EU AI Act Risk Classification Template
Classify Every AI System You Use or Build
The EU AI Act introduces four risk tiers for AI systems, each with different compliance obligations. This template helps you classify every AI system in your portfolio, understand what is required for each tier, and build the evidence base you need for compliance. Applies to organisations that deploy AI in the EU, regardless of where they are headquartered. Updated July 2026 to reflect the June 2026 digital omnibus and the deferred high-risk compliance dates.
Quick Classification Decision Tree
Compliance Timeline
The EU digital omnibus, formally adopted in June 2026, deferred the high-risk compliance dates without touching the prohibitions, GPAI obligations, or transparency obligations. These are the dates that matter for classification.
Risk Tier Reference Guide
Unacceptable Risk
ProhibitedAI systems that pose a clear threat to fundamental rights, safety, or EU values. These practices are banned from 2 February 2025. The June 2026 digital omnibus added a further prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026.
- •Biometric categorisation systems that infer sensitive attributes (race, political opinion, religion, sexual orientation) from biometric data
- •Real-time remote biometric identification in publicly accessible spaces by law enforcement (with narrow exceptions)
- •Social scoring systems by public authorities that lead to detrimental treatment
- •AI systems that exploit vulnerabilities (age, disability, social/economic situation) to manipulate behaviour
- •Subliminal techniques that bypass conscious awareness to distort behaviour causing harm
- •Predictive policing based solely on profiling or personality traits (not objective, verifiable facts)
- •AI systems that generate non-consensual intimate imagery or child sexual abuse material (prohibition added by the June 2026 digital omnibus, applies from 2 December 2026)
- Discontinue use immediately
- Do not procure or deploy
- Document the review and rationale for exclusion
High Risk
Full compliance requiredAI systems used in critical sectors or safety applications. Subject to strict requirements before market placement. Stand-alone Annex III systems must comply from 2 December 2027, and AI embedded in Annex I regulated products from 2 August 2028 (dates deferred by the June 2026 digital omnibus).
- •Biometric identification and categorisation (Annex III, 1)
- •Critical infrastructure management: electricity, water, gas, transport (Annex III, 2)
- •Educational/vocational assessment determining access to institutions (Annex III, 3)
- •Employment decisions: recruitment, CV screening, task allocation, promotion, termination (Annex III, 4)
- •Access to essential services: credit scoring, insurance risk assessment, emergency dispatch (Annex III, 5)
- •Law enforcement: individual risk assessment, polygraph, crime analytics (Annex III, 6)
- •Migration, asylum, and border control management (Annex III, 7)
- •Administration of justice and democratic processes (Annex III, 8)
- Risk management system (ongoing, documented)
- Data governance and training data documentation
- Technical documentation (before market placement)
- Record-keeping and automatic logging of events
- Transparency and information provision to deployers
- Human oversight measures built in by design
- Accuracy, robustness, and cybersecurity requirements
- EU conformity assessment (self-assessment or third-party)
- Registration in EU database (Art. 71)
- CE marking and Declaration of Conformity
- Post-market monitoring system
- Incident reporting to national authorities
Limited Risk
Transparency obligationsAI systems with specific transparency risks. Users must be told they are interacting with AI. These duties apply from 2 August 2026; generative systems already on the market before that date have until 2 December 2026 to meet Article 50(2)'s machine-readable marking duty.
- •Chatbots and virtual assistants interacting with natural persons
- •Emotion recognition systems (must disclose to individuals)
- •Deepfake images, audio, or video content generated by AI
- •AI-generated text published to inform the public on matters of public interest
- •Biometric categorisation or emotion recognition systems not in Annex III
- Notify users they are interacting with an AI system (unless obvious from context)
- Label AI-generated content (images, audio, video, text) as artificially generated
- Implement technical solutions for content provenance (watermarking recommended)
Minimal Risk
No mandatory requirementsThe vast majority of AI systems in use today fall here. No mandatory EU AI Act requirements beyond general law (GDPR, product liability, consumer protection). Voluntary codes of conduct encouraged.
- •AI-powered spam filters
- •AI-enabled inventory management
- •Product recommendation engines
- •AI-based content moderation (non-employment, non-public service context)
- •Business intelligence and analytics tools
- •AI writing assistants for internal use (not public-facing news)
- •AI-assisted scheduling and logistics optimisation
- No mandatory EU AI Act obligations
- Consider voluntary AI Code of Conduct
- Standard GDPR and data protection obligations still apply
- Document classification rationale for audit purposes
Automate your EU AI Act compliance
Aona AI discovers every AI tool in your organisation, classifies it by risk, and gives you the governance controls the EU AI Act requires.