complianceFor: innovation-lead-corporate

EU AI Act Risk Assessment Template: Classify Your AI System and Document Compliance

The EU AI Act came into force on 1 August 2024 with a phased implementation timeline. If you are building, deploying, or selling AI systems in the EU or UK, you are subject to its requirements. The first compliance obligation every organisation must meet is risk classification: determining which risk tier your AI system falls into and what that means for your compliance obligations. High-risk AI systems face the most demanding requirements, including conformity assessments, technical documentation, human oversight mechanisms, and registration in the EU database. Limited-risk and minimal-risk systems have lighter obligations, primarily around transparency. This template walks you through the EU AI Act risk classification process step by step. It is designed for CTOs, product managers, and compliance leads at startups and SMEs who need to understand their obligations before they build, not after they deploy. Important legal note: this template is an educational tool to help you structure your compliance thinking. It is not legal advice. Organisations deploying high-risk AI systems should engage qualified legal counsel with EU AI Act expertise. SpeedMVPs can connect you with specialist AI legal advisors.

How to use this template: Copy the sections below and adapt the placeholder content to your specific use case. Contact us if you need help implementing it.

EU AI Act Risk Classification Overview

The EU AI Act establishes four risk tiers. Understanding which tier your system falls into is the first step of compliance. Tier 1: Unacceptable Risk (Prohibited) AI systems in this category are banned outright from 2 February 2025. Examples include: social scoring systems by public authorities, AI that exploits psychological vulnerabilities to manipulate behaviour, real-time remote biometric identification in public spaces by law enforcement (with limited exceptions), and AI systems that infer emotions in the workplace or educational institutions (from August 2026). If your system falls here, it cannot be deployed in the EU or UK regardless of consent. Tier 2: High Risk High-risk AI systems are permitted but subject to significant obligations before deployment. They appear in Annex III of the Act and include: AI in safety components of critical infrastructure, AI used in education to determine access or evaluate students, AI for employment decisions (recruitment, performance monitoring), AI in essential services (credit scoring, life and health insurance risk assessment), AI used in law enforcement, migration management, administration of justice. High-risk systems require conformity assessment, CE marking, registration in the EU AI Act database, technical documentation, and ongoing post-market monitoring. Tier 3: Limited Risk AI systems that interact with humans but do not carry significant safety or rights risks. Primary obligation is transparency: users must know they are interacting with an AI. Examples: chatbots, AI-generated content, deepfake generation tools. Tier 4: Minimal Risk All other AI systems. No mandatory obligations, though the Act encourages voluntary codes of conduct. Examples: spam filters, AI in video games, AI content recommendation systems.

EU AI Act Risk Assessment Template (Blank Version)

