AI Risk Classification: How to Know If Your System Is High-Risk According to the AI Act

La clasificación de riesgo es la primera decisión que debes tomar para cumplir con el AI Act. Te explicamos el árbol de decisión paso a paso, con ejemplos reales por sector y una ficha descargable para documentar tu análisis

If you have read our article about what the AI Actis, you already know that the European artificial intelligence regulation works with a risk-based approach: the higher the risk, the greater the obligations. But there is one question everyone asks after understanding the theory: how do I know what risk level each AI system I use in my company is at?

The answer is risk classification: un análisis sistemático que determina qué obligaciones activa cada uso de IA. No es un ejercicio opcional ni un trámite burocrático. Es la decisión que condiciona todo lo demás: qué documentación necesitas, si requieres supervisión humana designada, si debes realizar una evaluación de impacto en derechos fundamentales (FRIA) o si basta con un aviso de transparencia.

En este artículo te damos el árbol de decisión paso a paso, ejemplos clasificados por sector (ecommerce, RRHH, atención al cliente, finanzas), las consecuencias de clasificar mal y una ficha de clasificación que puedes aplicar desde hoy.

Why classifying is the first step and the most important

The AI Act does not impose the same obligations on all AI systems. Regulatory intensity is proportional to the risk each specific use generates. This means that classifying correctly is what separates companies that comply efficiently from those that accumulate unnecessary bureaucracy or, worse, from those that fail to comply thinking the regulation does not apply to them.

Correct classification allows you to:

  • Avoid over-regulating yourself: If your recommendation engine is minimal risk, you do not need a 50-page technical file. Knowing this saves you time and money.
  • Avoid under-regulating yourself: Si tu sistema de selección de personal es alto riesgo y lo tratas como limitado, te expones a sanciones de hasta 15 millones de euros o el 3% de tu facturación.
  • Activate only the obligations that apply: Human supervision, FRIA, technical file, traceability logs... each one activates or not depending on the level.
  • Document auditable decisions: If an authority asks you why you classified a system as limited risk instead of high-risk, you need to be able to justify it with evidence.

Key principle: Compliance is not proclaimed, it is demonstrated with verifiable processes. The classification form is the first evidence that your company takes AI governance seriously.

Decision tree step by step: the four questions

To classify any AI system, answer these four questions in order. Each answer directs you to the next node of the tree:

Question 1: Does the system affect people?

It is the first fork. If the AI system does not interact with people or produce results that affect them directly or indirectly, it is minimal risk. End of analysis.

Examples of minimal risk: spam filters, inventory optimization, aggregated demand prediction, AI in video games, internal process automations with no individual impact.

If the answer is yes, the system interacts with users, processes their data or produces results that affect them, move to the next question.

Question 2: Does it produce legal or significant effects?

This is where limited and high separate. A legal or significant effect is one that affects access to a right, an essential service or a relevant opportunity for the person: a job, a credit, a public benefit, insurance, admission to an educational institution.

If the system interacts with people but does not produce legal or significant effects (a chatbot that answers questions, a product description generator, a content assistant), it is limited risk. Your main obligation: transparency. Tell the user they are talking to an AI and label generated content.

If it produces legal or significant effects, continue.

Question 3: In what environment is it used? Does it match Annex III?

Annex III of the AI Act lists the use cases that automatically activate high-riskclassification. If your system operates in any of these areas, it is high-risk by use:

  • Employment and people management: Hiring, dismissal, performance evaluation, promotion.
  • Education: Admission, evaluation, accreditation.
  • Essential services: Public benefits, insurance, housing, healthcare, energy.
  • Financial services: Creditworthiness assessment, fraud prevention, credit approval.
  • Justice and law enforcement: Migration, border control, support for judicial decisions.
  • Democratic processes: Systems that influence elections or participation processes.

It is also high-risk if the system is a safety component embedded in a regulated product (Annex I): medical devices, industrial machinery, autonomous vehicles.

If the system has significant effects but does not fit any area of Annex III and is not a safety component, it remains limited risk with strengthened transparency obligations.

Question 4: What is your company's role?

The last question does not change the risk level, but it does change who assumes which obligations::

  • Provider: You develop the system or commercialize it under your brand. Responsible for risk management, complete technical documentation, conformity assessment and post-market surveillance.
  • Deployer: You integrate and operate a system developed by a third party. Responsible for classification, DPIA/FRIA, human supervision, logs and local threshold validation. This is the most common role for SMEs.
  • Importer/Distributor: You introduce or resell systems from outside the EU. Responsible for verifying conformity, documentation and traceability.

Attention: If you substantially modify an AI system from a provider (change the model, add your own training data, alter the purpose), you may transition from deployer to provider. This activates significantly greater obligations.

Real classification examples by sector

Theory is better understood with concrete cases. These are typical classifications by sector:

Ecommerce

  • Product recommendation engine Minimal risk. Does not affect rights. No special obligations required.
  • Customer service chatbot: Limited risk. Interacts with people. Obligation: notice that it is an AI.
  • Product description generator: Limited risk. Obligation: label as AI-generated content.
  • Anti-fraud system that automatically rejects orders: High-risk if the decision is automatic without human review (affects access to a service).

Human Resources

  • Automatic CV screening: High-risk (Annex III). Affects access to employment. Requires technical file, FRIA, human supervision, logs.
  • Candidate ranking by AI score: High-risk. Same logic: decision that impacts fundamental rights.
  • Internal chatbot for HR questions: Limited risk if only informational. If it makes decisions (vacation approval, evaluation), it can move to high-risk.

