KlarComply
HomeKnowledge › Classifying AI risk

AI risk classes: how to classify a specific tool and defend the answer

The regulation governs use, not technology. So no tool has “a” risk class — the same language model can be unremarkable for drafting text and high-risk for pre-sorting job applications. This page sets out how to decide your case cleanly and how to write down why.

By , Founder of KlarComply · Reviewed on

Infographic: The risk classes: one pyramid, four tiers — The EU AI Act does not judge wholesale — it grades by risk. Here is how to classify correctly.
The key points of this article as a graphic — feel free to share or download it.

The four tiers

The regulation takes a graduated approach. The higher the risk to fundamental rights, health and safety, the stricter the obligations.

TierLegal basisConsequence
ProhibitedArticle 5Use is not permitted. Highest penalty range: up to 35 million euros or 7 per cent of total worldwide annual turnover
High-riskArticle 6 read with Annex I and Annex IIIExtensive obligations for providers, a defined set for deployers. Applies from 2 December 2027 and 2 August 2028
Transparency dutyArticle 50Disclosure to users and to the public. Has applied since 2 August 2026
Minimal riskNo specific obligations under the regulation. Data protection, copyright and contract law continue to apply

An important point for classification: the tiers are not mutually exclusive. A high-risk system can carry transparency duties as well. And a system of minimal risk under the AI Act can be a serious matter in data protection terms.

Tier 1: prohibited practices (Article 5)

Most of the prohibitions target state action or applications that do not arise in ordinary businesses: social scoring, subliminal manipulation, exploitation of vulnerability, biometric categorisation by sensitive characteristics, untargeted scraping of facial images, predictive policing.

The one prohibition that does reach ordinary companies

Inferring emotions in the workplace and in educational institutions is prohibited, with narrow exceptions for medical and safety reasons. That covers more products than people expect: tone-of-voice analysis in telephony, evaluation of facial expressions in video interviews, “sentiment analysis” of employees inside collaboration tools.

If a provider offers you something along those lines as an added feature: do not switch it on, and record the refusal. This point carries the highest penalty range in the regulation.

Tier 2: high-risk — Annex I and Annex III

Two routes lead into this tier.

Route A (Annex I): the AI is a safety component of a product subject to a conformity assessment under EU harmonisation law — machinery, medical devices, lifts, toys, pressure equipment and others. Manufacturers of such products should settle this route with their notified body.

Route B (Annex III): the more common one in practice. Annex III lists eight areas:

  1. Biometrics, so far as permitted
  2. Critical infrastructure
  3. Education and vocational training
  4. Employment, workers management and access to self-employment
  5. Access to essential private and public services, including creditworthiness assessment and risk assessment in life and health insurance
  6. Law enforcement
  7. Migration, asylum and border control
  8. Administration of justice and democratic processes

For small and mid-sized companies only numbers 4 and 5 are realistically relevant. The rest concerns public bodies, banks, insurers, educational institutions or operators of critical infrastructure.

Number 4 is the trap

It covers, among other things, systems for recruitment and selection — in particular for placing targeted job advertisements, analysing and filtering applications and evaluating candidates — and systems used for decisions on promotion and termination, for allocating tasks, and for monitoring and evaluating performance and conduct.

The most common objection is: “a human decides at the end, so it is unproblematic.” That does not hold. Reducing two hundred applications to twenty shapes the decision. That pre-sorting is exactly what the annex is about.

The exemptions in Article 6(3)

A system falling within Annex III is exceptionally not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, because it

An exception to the exception: where the system performs profiling of natural persons, it remains high-risk in every case. Anyone relying on one of the four grounds must also document the assessment — this is not a silent exemption.

Frankly: these exemptions are narrow and the boundaries are contested in individual cases. Recruitment software that ranks candidates by fit does not, in our view, fall within them, because it plainly does influence the human assessment. If you intend to rely on an exemption, have it checked by a lawyer.

Tier 3: transparency duties (Article 50)

This is the only tier that has reached ordinary deploying companies directly and visibly since 2 August 2026. It covers systems that interact with people, generate content or produce deepfakes. For deployers the relevant provision is Article 50(4), first sentence: the disclosure of deepfakes.

The detail — which paragraph binds whom, what a deepfake means under Article 3(60), and why ordinary marketing copy is not subject to a labelling duty — is on labelling under Article 50. Ready-made labels in three languages are free on our AI labels page.

Tier 4: minimal risk

This is where the large majority of everyday office tools land: spelling and grammar help, translation, summarising, idea generation, scheduling suggestions, image editing with no personal data. No specific obligations follow from the AI Act — apart from the general literacy duty in Article 4, which applies to any AI use.

That does not mean “unproblematic”. Data protection, copyright, trade secret protection and contractual duties apply regardless of the risk class.

The assessment in five steps

  1. Describe the purpose precisely. Not “working with text” but “pre-sorting incoming applications by fit against the role profile”. The class hangs on the purpose, so the accuracy of that sentence decides everything after it.
  2. Check Article 5. Is there a prohibited practice, in particular emotion inference in the workplace? If yes: assessment over, do not deploy.
  3. Check Annex III. Does the purpose fall in one of the eight areas? For SMEs, numbers 4 and 5 are the relevant ones.
  4. If it does, check Article 6(3). Does one of the four exemptions apply — and is there no profiling? Document the outcome either way.
  5. Check Article 50. Does the system interact with people or produce content for publication? Then transparency duties come on top, not instead.

