III expressly captures filtering and evaluation, not only the final decision. |
| “We only use AI, we do not build it, so this is not about us.” | Deployers have obligations of their own. And anyone offering a system under their own name or substantially modifying it can become a provider under Article 25. |
| “High-risk was postponed, so there is nothing to do.” | The high-risk obligations were postponed. The classification and its documentation should be in place now — otherwise you have no lead time in 2027, and no answer for a supplier questionnaire today. |
| “We have a certificate, so the class is settled.” | No certificate establishes a risk class. Classification is an application of law to your facts and sits with the company. There is no official EU AI seal of any kind. |
| “The tool has a class and it applies everywhere in the company.” | The class hangs on the purpose of use. The same tool can be minimal in marketing and high-risk in HR. Keep the entries per purpose, not per tool. |
Classification is not a question about your registered office. Under Article 2 the regulation reaches providers and deployers in a third country where the output produced by the AI system is used in the Union. A recruitment tool used from outside the EU to pre-sort applications for a role based in a member state produces output used in the Union — and it sits in Annex III number 4. The class follows the use, and the use follows the output.
Whether your classifications are documented is one of the ten points in the free quick check.
Four: prohibited practices under Article 5, high-risk systems under Article 6 read with Annexes I and III, systems with transparency duties under Article 50, and systems of minimal risk with no specific obligations. The tiers are not mutually exclusive — a high-risk system can carry transparency duties as well.
Not as such. A general-purpose language model is not high-risk in itself, and general-purpose models carry their own rules aimed mainly at providers. What becomes high-risk is the specific application, where its purpose falls in an Annex III area — for example pre-sorting job applications.
Realistically only two: employment and workers management (number 4) and access to essential services including creditworthiness assessment (number 5). The other six concern public bodies, banks, insurers, educational institutions or operators of critical infrastructure.
Usually yes. Annex III expressly covers the analysis and filtering of applications and the evaluation of candidates, not only the final decision. Reducing two hundred applications to twenty influences the decision, and that is enough.
The prohibition that matters in practice is on inferring emotions in the workplace, with narrow exceptions for medical and safety purposes. That reaches sentiment analysis inside collaboration tools, tone-of-voice analysis in telephony and evaluation of facial expressions in video interviews.
Yes. What was postponed is the set of high-risk obligations, to December 2027 and August 2028 — not the need to know where you stand. Without a documented classification you have no lead time for a possible change of tool, and no answer for a supplier questionnaire today.
No authority and no certificate establishes the class for you. Classification is an application of law that the company carries out and reasons for itself. The Commission's AI Act Service Desk and the classification aids published by some national authorities are useful cross-checks, not substitutes for legal assessment.
No. Under Article 2 the regulation reaches deployers in a third country where the output produced by the AI system is used in the Union. The class follows the purpose of use, and the scope follows the output — not your registered office.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free