--- EU AI ACT RISK ASSESSMENT --- Document reference: [RA-YYYY-MM-001] Date: [DD/MM/YYYY] AI system name: [Name of the AI system or feature] Version assessed: [e.g. v1.0, or 'Pre-development'] Organisation (Provider/Deployer): [Legal company name] Role: [ ] Provider (you built it) [ ] Deployer (you use it) [ ] Both Prepared by: [Name, Role] Reviewed by: [Name, Role, Date] Next review date: [DD/MM/YYYY] STEP 1: PROHIBITED SYSTEM CHECK Answer all questions. If any answer is YES, stop - this system may be prohibited. 1.1 Does this system perform real-time remote biometric identification in publicly accessible spaces? [ ] Yes [ ] No 1.2 Does this system create or expand facial recognition databases through untargeted scraping? [ ] Yes [ ] No 1.3 Does this system infer emotions of individuals in workplace or educational settings? [ ] Yes [ ] No (Note: prohibited from August 2026) 1.4 Does this system perform social scoring of individuals by or on behalf of public authorities? [ ] Yes [ ] No 1.5 Does this system exploit psychological vulnerabilities (age, disability, social situation) to manipulate behaviour in a way that causes or is likely to cause significant harm? [ ] Yes [ ] No 1.6 Does this system categorise individuals based on biometric data to infer race, political opinions, trade union membership, religious beliefs, or sexual orientation? [ ] Yes [ ] No If all answers are NO: proceed to Step 2. If any answer is YES: Document the finding and engage legal counsel immediately. Do not deploy this system. STEP 2: HIGH-RISK CLASSIFICATION CHECK (ANNEX III) Check each category. If your system performs the described function, it is likely high-risk. 2.1 Critical infrastructure Does this AI system operate as a safety component of critical infrastructure (energy, water, transport, financial infrastructure)? [ ] Yes [ ] No If YES: High-risk. Document which infrastructure sector: [specify] 2.2 Education and vocational training Does this AI system determine access to educational or vocational training institutions, or evaluate learning outcomes or student progress in a way that affects educational attainment? [ ] Yes [ ] No If YES: High-risk. 2.3 Employment and workers management Does this AI system perform any of the following? - Recruitment or selection of natural persons (CV screening, interview analysis, scoring) - Decisions about promotion, dismissal, task allocation, or performance monitoring [ ] Yes [ ] No If YES: High-risk. Specify function: [e.g. CV screening] 2.4 Access to essential private or public services Does this AI system evaluate credit scores or creditworthiness? Does this AI system assess life, health, or insurance risk for individuals? Does this AI system dispatch or prioritise emergency services based on AI decisions? [ ] Yes [ ] No If YES: High-risk. Specify service type: [specify] 2.5 Law enforcement Does this AI system assist in law enforcement functions including threat assessment, crime analysis, evidence evaluation, or lie detection? [ ] Yes [ ] No If YES: High-risk. 2.6 Migration, asylum, and border control Does this AI system assist in immigration or asylum decisions, risk assessments, or document authenticity verification? [ ] Yes [ ] No If YES: High-risk. 2.7 Administration of justice Does this AI system assist in judicial decisions or legal disputes? [ ] Yes [ ] No If YES: High-risk. 2.8 Democratic processes Does this AI system influence elections, voting behaviour, or electoral campaigns? [ ] Yes [ ] No If YES: High-risk (from August 2026 for certain systems). STEP 3: RISK CLASSIFICATION DETERMINATION Based on Step 1 and Step 2: [ ] PROHIBITED: Stop. Engage legal counsel. Do not deploy. [ ] HIGH RISK: Complete Sections 4-7 of this assessment in full. [ ] LIMITED RISK: Complete Section 5 (Transparency obligations) only. [ ] MINIMAL RISK: No mandatory obligations. Document this finding and proceed. Classification rationale: [Write a brief explanation of why this classification was reached, including which Annex III category applies if high-risk, or why no category applies if limited/minimal risk.] STEP 4: HIGH-RISK COMPLIANCE OBLIGATIONS CHECKLIST (Complete only if High Risk classification confirmed) 4.1 Technical documentation (Article 11 + Annex IV) [ ] System description and intended purpose documented [ ] Description of design and development process documented [ ] Training, validation, and testing data documented [ ] Performance metrics and accuracy documented [ ] Foreseeable risks and risk mitigation measures documented [ ] Human oversight measures documented [ ] Instructions for use prepared for deployers 4.2 Data governance (Article 10) [ ] Training data quality criteria defined [ ] Training data examined for bias [ ] Data governance and management practices documented [ ] Relevant personal data GDPR-compliant 4.3 Transparency and instructions for use (Article 13) [ ] Users informed of AI system capabilities and limitations [ ] Level of accuracy and robustness disclosed [ ] Any known bias or unfairness risks disclosed [ ] Instructions for use prepared and provided to deployers [ ] Contact details of provider available to deployers 4.4 Human oversight (Article 14) [ ] Human oversight mechanism defined and implemented [ ] Override capability available to human operators [ ] High-risk decision alert mechanism in place [ ] Staff operating the system trained on limitations and oversight duties 4.5 Accuracy, robustness, and cybersecurity (Article 15) [ ] Accuracy levels defined and documented [ ] Robustness against errors and third-party manipulation tested [ ] Cybersecurity measures implemented and documented 4.6 Conformity assessment (Chapter V) Conformity assessment type required: [ ] Internal conformity assessment (Article 43(2)) - most high-risk systems [ ] Third-party conformity assessment (Article 43(1)) - biometric and critical infrastructure systems Conformity assessment status: [ ] Not started [ ] In progress [ ] Completed Estimated completion date: [DD/MM/YYYY] 4.7 EU database registration (Article 49) Required before market deployment for high-risk systems. Registration status: [ ] Not started [ ] In progress [ ] Registered EU database registration number (if registered): [Number] 4.8 CE marking CE marking affixed: [ ] Yes [ ] No [ ] Not yet applicable STEP 5: TRANSPARENCY OBLIGATIONS (LIMITED RISK SYSTEMS) 5.1 Chatbot / conversational AI [ ] Users are informed they are interacting with an AI at the start of each interaction [ ] Disclosure mechanism is clear and unambiguous (not buried in terms of service) 5.2 AI-generated content (text, image, audio, video) [ ] AI-generated content is labelled as such in machine-readable format [ ] Deepfakes or synthetic media clearly labelled as artificially generated 5.3 Emotion recognition or biometric categorisation systems [ ] Users informed the system uses emotion recognition or biometric categorisation STEP 6: GDPR ALIGNMENT CHECK 6.1 Does this AI system process personal data of EU data subjects? [ ] Yes [ ] No 6.2 If yes, is a DPIA (Data Protection Impact Assessment) required? (DPIA required for systematic large-scale processing, or high-risk processing under GDPR Article 35) [ ] Yes - DPIA completed on [DD/MM/YYYY] [ ] Yes - DPIA in progress, expected [DD/MM/YYYY] [ ] No - rationale: [Brief explanation] 6.3 Lawful basis for processing: [ ] Consent [ ] Contract [ ] Legal obligation [ ] Vital interests [ ] Public task [ ] Legitimate interests STEP 7: RISK ASSESSMENT SUMMARY 7.1 Classification: [PROHIBITED / HIGH RISK / LIMITED RISK / MINIMAL RISK] 7.2 Key obligations triggered: [List the main compliance obligations that apply based on this classification] 7.3 Compliance gaps identified: [List any obligations not yet met, with planned remediation and dates] 7.4 Residual risks: [List any risks that cannot be fully mitigated through technical or organisational measures, and how they are disclosed to deployers/users] 7.5 Sign-off: Prepared by: [Name] [Date] Reviewed by: [Name] [Date] Approved by: [Name (CEO/CTO/DPO)] [Date] --- END OF TEMPLATE ---