Customer service

  • RAG assistant with human approval: Limited risk. AI suggests, human decides and sends.
  • Automatic ticket classifier: Minimal risk if it only routes. Does not make decisions about people.
  • Direct automatic response to customer: Limited risk. If it decides refunds or compensation without human, it can be high-risk.

Finance and Insurance

  • Credit scoring model: High-risk (Annex III). Decides access to financing.
  • Money laundering detection: High-risk. Automatic transaction blocking affects rights.
  • Market trend predictive analysis: Minimal risk. Does not affect individual people.

Same model, different risk. What classifies is not the technology, but the use.

What happens if you misclassify: real consequences

Classifying below the actual risk is not a minor error. The consequences are concrete:

Direct consequences

  • Economic sanctions: If you classify as limited what is actually high-risk, you can face fines of up to 15 million euros or 3% of revenue. For SMEs the lower amount applies, but it is still significant.
  • System withdrawal: The competent authority can order the product withdrawn from the market or the service suspended until corrected.
  • Civil liability: If the system causes harm to a person and was under-classified, legal responsibility is aggravated.

Operational consequences

  • Blockage at the Gates: In a governance model with Gates (ideation → pilot → production), an incorrect classification is detected when evidence does not match the actual obligations. The system fails to progress from Gate 1 to Gate 2.
  • Reputational damage: An investigation opened by the AI authority generates distrust in customers and partners.
  • Regulatory technical debt: Reclassifying a system in production is much more costly than classifying it correctly from the start. You need to redo documentation, add controls, implement logs retroactively.

Classification is not a one-shot. Systems must be reclassified when their purpose changes, the affected population changes, the data they use changes or they are integrated into new regulated products. Document these reclassification triggers in your form.

Practical tool: the Classification and Scope Form

The Classification and Scope Form is the operational document where you record the result of your analysis. It is the first evidence of compliance and the starting point for any subsequent obligation.

A complete form should include:

  1. System identification: Name, version, date, responsible party, reviewer and approver.
  2. Use case and context: What the system does, what channel it operates on, what population it affects, what operating environment it functions in.
  3. Affected people and effects: Who receives the impact of the system's decisions and what type of impact it is (legal, economic, emotional, access to services).
  4. Classification and role: AI Act category (prohibited, high-risk, limited, minimal), company role (provider, deployer, importer, distributor).
  5. Applicable regulations: Mark which apply: AI Act, GDPR, DSA, DMA, NIS2.
  6. Classification justification: Reference to the AI Act articles and annexes that support your decision.
  7. Reclassification triggers: What changes would require reclassification: change of purpose, new population, new data, integration into regulated product.
  8. Key controls: Required human supervision, abstention conditions (when the system should not act), use limits.

Practical tip: Complete one form for each active AI system in your company. It does not have to be a 20-page document: a well-made form fits in 1-2 pages. What matters is that it exists, is signed by a responsible party and is auditable.

The complete process: from classification to action

Once each system is classified, subsequent actions depend on the level:

Minimal risk

Document the classification in the form and file it. No additional actions are required beyond general legal compliance.

Limited risk

  • Implement transparency notices (the user must know they are talking to an AI).
  • Label AI-generated content.
  • Document in the form and review periodically.

High-risk

  • Start the technical file: purpose, data, architecture, metrics, thresholds, risks, safeguards.
  • Complete the FRIA (Fundamental Rights Impact Assessment).
  • Complete the DPIA if the system processes personal data.
  • Designate the person responsible for human supervision: with competence, authority and judgment.
  • Enable traceability logs to reconstruct any decision.
  • Configure traffic light thresholds: green (GO), amber (FIX), red (KILL).
  • Do not deploy without passing validation Gates.

For prohibited risk, the action is only one: ritiro immediato.. There are no controls or possible mitigations.

The five most common classification errors

After accompanying dozens of companies through this process, these are the error patterns we see most frequently:

  1. Confusing technology with risk. Thinking that because you use ChatGPT the risk is high, or because it is "just a chatbot" it is minimal. Risk is not defined by the model, but by the use and impact on people.
  2. Operating with provider default thresholds. One of the most serious errors in high-risk systems: accepting standard configuration without validating it in your specific context. Provider thresholds are generic; your population and environment are not.
  3. Not documenting the justification. Classifying mentally as "limited" without leaving written record. When an authority asks, "we thought it was limited" is not evidence. You need the signed form with reference to articles and annexes.
  4. Forgetting reclassification. Classify once and never review again. Systems evolve: data changes, population expands, purpose is modified. Each relevant change requires re-evaluation.
  5. Ignoring company role. Many companies assume they are "just users" of AI with no obligations. If you integrate, configure and operate the system, you are a deployer and have specific obligations: DPIA, human supervision, logs, threshold validation.

 

Golden rule: When in doubt, classify upward. It is easier to relax controls when you demonstrate they are unnecessary than to add them retroactively when an authority determines they were required.

Your next step

Risk classification is not an academic exercise. It is the operational decision that determines what the law requires of you, how many resources you need to invest in compliance and how you protect your company against sanctions.

Start today: make a list of all active AI systems in your company, pass each one through the four questions of the decision tree and document the result in a form. If you discover you have high-risk systems without the necessary evidence, that is your next priority project.

If you need help conducting a classification audit, preparing the forms or building the technical file for high-risk systems, at Impulsa3 we accompany you through the entire process with a practical approach and without unnecessary legal jargon.