The EU AI Act introduces four risk tiers for AI systems, each with different compliance obligations. This template helps you classify every AI system in your portfolio, understand what is required for each tier, and build the evidence base you need for compliance. Applies to organisations that deploy AI in the EU, regardless of where they are headquartered. Updated July 2026 to reflect the June 2026 digital omnibus and the deferred high-risk compliance dates.
The EU digital omnibus, formally adopted in June 2026, deferred the high-risk compliance dates without touching the prohibitions, GPAI obligations, or transparency obligations. These are the dates that matter for classification.
AI systems that pose a clear threat to fundamental rights, safety, or EU values. These practices are banned from 2 February 2025. The June 2026 digital omnibus added a further prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026.
AI systems used in critical sectors or safety applications. Subject to strict requirements before market placement. Stand-alone Annex III systems must comply from 2 December 2027, and AI embedded in Annex I regulated products from 2 August 2028 (dates deferred by the June 2026 digital omnibus).
AI systems with specific transparency risks. Users must be told they are interacting with AI. These duties apply from 2 August 2026; generative systems already on the market before that date have until 2 December 2026 to meet Article 50(2)'s machine-readable marking duty.
The vast majority of AI systems in use today fall here. No mandatory EU AI Act requirements beyond general law (GDPR, product liability, consumer protection). Voluntary codes of conduct encouraged.
Aona AI discovers every AI tool in your organisation, classifies it by risk, and gives you the governance controls the EU AI Act requires.