Step 1 — check prohibited practices (Art. 5)
Before anything else, test against Art. 5. If your system uses forbidden manipulation, untargeted scraping for facial recognition, or social scoring, it is prohibited regardless of benefit. This is a hard stop, not a tier to manage.
Step 2 — check Annex III high-risk uses
If your use case is listed in Annex III — recruitment, credit scoring, education, safety components, biometrics, law enforcement, and more — it is high-risk and triggers Art. 9–17: risk management, data governance, technical documentation, human oversight, accuracy/robustness, and conformity assessment.
Step 3 — check transparency duties (Art. 50)
If the system generates or manipulates content (deepfakes, chatbots), Art. 50 imposes transparency duties — labeling and disclosure — even when the system is not high-risk. This is the "limited-risk" layer most consumer AI hits.
Step 4 — assign the tier and the obligations
The output is one of: prohibited / high-risk / limited / minimal. Each tier carries a distinct obligation set. The classification is a view of exposure, not a guarantee, and should be validated with qualified counsel — especially because the Digital Omnibus has delayed several high-risk obligations (Annex III extensions currently track toward 2 December 2027).
What classification does not do
It tells you which duties apply. It does not make the system compliant, and it is not a legal opinion. Closing the gaps is the deployer's work; the classification just names them.
Authoritative references
- EU AI Act (Reg. 2024/1689), Art. 5 / 6 / 50, Annex III: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- AI Act explorer: https://artificialintelligenceact.eu/
- European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai