compliance

AI Risk Classification Under the EU AI Act

The EU AI Act's framework for categorising AI systems by risk level: minimal, limited, high, and unacceptable, determining applicable compliance obligations.

Before your AI product can reach customers in the EU, you need to understand where it sits in the EU AI Act's risk framework. Risk classification is not a bureaucratic formality - it determines whether your product can ship without any compliance action, whether it needs transparency notices, or whether it requires rigorous conformity assessment before deployment. Getting this wrong is expensive. Getting it right early is one of the most useful things a product team can do during scoping. This guide explains the four risk tiers, how to determine which applies to your system, and what the classification means for your development process. For UK founders, the stakes are practical: a misclassified system targeting enterprise EU buyers can stall a sales process the moment their procurement team asks for conformity documentation that does not exist. The EU AI Act's high-risk obligations apply from August 2026, meaning products already in development need a classification decision now, not at launch. SpeedMVPs has helped seed-stage and Series A teams work through risk classification during the scoping phase, so architecture choices and compliance documentation requirements are locked in before a line of code is written, avoiding costly rework at the point of market entry.

The Four Risk Tiers Explained

The EU AI Act organises AI systems into four tiers based on the potential harm they could cause. Unacceptable risk covers AI uses that are banned outright: social scoring by governments, real-time remote biometric surveillance in public spaces, systems that exploit psychological vulnerabilities to manipulate behaviour. No commercial AI product should sit here. High risk covers AI systems in eight regulated domains including critical infrastructure, education, employment and HR tools, essential private and public services, law enforcement, migration, administration of justice, and democratic processes. If your product automates a credit decision, screens job candidates, allocates NHS resources, or assists in legal judgements, you are in this tier. Limited risk applies to systems with specific transparency obligations only, chiefly chatbots and AI-generated content. Users must be told they are interacting with an AI. Minimal risk covers everything else, including most business productivity tools, recommendation engines for entertainment, and general-purpose AI assistants where no high-risk use case is in scope. Most early-stage AI MVPs fall here or in limited risk.

High-Risk AI: What Compliance Actually Requires

If your system qualifies as high risk, the compliance burden is substantial. You need a risk management system documented and maintained across the product lifecycle. Your training data must be assessed for quality, relevance, and potential bias. Technical documentation must be produced before the system is placed on the market. Automatic logging must capture enough data for post-market monitoring and incident investigation. Human oversight must be built into the system design, not bolted on. For providers established outside the EU, you must appoint an EU-based authorised representative. For UK companies like those working with SpeedMVPs, this means the EU market requires either an in-EU legal entity or a designated representative before a high-risk system can be sold to EU customers. The obligations sound heavy because they are. Most founders discover they are not in this tier once they examine their use case carefully.

How to Determine Your Classification

The first question is whether your AI system is listed in Annex III of the EU AI Act, which defines the high-risk use cases. Read the annex literally. Courts and regulators interpret legal text narrowly, not by analogy. If your HR tool screens CVs before a human reviews them, that is Annex III. If your tool helps HR professionals draft job descriptions, it is not. The second question is whether your product is a general-purpose AI model, which carries its own obligations under the Act regardless of risk tier. The third question is what the actual deployment context is. An AI used by a medical professional to inform a clinical decision is assessed differently from one that makes the decision autonomously. Document your classification decision and the reasoning behind it. If regulators later challenge your categorisation, documented reasoning is your strongest defence.

GDPR Intersection and DPIA Triggers

AI risk classification under the EU AI Act does not replace your GDPR obligations, it adds to them. A system that qualifies as high risk under the EU AI Act will almost certainly also trigger a Data Protection Impact Assessment under GDPR Article 35, particularly if it involves systematic profiling, processing of special category data such as health or biometric data, or automated decision-making with legal or similarly significant effects. The ICO in the UK has published guidance on AI and data protection that maps closely to the EU AI Act framework. If you are building for both UK and EU markets, your DPIA should address both UK GDPR and EU AI Act obligations together rather than treating them as separate documents. SpeedMVPs builds GDPR-aware architecture from sprint one, which gives projects a foundation that simplifies both DPIA completion and EU AI Act technical documentation.

