EU AI Act Risk Classification Overview
The EU AI Act establishes four risk tiers. Understanding which tier your system falls into is the first step of compliance. Tier 1: Unacceptable Risk (Prohibited) AI systems in this category are banned outright from 2 February 2025. Examples include: social scoring systems by public authorities, AI that exploits psychological vulnerabilities to manipulate behaviour, real-time remote biometric identification in public spaces by law enforcement (with limited exceptions), and AI systems that infer emotions in the workplace or educational institutions (from August 2026). If your system falls here, it cannot be deployed in the EU or UK regardless of consent. Tier 2: High Risk High-risk AI systems are permitted but subject to significant obligations before deployment. They appear in Annex III of the Act and include: AI in safety components of critical infrastructure, AI used in education to determine access or evaluate students, AI for employment decisions (recruitment, performance monitoring), AI in essential services (credit scoring, life and health insurance risk assessment), AI used in law enforcement, migration management, administration of justice. High-risk systems require conformity assessment, CE marking, registration in the EU AI Act database, technical documentation, and ongoing post-market monitoring. Tier 3: Limited Risk AI systems that interact with humans but do not carry significant safety or rights risks. Primary obligation is transparency: users must know they are interacting with an AI. Examples: chatbots, AI-generated content, deepfake generation tools. Tier 4: Minimal Risk All other AI systems. No mandatory obligations, though the Act encourages voluntary codes of conduct. Examples: spam filters, AI in video games, AI content recommendation systems.
EU AI Act Risk Assessment Template (Blank Version)
--- EU AI ACT RISK ASSESSMENT --- Document reference: [RA-YYYY-MM-001] Date: [DD/MM/YYYY] AI system name: [Name of the AI system or feature] Version assessed: [e.g. v1.0, or 'Pre-development'] Organisation (Provider/Deployer): [Legal company name] Role: [ ] Provider (you built it) [ ] Deployer (you use it) [ ] Both Prepared by: [Name, Role] Reviewed by: [Name, Role, Date] Next review date: [DD/MM/YYYY] STEP 1: PROHIBITED SYSTEM CHECK Answer all questions. If any answer is YES, stop - this system may be prohibited. 1.1 Does this system perform real-time remote biometric identification in publicly accessible spaces? [ ] Yes [ ] No 1.2 Does this system create or expand facial recognition databases through untargeted scraping? [ ] Yes [ ] No 1.3 Does this system infer emotions of individuals in workplace or educational settings? [ ] Yes [ ] No (Note: prohibited from August 2026) 1.4 Does this system perform social scoring of individuals by or on behalf of public authorities? [ ] Yes [ ] No 1.5 Does this system exploit psychological vulnerabilities (age, disability, social situation) to manipulate behaviour in a way that causes or is likely to cause significant harm? [ ] Yes [ ] No 1.6 Does this system categorise individuals based on biometric data to infer race, political opinions, trade union membership, religious beliefs, or sexual orientation? [ ] Yes [ ] No If all answers are NO: proceed to Step 2. If any answer is YES: Document the finding and engage legal counsel immediately. Do not deploy this system. STEP 2: HIGH-RISK CLASSIFICATION CHECK (ANNEX III) Check each category. If your system performs the described function, it is likely high-risk. 2.1 Critical infrastructure Does this AI system operate as a safety component of critical infrastructure (energy, water, transport, financial infrastructure)? [ ] Yes [ ] No If YES: High-risk. Document which infrastructure sector: [specify] 2.2 Education and vocational training Does this AI system determine access to educational or vocational training institutions, or evaluate learning outcomes or student progress in a way that affects educational attainment? [ ] Yes [ ] No If YES: High-risk. 2.3 Employment and workers management Does this AI system perform any of the following? - Recruitment or selection of natural persons (CV screening, interview analysis, scoring) - Decisions about promotion, dismissal, task allocation, or performance monitoring [ ] Yes [ ] No If YES: High-risk. Specify function: [e.g. CV screening] 2.4 Access to essential private or public services Does this AI system evaluate credit scores or creditworthiness? Does this AI system assess life, health, or insurance risk for individuals? Does this AI system dispatch or prioritise emergency services based on AI decisions? [ ] Yes [ ] No If YES: High-risk. Specify service type: [specify] 2.5 Law enforcement Does this AI system assist in law enforcement functions including threat assessment, crime analysis, evidence evaluation, or lie detection? [ ] Yes [ ] No If YES: High-risk. 2.6 Migration, asylum, and border control Does this AI system assist in