Filled Example: ContractCheck AI (Limited Risk Classification)

AI system name: ContractCheck AI - Contract Review Feature Version: v1.0 (pre-deployment assessment) Organisation: LegalEdge Ltd (Provider) Date: 10/06/2025 STEP 1: Prohibited system check - All answers NO. Proceed to Step 2. STEP 2: High-risk check: 2.1 Critical infrastructure: NO 2.2 Education: NO 2.3 Employment: NO - the system analyses contracts, not employment decisions 2.4 Essential services: NO - the system does not score creditworthiness; it reviews commercial contracts uploaded voluntarily by the user 2.5-2.8: All NO STEP 3: Classification: LIMITED RISK Rationale: ContractCheck AI is a B2B tool that analyses contract documents uploaded by the user and produces a plain-English risk summary. It does not make binding decisions about individuals, does not access personal data of third parties beyond what is included in user-uploaded documents, and does not fall within any Annex III high-risk category. As a conversational/analytical AI interface, it is subject to transparency obligations only. STEP 5: Transparency obligations: The system presents a disclosure banner at first use: 'ContractCheck uses AI to analyse your contracts. This is not legal advice. Always consult a qualified solicitor before signing.' This disclosure is also included in every generated report as a mandatory disclaimer. STEP 6: GDPR alignment: 6.1 YES - contracts uploaded may contain personal data of third parties (counterparty names, addresses, signatories) 6.2 DPIA completed 01/06/2025. Low-risk finding: data is processed transiently (not stored beyond session unless user saves report), no systematic monitoring of individuals, third-party data is incidental to the contract analysis purpose. 6.3 Lawful basis: Contract performance (user has contracted with LegalEdge for the service); Legitimate interests for incidental processing of third-party personal data in uploaded contracts.