Limited Risk: Chatbot Transparency Requirements

Most consumer-facing AI products land in the limited risk tier, where the primary obligation is transparency. If your product includes a chatbot or AI-generated conversational interface, users must be told they are talking to an AI system. This disclosure must happen at the start of interaction, not buried in terms of service. Similarly, AI-generated text, images, audio, or video that could be mistaken for human-created content must carry a machine-readable label. For deepfake-style content the labelling obligation is stricter. These requirements sound simple, and technically they are. The implementation challenge is doing the disclosure in a way that does not damage user experience or conversion rates. The solution is usually a brief, plain-language notice at conversation start that most users accept naturally because they expect AI interaction in modern products.

Practical Steps for UK AI Product Teams

Start classification during scoping, not after build. The earlier you know which tier applies, the more your architecture can accommodate compliance requirements without expensive rework. Document your classification decision with reference to the specific Annex III use cases you considered and ruled out. Build your transparency disclosures into the product design from the beginning rather than retrofitting them. If you are selling to enterprise customers in the EU, expect them to ask for your EU AI Act documentation as part of procurement due diligence by 2026 and beyond. If your system is high risk, begin your conformity assessment process six to twelve months before market entry, not in the final weeks before launch. The transition periods in the EU AI Act are tightening, with prohibitions already in force and high-risk obligations applying from August 2026.

Frequently Asked Questions

How do I know if my AI product is high risk under the EU AI Act?+

Check Annex III of the EU AI Act, which lists the eight categories of high-risk AI use cases. These cover employment screening, credit scoring, essential service allocation, educational assessment, law enforcement, migration, justice, and critical infrastructure. If your system performs a function within one of these categories, read the specific subcategory carefully. The classification is use-case specific, not technology specific. The same underlying model can be minimal risk in one deployment context and high risk in another.

Does the EU AI Act apply to UK companies?+

Yes, if your AI product is placed on the EU market or affects EU residents, the EU AI Act applies regardless of where you are established. UK companies selling AI systems to EU customers, deploying systems used by EU residents, or providing AI services consumed in the EU must comply. Post-Brexit, UK companies do not benefit from any automatic alignment with EU AI Act requirements. You must appoint an EU-based authorised representative for high-risk systems if your company has no EU establishment.

What is the penalty for misclassifying an AI system?+

The EU AI Act sets fines by tier. Placing a prohibited AI system on the market carries fines up to EUR 35 million or 7% of global annual turnover. Non-compliance with obligations for high-risk systems carries fines up to EUR 15 million or 3% of turnover. Providing incorrect or misleading information to authorities carries fines up to EUR 7.5 million or 1.5% of turnover. Member state market surveillance authorities will investigate, and enforcement is expected to intensify from 2026 onwards.

If my AI chatbot is limited risk, what do I actually need to implement?+

For a limited-risk chatbot, the main requirement is that users are clearly informed they are interacting with an AI system at the start of each interaction. This must be explicit, not implied. You also need to ensure that any AI-generated content that could be mistaken for real is labelled appropriately. Beyond that, your primary obligations are GDPR-based: lawful basis for any personal data processing, data minimisation, transparency in your privacy notice about AI use, and a DPIA if the processing involves profiling or sensitive categories of data.

Can I build a high-risk AI MVP and sort out compliance later?+

Not safely. High-risk AI systems cannot be placed on the EU market without completing the required conformity assessment first. This is not like a GDPR compliance programme you can start after launch - it is a pre-market requirement. If you are building in a high-risk category, compliance must be part of the build plan from day one. SpeedMVPs recommends scoping compliance requirements in the discovery phase for any AI product touching Annex III use cases, so the architecture supports documentation, logging, and oversight requirements from the start.

If you are unsure where your AI product sits in the EU AI Act risk framework, we can help you work through it during scoping. Get a free consultation at speedmvps.co.uk

Get a Free Quote