Risk classification is the first decision you must make to comply with the AI Act. We explain the decision tree step by step, with real examples by sector and a downloadable worksheet to document your analysis.
If you have read our article about what the AI Act is, you already know that the European regulation on artificial intelligence follows a risk-based approach: the higher the risk, the greater the obligations. But there is one question everyone asks after understanding the theory: how do I know what risk level each AI system used by my company falls into?
The answer is risk classification: a systematic analysis that determines which obligations each AI use triggers. It is not an optional exercise or a bureaucratic formality. It is the decision that shapes everything else: what documentation you need, whether you need designated human oversight, whether you must carry out a fundamental rights impact assessment (FRIA), or whether a transparency notice is enough.
In this article, we give you the step-by-step decision tree, examples classified by sector (ecommerce, HR, customer service, finance), the consequences of misclassification, and a classification worksheet you can use today.
Why classification is the first and most important step
The AI Act does not impose the same obligations on every AI system. Regulatory intensity is proportional to the risk generated by each specific use. This means that classifying correctly is what separates companies that comply efficiently from those that accumulate unnecessary bureaucracy or, worse, fail to comply because they believe the rules do not apply to them.
Correct classification allows you to:
- Avoid over-regulating yourself: If your recommendation engine is minimal risk, you do not need a 50-page technical file. Knowing this saves you time and money.
- Avoid under-regulating yourself: If your recruitment system is high-risk and you treat it as limited risk, you could face fines of up to 15 million euros or 3% of your turnover.
- Activate only the obligations that apply: Human oversight, FRIA, technical file, traceability logs… each one is activated or not depending on the level.
- Document auditable decisions: If an authority asks why you classified a system as limited risk instead of high-risk, you need to be able to justify it with evidence.
Key principle: Compliance is not proclaimed; it is demonstrated through verifiable processes. The classification worksheet is the first piece of evidence that your company takes AI governance seriously.
Step-by-step decision tree: the four questions
To classify any AI system, answer these four questions in order. Each answer directs you to the next node in the tree:
Question 1: Does the system affect people?
This is the first fork. If the AI system does not interact with people or produce results that affect them directly or indirectly, it is minimal risk. The analysis ends here.
Examples of minimal risk: spam filters, inventory optimisation, aggregate demand forecasting, AI in video games, and internal process automation with no individual impact.
If the answer is yes, the system interacts with users, processes their data, or produces results that affect them, move on to the next question.
Question 2: Does it produce legal or significant effects?
This is where limited risk and high-risk are separated. A legal or significant effect is one that affects a person’s access to a right, an essential service, or a relevant opportunity: a job, credit, public assistance, insurance, or admission to an educational institution.
If the system interacts with people but does not produce legal or significant effects (a chatbot that answers questions, a product-description generator, or a content assistant), it is limited risk. Your main obligation is transparency: tell users that they are talking to an AI and label AI-generated content.
If it produces legal or significant effects, continue.
Question 3: In what environment is it used? Does it match Annex III?
Annex III of the AI Act lists the areas of use that automatically trigger a high-risk classification. If your system operates in one of these areas, it is high-risk by use:
- Employment and people management: Recruitment, dismissal, performance evaluation, promotion.
- Education: Admission, assessment, certification.
- Essential services: Public assistance, insurance, housing, healthcare, energy.
- Financial services: Creditworthiness assessment, fraud prevention, credit approval.
- Justice and law enforcement: Migration, border control, support for judicial decisions.
- Democratic processes: Systems that influence elections or participation processes.
It is also high-risk if the system is an embedded safety component in a regulated product (Annex I): medical devices, industrial machinery, or autonomous vehicles.
If the system has significant effects but does not fit any area in Annex III and is not a safety component, it remains limited risk with enhanced transparency obligations.
Question 4: What role does your company have?
The last question does not change the risk level, but it does change who assumes which obligations:
- Provider: You develop the system or market it under your brand. You are responsible for risk management, complete technical documentation, conformity assessment, and post-market monitoring.
- Deployer: You integrate and operate a system developed by a third party. You are responsible for classification, DPIA/FRIA, human oversight, logs, and local validation of thresholds. This is the most common role for SMEs.
- Importer/Distributor: You introduce or resell systems from outside the EU. You are responsible for verifying conformity, documentation, and traceability.
Warning: If you substantially modify an AI system from a provider (you change the model, add your own training data, or alter its intended purpose), you may move from deployer to provider. This activates significantly greater obligations.
Real classification examples by sector
The theory is easier to understand with concrete cases. These are typical classifications by sector:
Ecommerce
- Product recommendation engine: Minimal risk. It does not affect rights. No special obligations are required.
- Customer service chatbot: Limited risk. It interacts with people. Obligation: disclose that it is an AI.
- Product-description generator: Limited risk. Obligation: label it as AI-generated content.
- Anti-fraud system that automatically rejects orders: High-risk if the decision is automated without human review (it affects access to a service).
Human resources
- Automated CV screening: High-risk (Annex III). It affects access to employment. It requires a technical file, FRIA, human oversight, and logs.
- AI candidate ranking: High-risk. The same logic applies: it is a decision that affects fundamental rights.
- Internal chatbot for HR questions: Limited risk if it only provides information. If it makes decisions (holiday approval, evaluation), it may rise to high-risk.
Customer service
- RAG assistant with human approval: Limited risk. The AI suggests; a human decides and sends.