EU AI Act Implementation Timeline

Understanding which obligations apply when is essential for compliance planning. 2 February 2025: Prohibited AI systems prohibited. GPAI (General Purpose AI) model obligations begin for providers of GPAI models. 2 August 2025: Obligations for GPAI model providers with systemic risk apply. Codes of practice for GPAI. All newly deployed AI systems must begin compliance efforts. 2 August 2026: Full application of most provisions, including all high-risk AI system obligations. High-risk systems already on the market before this date have a 2-year grace period from this point (until August 2028) to comply if no significant changes are made. 2 August 2027: High-risk AI systems used as safety components of products under other EU product safety directives must comply. For UK organisations: The UK has not adopted the EU AI Act directly. The UK government is taking a sector-led, proportionate approach via the AI Safety Institute and existing sector regulators (FCA, ICO, CMA). However, UK organisations selling into the EU market are subject to the EU AI Act for those deployments. UK organisations with GDPR compliance obligations via UK GDPR should also align AI practices with ICO AI guidance.

How SpeedMVPs Builds EU AI Act Compliance In By Default

Every AI system SpeedMVPs builds includes the following by default, at no additional cost: self-referencing transparency disclosures for conversational AI interfaces, human oversight hook points documented in the codebase, structured logging for post-market monitoring, data processing documentation for GDPR compliance, and risk classification review as part of the technical scoping process. For clients building systems that may fall under high-risk classification, we provide a paid EU AI Act compliance sprint that produces: a completed risk assessment document, a gap analysis against Article 9-15 obligations, a technical documentation pack meeting Annex IV requirements, and a conformity assessment preparation checklist. We also work with partner legal firms specialising in EU AI Act compliance for the legal opinion components that require qualified legal counsel.

Frequently Asked Questions

Does the EU AI Act apply to UK companies?+

The EU AI Act applies to AI systems placed on the EU market or put into service in the EU, regardless of where the provider is established. If you are a UK company with EU customers, or if your AI system is used by EU-based users or companies, the EU AI Act applies to that deployment. UK companies selling only to UK customers are not directly subject to the EU AI Act, but the UK government may introduce equivalent legislation. The ICO has already published AI guidance that creates de facto obligations for UK AI systems processing personal data.

When do EU AI Act obligations start for startups?+

Prohibited systems have been banned since 2 February 2025. For high-risk AI systems, the main obligations apply from 2 August 2026 for newly deployed systems. However, you should begin compliance work now if you are building a system that may be high-risk - conformity assessments, technical documentation, and governance structures take time to implement. Leaving compliance until the deadline creates risk and cost. For limited-risk systems (chatbots, AI-generated content), transparency obligations apply from August 2026 but are straightforward to implement.

What happens if my AI system is classified as high-risk?+

You are still allowed to build and deploy it, but you must meet significant requirements before deployment: complete technical documentation (Annex IV), a conformity assessment (self-assessment or third-party depending on the system type), registration in the EU AI Act database, CE marking for products, and ongoing post-market monitoring. The conformity assessment is the most demanding requirement for most systems - it requires demonstrating compliance against Articles 9-15 of the Act. SpeedMVPs can help structure technical documentation and build oversight mechanisms; legal review of the conformity assessment by qualified EU AI Act counsel is recommended.

Is a B2B SaaS product that uses OpenAI or Claude APIs subject to the EU AI Act?+

Yes, if you deploy it to EU users. As a deployer of a General Purpose AI (GPAI) model (GPT-4o, Claude, etc.), you are responsible for ensuring your use of that model complies with the Act. The GPAI model provider (OpenAI, Anthropic) has separate obligations as a GPAI provider. Your obligations as a deployer depend on whether your use case falls into a high-risk category. Most B2B SaaS products that use LLMs for content generation, summarisation, or analysis will be classified as minimal or limited risk, with transparency as the main obligation.

Can SpeedMVPs help with EU AI Act compliance for our AI product?+

Yes. SpeedMVPs includes risk classification review and basic transparency implementation in every AI development engagement. For organisations requiring full high-risk compliance documentation, we offer a dedicated EU AI Act Compliance Sprint that produces complete technical documentation, a conformity assessment preparation pack, and human oversight implementation. We also partner with specialist EU AI Act legal advisors for the legal opinion components.

Want us to build this for you?

Building an AI system for EU markets? SpeedMVPs builds GDPR and EU AI Act compliant AI products with compliance built in from day one - not bolted on after launch. Book a free consultation to discuss your compliance obligations before you start building.

Get a Free Quote