CLASSIFICATION GUIDE

How to classify an AI system under the EU AI Act

A step-by-step EU AI Act risk classification guide covering prohibited practices, high-risk systems and transparency obligations.

10 min readReviewed September 2026
In brief

Classification follows the intended purpose and actual use of a system. Use a decision process, preserve the evidence and reassess material changes.

1. Screen for prohibited AI practices

Begin with Article 5. The prohibited-practice screen comes before high-risk analysis because a prohibited use cannot be made acceptable by adding high-risk controls. Review both the system's design and how people intend to operate it.

Examples include certain harmful manipulation or exploitation, social scoring, individual predictive policing based solely on profiling, untargeted scraping to build facial-recognition databases, and some biometric categorisation and emotion-recognition uses. The legal conditions and exceptions matter, so do not classify from a short label alone.

2. Test both high-risk routes

Article 6 provides two main routes. The first covers an AI system that is a product, or a safety component of a product, listed under Annex I legislation where third-party conformity assessment is required. The second covers specified use cases in Annex III.

  • Annex I route: identify the regulated product, applicable Union legislation and conformity-assessment requirement.
  • Annex III route: compare the exact intended purpose with the listed use cases, including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and justice-related uses.
  • For Annex III, analyse any statutory qualification or exception and document whether the system materially influences decision-making.
  • Systems that perform profiling of natural persons in an Annex III context require particular care under the classification rules.

The industry alone does not decide classification. A low-impact administrative tool and a decision system can sit in the same sector but have different outcomes.

3. Check transparency-triggering uses

Some systems are not high-risk but still carry specific transparency duties under Article 50. Depending on the use, people may need to know that they are interacting with AI, and synthetic or manipulated content may need machine-readable marking or disclosure.

Record whether the system interacts directly with people, performs emotion recognition or biometric categorisation, or generates or manipulates image, audio, video or text content. Then test the precise conditions and exceptions for the provider and deployer.

4. Do not treat ‘not high-risk’ as ‘no obligations’

AI literacy duties can apply across risk categories. Providers of general-purpose AI models have a separate framework. Codes of conduct may be relevant for other systems, and sectoral law continues to apply.

Your classification record should state every branch considered: in scope or excluded, prohibited or permitted, high-risk or not, Article 50 transparency, general-purpose AI involvement and the organisation's role.

5. Build a classification file that can be reviewed

A useful file explains the conclusion and makes it reproducible. Capture the system version, intended purpose, actual workflow, affected persons, territories, roles, decision-tree answers, evidence sources, reviewer and approval date.

  • Use source quotations and page references, not unsupported yes/no answers.
  • Mark unknown facts rather than forcing a conclusion.
  • Create review triggers for new purposes, integrations, countries and model versions.

Official sources

Use the official text and current Commission guidance for decisions about a specific system.