- Automatic ticket classifier: Minimal risk if it only routes tickets. It does not make decisions about people.
- Direct automatic response to the customer: Limited risk. If it decides refunds or compensation without a human, it may be high-risk.
Finance and insurance
- Credit scoring model: High-risk (Annex III). It decides access to financing.
- Money laundering detection: High-risk. Automatic transaction blocking affects rights.
- Predictive analysis of market trends: Minimal risk. It does not affect individual people.
Same model, different risk. What determines the classification is not the technology, but the use.
What happens if you classify incorrectly: real consequences
Classifying below the actual risk level is not a minor mistake. The consequences are concrete:
Direct consequences
- Financial penalties: If you classify as limited risk what is actually high-risk, you could face fines of up to 15 million euros or 3% of turnover. For SMEs, the lower amount applies, but it can still be significant.
- System withdrawal: The competent authority may order the system to be withdrawn from the market or the service to be suspended until the issue is corrected.
- Civil liability: If the system harms someone and was under-classified, the legal liability becomes more serious.
Operational consequences
- Blocked at the Gates: In a governance model with Gates (ideation → pilot → production), an incorrect classification is detected when the evidence does not match the actual obligations. The system does not pass from Gate 1 to Gate 2.
- Reputational damage: An investigation opened by the AI authority creates distrust among customers and partners.
- Regulatory technical debt: Reclassifying a system in production is much more expensive than classifying it correctly from the start. You need to redo documentation, add controls, and implement logs retrospectively.
Classification is not a one-shot exercise. Systems must be reclassified when their purpose, affected population, data used, or integration into new regulated products changes. Document these reclassification triggers in your worksheet.
Practical tool: the Classification and Scope Worksheet
The Classification and Scope Worksheet is the operational document where you record the result of your analysis. It is the first piece of compliance evidence and the starting point for any subsequent obligation.
A complete worksheet should include:
- System identification: Name, version, date, owner, reviewer, and approver.
- Use case and context: What the system does, which channel it operates in, which population it affects, and in what operational environment it works.
- Affected people and effects: Who is impacted by the system’s decisions and what type of impact it is (legal, economic, emotional, or access to services).
- Classification and role: AI Act category (prohibited, high-risk, limited, minimal), and the company’s role (provider, deployer, importer, distributor).
- Applicable regulations: Mark which ones apply: AI Act, GDPR, DSA, DMA, NIS2.
- Classification rationale: Reference the AI Act articles and annexes that support your decision.
- Reclassification triggers: What changes would require a new classification: change of purpose, new population, new data, or integration into a regulated product.
- Key controls: Required human oversight, abstention conditions (when the system must not act), and usage limits.
Practical advice: Complete one worksheet for every active AI system in your company. It does not need to be a 20-page document: a well-prepared worksheet fits on 1–2 pages. What matters is that it exists, is signed by a responsible person, and can be audited.
The complete process: from classification to action
Once each system has been classified, the next actions depend on its level:
Minimal risk
Document the classification in the worksheet and file it. No additional actions are required beyond general legal compliance.
Limited risk
- Implement transparency notices (users must know that they are talking to an AI).
- Label AI-generated content.
- Document it in the worksheet and review it periodically.
High-risk
- Start the technical file: purpose, data, architecture, metrics, thresholds, risks, and safeguards.
- Complete the FRIA (fundamental rights impact assessment).
- Complete the DPIA if the system processes personal data.
- Appoint the person responsible for human oversight, with the necessary competence, authority, and judgement.
- Enable traceability logs to reconstruct any decision.
- Configure traffic-light thresholds: green (GO), amber (FIX), red (KILL).
- Do not deploy without passing the validation Gates.
For prohibited risk, there is only one action: immediate withdrawal. No controls or mitigations are possible.
The five most common classification mistakes
After supporting dozens of companies through this process, these are the error patterns we see most often:
- Confusing technology with risk. Thinking that because you use ChatGPT the risk is high, or that because it is “just a chatbot” it is minimal. Risk is not defined by the model, but by the use and its impact on people.
- Operating with the provider’s default thresholds. One of the most serious mistakes in high-risk systems: accepting the standard configuration without validating it in your specific context. Provider thresholds are generic; your population and environment are not.
- Failing to document the rationale. Classifying something mentally as “limited” without leaving a written record. When an authority asks, “we thought it was limited” is not evidence. You need a signed worksheet with references to the relevant articles and annexes.
- Forgetting reclassification. Classifying once and never reviewing again. Systems evolve: data changes, the population expands, and the purpose is modified. Every relevant change requires a reassessment.
- Ignoring the company’s role. Many companies assume they are “just users” of AI with no obligations. If you integrate, configure, and operate the system, you are the deployer and have concrete obligations: DPIA, human oversight, logs, and threshold validation.
Rule of thumb: When in doubt, classify upwards. It is easier to relax controls when you can demonstrate that they are not necessary than to add them retrospectively when an authority determines that they were.
Your next step
Risk classification is not an academic exercise. It is the operational decision that determines what the law requires of you, how many resources you need to invest in compliance, and how you protect your company from penalties.
Start today: make a list of all active AI systems in your company, take each one through the four questions in the decision tree, and document the result in a worksheet. If you discover that you have high-risk systems without the necessary evidence, that is your next priority project.
If you need help carrying out the classification audit, preparing the worksheets, or putting together the technical file for high-risk systems, Impulsa3 can support you throughout the process with a practical approach and no unnecessary legal jargon.