# EU AI Act Risk Classification Template

**Organisation:** [ORGANISATION NAME]
**Owner:** [NAME / ROLE]
**Date:** [DATE]
**Version:** 1.0
**Last updated:** July 2026, reflects the June 2026 digital omnibus

---

## Purpose

The EU AI Act introduces four risk tiers for AI systems, each with different compliance obligations. Use this template to classify every AI system in your portfolio, understand what is required for each tier, and build the evidence base you need for compliance. It applies to organisations that deploy AI in the EU, regardless of where they are headquartered.

---

## How to Use

1. List every AI system, tool, model, or embedded AI feature in your portfolio in the system register below.
2. Run each system through the quick classification decision tree to assign a risk tier.
3. Use the risk tier reference guide to record the obligations that apply.
4. Document the rationale for each classification and store it as audit evidence.
5. Re-classify whenever a system changes materially or new use cases are added.

---

## Compliance Timeline

The digital omnibus, formally adopted at the end of June 2026 (Parliament on 16 June, Council on 29 June), deferred the high-risk compliance dates and made targeted simplifications, including extending SME relief to small mid-caps (fewer than 750 employees). Prohibitions, GPAI obligations, and the core transparency obligations kept their dates; providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty.

| Date | What applies |
|------|--------------|
| 2 February 2025 | Article 5 prohibitions on unacceptable-risk AI practices |
| 2 August 2025 | Obligations for general-purpose AI (GPAI) models |
| 2 August 2026 | Article 50 transparency obligations: AI disclosure and labelling of AI-generated content |
| 2 December 2026 | New prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material; content-marking deadline for systems already on the market before 2 August 2026 |
| 2 December 2027 | High-risk obligations for stand-alone Annex III systems (deferred from 2 August 2026) |
| 2 August 2028 | High-risk obligations for AI embedded in Annex I regulated products (deferred from 2 August 2027) |

---

## Quick Classification Decision Tree

Answer each question in order. Stop at the first tier you reach.

1. **Is the AI system prohibited under Article 5?** Yes: Unacceptable Risk (Prohibited). No: continue.
2. **Is it a safety component of a product covered by EU harmonised legislation (Annex I)?** Yes: High Risk. No: continue.
3. **Is it listed in Annex III (critical sectors and use cases)?** Yes: High Risk (unless an exception applies). No: continue.
4. **Does it interact with users presenting as human, or generate or manipulate content?** Yes: Limited Risk (transparency obligations). No: Minimal Risk.

---

## System Register

| # | System name | Use case | Tier assigned | Rationale | Owner |
|---|-------------|----------|---------------|-----------|-------|
| 1 | [System] | [Use case] | [Tier] | [Why] | [Owner] |
| 2 | | | | | |
| 3 | | | | | |

---

## Risk Tier Reference Guide

### Unacceptable Risk: Prohibited

AI systems that pose a clear threat to fundamental rights, safety, or EU values. These practices are banned from 2 February 2025. The June 2026 digital omnibus added a further prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026.

**Examples**

- Biometric categorisation systems that infer sensitive attributes (race, political opinion, religion, sexual orientation) from biometric data
- Real-time remote biometric identification in publicly accessible spaces by law enforcement (with narrow exceptions)
- Social scoring systems by public authorities that lead to detrimental treatment
- AI systems that exploit vulnerabilities (age, disability, social or economic situation) to manipulate behaviour
- Subliminal techniques that bypass conscious awareness to distort behaviour causing harm
- Predictive policing based solely on profiling or personality traits (not objective, verifiable facts)
- AI systems that generate non-consensual intimate imagery or child sexual abuse material (prohibition added by the June 2026 digital omnibus, applies from 2 December 2026)

**Obligations**

- Discontinue use immediately
- Do not procure or deploy
- Document the review and rationale for exclusion

> Full prohibition, no grace period. Any system matching these criteria must be decommissioned.

---

### High Risk: Full compliance required

AI systems used in critical sectors or safety applications. Subject to strict requirements before market placement. Stand-alone Annex III systems must comply from 2 December 2027, and AI embedded in Annex I regulated products from 2 August 2028. Both dates were deferred by the June 2026 digital omnibus.

**Examples**

- Biometric identification and categorisation (Annex III, 1)
- Critical infrastructure management: electricity, water, gas, transport (Annex III, 2)
- Educational or vocational assessment determining access to institutions (Annex III, 3)
- Employment decisions: recruitment, CV screening, task allocation, promotion, termination (Annex III, 4)
- Access to essential services: credit scoring, insurance risk assessment, emergency dispatch (Annex III, 5)
- Law enforcement: individual risk assessment, polygraph, crime analytics (Annex III, 6)
- Migration, asylum, and border control management (Annex III, 7)
- Administration of justice and democratic processes (Annex III, 8)

**Obligations**

- Risk management system (ongoing, documented)
- Data governance and training data documentation
- Technical documentation (before market placement)
- Record-keeping and automatic logging of events
- Transparency and information provision to deployers
- Human oversight measures built in by design
- Accuracy, robustness, and cybersecurity requirements
- EU conformity assessment (self-assessment or third-party)
- Registration in EU database (Art. 71)
- CE marking and Declaration of Conformity
- Post-market monitoring system
- Incident reporting to national authorities

**Compliance actions**

- Designate an EU AI Act compliance owner
- Complete conformity assessment before deployment
- Register in the EU AI Act public database
- Implement ongoing post-market monitoring

---

### Limited Risk: Transparency obligations

AI systems with specific transparency risks. Users must be told they are interacting with AI. These duties apply from 2 August 2026; generative systems already on the market before that date have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty.

**Examples**

- Chatbots and virtual assistants interacting with natural persons
- Emotion recognition systems (must disclose to individuals)
- Deepfake images, audio, or video content generated by AI
- AI-generated text published to inform the public on matters of public interest
- Biometric categorisation or emotion recognition systems not in Annex III

**Obligations**

- Notify users they are interacting with an AI system (unless obvious from context)
- Label AI-generated content (images, audio, video, text) as artificially generated
- Implement technical solutions for content provenance and marking of AI-generated content (systems already on the market before 2 August 2026 have until 2 December 2026 to comply with content marking)

**Compliance actions**

- Add AI disclosure notices to chatbot UIs
- Label generated content
- Update privacy notices to disclose AI use

---

### Minimal Risk: No mandatory requirements

The vast majority of AI systems in use today fall here. No mandatory EU AI Act requirements beyond general law (GDPR, product liability, consumer protection). Voluntary codes of conduct are encouraged.

**Examples**

- AI-powered spam filters
- AI-enabled inventory management
- Product recommendation engines
- AI-based content moderation (non-employment, non-public-service context)
- Business intelligence and analytics tools
- AI writing assistants for internal use (not public-facing news)
- AI-assisted scheduling and logistics optimisation

**Obligations**

- No mandatory EU AI Act obligations
- Consider a voluntary AI Code of Conduct
- Standard GDPR and data protection obligations still apply
- Document classification rationale for audit purposes

**Compliance actions**

- Document why each system is classified minimal risk
- Apply GDPR as applicable
- Consider voluntary transparency measures for user trust

---

*This template is provided free by Aona AI and is general information, not legal advice. Confirm obligations and effective dates against the official text of the EU AI Act and your own legal counsel. See `/resources/templates` for related governance templates.*