For steps 3 to 5, the European Commission's AI Act Service Desk is a useful free reference point, and several national market surveillance authorities publish their own interactive classification aids. None of them replaces a legal assessment, but they are a good cross-check on your own conclusion.

What to document — and what alone counts

The class is not the evidence. The reasoning is. Four lines is enough:

“Tool: [name]. Purpose: [one precise sentence]. Assessed on [date] against Article 5, Annex III and Article 50. Result: [class], because [reason in one sentence]. Next review: [date].”

A reviewer does not ask “which class?” They ask “how did you arrive at that?” Anyone with those four lines in their AI inventory answers in thirty seconds.

The six most common misreadings

AssumptionWhy it does not hold
“ChatGPT is high-risk AI.”No. A general-purpose language model is not high-risk as such. The application becomes high-risk where it falls in an Annex III area. General-purpose models carry their own rules, which bind providers rather than users.
“A human decides at the end, so it is fine.”Pre-sorting shapes the decision. Annex III expressly captures filtering and evaluation, not only the final decision.
“We only use AI, we do not build it, so this is not about us.”Deployers have obligations of their own. And anyone offering a system under their own name or substantially modifying it can become a provider under Article 25.
“High-risk was postponed, so there is nothing to do.”The high-risk obligations were postponed. The classification and its documentation should be in place now — otherwise you have no lead time in 2027, and no answer for a supplier questionnaire today.
“We have a certificate, so the class is settled.”No certificate establishes a risk class. Classification is an application of law to your facts and sits with the company. There is no official EU AI seal of any kind.
“The tool has a class and it applies everywhere in the company.”The class hangs on the purpose of use. The same tool can be minimal in marketing and high-risk in HR. Keep the entries per purpose, not per tool.

If you land in the high-risk area

  1. Do not switch the tool off in a panic. The obligations apply from December 2027 or August 2028. You have time for an orderly decision.
  2. Record the classification in writing, with purpose, assessment date and reasoning.
  3. Escalate it to the management. This is not a decision to be taken at working level.
  4. Take legal advice on whether an Article 6(3) exemption applies and which deployer obligations will fall due.
  5. Ask the provider whether it is preparing a declaration of conformity and by when. If not, you need an alternative, and that needs lead time.
  6. Involve employee representatives where staff are affected. Those rights apply today, independently of the postponed deadline — see AI and employee representation.

A note if you are established outside the EU

Classification is not a question about your registered office. Under Article 2 the regulation reaches providers and deployers in a third country where the output produced by the AI system is used in the Union. A recruitment tool used from outside the EU to pre-sort applications for a role based in a member state produces output used in the Union — and it sits in Annex III number 4. The class follows the use, and the use follows the output.

What you do not need

Whether your classifications are documented is one of the ten points in the free quick check.

Frequently asked questions

Which risk classes does the EU AI Act use?

Four: prohibited practices under Article 5, high-risk systems under Article 6 read with Annexes I and III, systems with transparency duties under Article 50, and systems of minimal risk with no specific obligations. The tiers are not mutually exclusive — a high-risk system can carry transparency duties as well.

Is ChatGPT a high-risk system?

Not as such. A general-purpose language model is not high-risk in itself, and general-purpose models carry their own rules aimed mainly at providers. What becomes high-risk is the specific application, where its purpose falls in an Annex III area — for example pre-sorting job applications.

Which Annex III areas affect ordinary companies?

Realistically only two: employment and workers management (number 4) and access to essential services including creditworthiness assessment (number 5). The other six concern public bodies, banks, insurers, educational institutions or operators of critical infrastructure.

Is it still high-risk if a human takes the final decision?

Usually yes. Annex III expressly covers the analysis and filtering of applications and the evaluation of candidates, not only the final decision. Reducing two hundred applications to twenty influences the decision, and that is enough.

What is prohibited under Article 5 for an ordinary business?

The prohibition that matters in practice is on inferring emotions in the workplace, with narrow exceptions for medical and safety purposes. That reaches sentiment analysis inside collaboration tools, tone-of-voice analysis in telephony and evaluation of facial expressions in video interviews.

Do we have to classify now, given that high-risk was postponed?

Yes. What was postponed is the set of high-risk obligations, to December 2027 and August 2028 — not the need to know where you stand. Without a documented classification you have no lead time for a possible change of tool, and no answer for a supplier questionnaire today.

Who decides the risk class with binding effect?

No authority and no certificate establishes the class for you. Classification is an application of law that the company carries out and reasons for itself. The Commission's AI Act Service Desk and the classification aids published by some national authorities are useful cross-checks, not substitutes for legal assessment.

Does the classification change if we are based outside the EU?

No. Under Article 2 the regulation reaches deployers in a third country where the output produced by the AI system is used in the Union. The class follows the purpose of use, and the scope follows the output — not your registered office.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 5 EU AI Act — prohibited practices
Article 6 EU AI Act — classification rules for high-risk systems
Article 50 EU AI Act — transparency obligations
Article 2 EU AI Act — scope
Regulation (EU) 2024/1689 — official consolidated text with Annex III
European Commission — AI Act Service Desk
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.