30 Days Gen AI Risk Trial -Start Now
Skip to main content
Free Template · EU AI Act

EU AI Act Risk Classification TemplateClassify Every AI System You Use or Build

The EU AI Act introduces four risk tiers for AI systems, each with different compliance obligations. This template helps you classify every AI system in your portfolio, understand what is required for each tier, and build the evidence base you need for compliance. Applies to organisations that deploy AI in the EU, regardless of where they are headquartered. Updated July 2026 to reflect the June 2026 digital omnibus and the deferred high-risk compliance dates.

Updated July 2026 for the EU digital omnibus

Quick Classification Decision Tree

1
Is the AI system prohibited under Article 5?
Yes: → Unacceptable Risk (Prohibited)
No: Continue to next question
2
Is it a safety component of a product covered by EU harmonised legislation (Annex I)?
Yes: → High Risk
No: Continue
3
Is it listed in Annex III (critical sectors & use cases)?
Yes: → High Risk (unless exception applies)
No: Continue
4
Does it interact with users presenting as human, or generate/manipulate content?
Yes: → Limited Risk (transparency obligations)
No: → Minimal Risk

Compliance Timeline

The EU digital omnibus, formally adopted in June 2026, deferred the high-risk compliance dates without touching the prohibitions, GPAI obligations, or transparency obligations. These are the dates that matter for classification.

2 February 2025
Article 5 prohibitions on unacceptable-risk AI practices apply.
2 August 2025
Obligations for general-purpose AI (GPAI) models apply.
2 August 2026
Article 50 transparency obligations apply: users must be told they are interacting with AI, and AI-generated content must be disclosed.
2 December 2026
New prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material applies; deadline for machine-readable marking of AI-generated content by systems already on the market.
2 December 2027
High-risk obligations apply to stand-alone Annex III systems, deferred from 2 August 2026 by the digital omnibus.
2 August 2028
High-risk obligations apply to AI embedded in Annex I regulated products, deferred from 2 August 2027.

Risk Tier Reference Guide

Unacceptable Risk

Prohibited

AI systems that pose a clear threat to fundamental rights, safety, or EU values. These practices are banned from 2 February 2025. The June 2026 digital omnibus added a further prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026.

Examples
  • Biometric categorisation systems that infer sensitive attributes (race, political opinion, religion, sexual orientation) from biometric data
  • Real-time remote biometric identification in publicly accessible spaces by law enforcement (with narrow exceptions)
  • Social scoring systems by public authorities that lead to detrimental treatment
  • AI systems that exploit vulnerabilities (age, disability, social/economic situation) to manipulate behaviour
  • Subliminal techniques that bypass conscious awareness to distort behaviour causing harm
  • Predictive policing based solely on profiling or personality traits (not objective, verifiable facts)
  • AI systems that generate non-consensual intimate imagery or child sexual abuse material (prohibition added by the June 2026 digital omnibus, applies from 2 December 2026)
Obligations
  • Discontinue use immediately
  • Do not procure or deploy
  • Document the review and rationale for exclusion

High Risk

Full compliance required

AI systems used in critical sectors or safety applications. Subject to strict requirements before market placement. Stand-alone Annex III systems must comply from 2 December 2027, and AI embedded in Annex I regulated products from 2 August 2028 (dates deferred by the June 2026 digital omnibus).

Examples
  • Biometric identification and categorisation (Annex III, 1)
  • Critical infrastructure management: electricity, water, gas, transport (Annex III, 2)
  • Educational/vocational assessment determining access to institutions (Annex III, 3)
  • Employment decisions: recruitment, CV screening, task allocation, promotion, termination (Annex III, 4)
  • Access to essential services: credit scoring, insurance risk assessment, emergency dispatch (Annex III, 5)
  • Law enforcement: individual risk assessment, polygraph, crime analytics (Annex III, 6)
  • Migration, asylum, and border control management (Annex III, 7)
  • Administration of justice and democratic processes (Annex III, 8)
Obligations
  • Risk management system (ongoing, documented)
  • Data governance and training data documentation
  • Technical documentation (before market placement)
  • Record-keeping and automatic logging of events
  • Transparency and information provision to deployers
  • Human oversight measures built in by design
  • Accuracy, robustness, and cybersecurity requirements
  • EU conformity assessment (self-assessment or third-party)
  • Registration in EU database (Art. 71)
  • CE marking and Declaration of Conformity
  • Post-market monitoring system
  • Incident reporting to national authorities

Limited Risk

Transparency obligations

AI systems with specific transparency risks. Users must be told they are interacting with AI. These duties apply from 2 August 2026; generative systems already on the market before that date have until 2 December 2026 to meet Article 50(2)'s machine-readable marking duty.

Examples
  • Chatbots and virtual assistants interacting with natural persons
  • Emotion recognition systems (must disclose to individuals)
  • Deepfake images, audio, or video content generated by AI
  • AI-generated text published to inform the public on matters of public interest
  • Biometric categorisation or emotion recognition systems not in Annex III
Obligations
  • Notify users they are interacting with an AI system (unless obvious from context)
  • Label AI-generated content (images, audio, video, text) as artificially generated
  • Implement technical solutions for content provenance (watermarking recommended)

Minimal Risk

No mandatory requirements

The vast majority of AI systems in use today fall here. No mandatory EU AI Act requirements beyond general law (GDPR, product liability, consumer protection). Voluntary codes of conduct encouraged.

Examples
  • AI-powered spam filters
  • AI-enabled inventory management
  • Product recommendation engines
  • AI-based content moderation (non-employment, non-public service context)
  • Business intelligence and analytics tools
  • AI writing assistants for internal use (not public-facing news)
  • AI-assisted scheduling and logistics optimisation
Obligations
  • No mandatory EU AI Act obligations
  • Consider voluntary AI Code of Conduct
  • Standard GDPR and data protection obligations still apply
  • Document classification rationale for audit purposes
Get started

Automate your EU AI Act compliance

Aona AI discovers every AI tool in your organisation, classifies it by risk, and gives you the governance controls the EU AI Act requires.