immigration or asylum decisions, risk assessments, or document authenticity verification? [ ] Yes [ ] No If YES: High-risk. 2.7 Administration of justice Does this AI system assist in judicial decisions or legal disputes? [ ] Yes [ ] No If YES: High-risk. 2.8 Democratic processes Does this AI system influence elections, voting behaviour, or electoral campaigns? [ ] Yes [ ] No If YES: High-risk (from August 2026 for certain systems). STEP 3: RISK CLASSIFICATION DETERMINATION Based on Step 1 and Step 2: [ ] PROHIBITED: Stop. Engage legal counsel. Do not deploy. [ ] HIGH RISK: Complete Sections 4-7 of this assessment in full. [ ] LIMITED RISK: Complete Section 5 (Transparency obligations) only. [ ] MINIMAL RISK: No mandatory obligations. Document this finding and proceed. Classification rationale: [Write a brief explanation of why this classification was reached, including which Annex III category applies if high-risk, or why no category applies if limited/minimal risk.] STEP 4: HIGH-RISK COMPLIANCE OBLIGATIONS CHECKLIST (Complete only if High Risk classification confirmed) 4.1 Technical documentation (Article 11 + Annex IV) [ ] System description and intended purpose documented [ ] Description of design and development process documented [ ] Training, validation, and testing data documented [ ] Performance metrics and accuracy documented [ ] Foreseeable risks and risk mitigation measures documented [ ] Human oversight measures documented [ ] Instructions for use prepared for deployers 4.2 Data governance (Article 10) [ ] Training data quality criteria defined [ ] Training data examined for bias [ ] Data governance and management practices documented [ ] Relevant personal data GDPR-compliant 4.3 Transparency and instructions for use (Article 13) [ ] Users informed of AI system capabilities and limitations [ ] Level of accuracy and robustness disclosed [ ] Any known bias or unfairness risks disclosed [ ] Instructions for use prepared and provided to deployers [ ] Contact details of provider available to deployers 4.4 Human oversight (Article 14) [ ] Human oversight mechanism defined and implemented [ ] Override capability available to human operators [ ] High-risk decision alert mechanism in place [ ] Staff operating the system trained on limitations and oversight duties 4.5 Accuracy, robustness, and cybersecurity (Article 15) [ ] Accuracy levels defined and documented [ ] Robustness against errors and third-party manipulation tested [ ] Cybersecurity measures implemented and documented 4.6 Conformity assessment (Chapter V) Conformity assessment type required: [ ] Internal conformity assessment (Article 43(2)) - most high-risk systems [ ] Third-party conformity assessment (Article 43(1)) - biometric and critical infrastructure systems Conformity assessment status: [ ] Not started [ ] In progress [ ] Completed Estimated completion date: [DD/MM/YYYY] 4.7 EU database registration (Article 49) Required before market deployment for high-risk systems. Registration status: [ ] Not started [ ] In progress [ ] Registered EU database registration number (if registered): [Number] 4.8 CE marking CE marking affixed: [ ] Yes [ ] No [ ] Not yet applicable STEP 5: TRANSPARENCY OBLIGATIONS (LIMITED RISK SYSTEMS) 5.1 Chatbot / conversational AI [ ] Users are informed they are interacting with an AI at the start of each interaction [ ] Disclosure mechanism is clear and unambiguous (not buried in terms of service) 5.2 AI-generated content (text, image, audio, video) [ ] AI-generated content is labelled as such in machine-readable format [ ] Deepfakes or synthetic media clearly labelled as artificially generated 5.3 Emotion recognition or biometric categorisation systems [ ] Users informed the system uses emotion recognition or biometric categorisation STEP 6: GDPR ALIGNMENT CHECK 6.1 Does this AI system process personal data of EU data subjects? [ ] Yes [ ] No 6.2 If yes, is a DPIA (Data Protection Impact Assessment) required? (DPIA required for systematic large-scale processing, or high-risk processing under GDPR Article 35) [ ] Yes - DPIA completed on [DD/MM/YYYY] [ ] Yes - DPIA in progress, expected [DD/MM/YYYY] [ ] No - rationale: [Brief explanation] 6.3 Lawful basis for processing: [ ] Consent [ ] Contract [ ] Legal obligation [ ] Vital interests [ ] Public task [ ] Legitimate interests STEP 7: RISK ASSESSMENT SUMMARY 7.1 Classification: [PROHIBITED / HIGH RISK / LIMITED RISK / MINIMAL RISK] 7.2 Key obligations triggered: [List the main compliance obligations that apply based on this classification] 7.3 Compliance gaps identified: [List any obligations not yet met, with planned remediation and dates] 7.4 Residual risks: [List any risks that cannot be fully mitigated through technical or organisational measures, and how they are disclosed to deployers/users] 7.5 Sign-off: Prepared by: [Name] [Date] Reviewed by: [Name] [Date] Approved by: [Name (CEO/CTO/DPO)] [Date] --- END OF TEMPLATE ---
Filled Example: ContractCheck AI (Limited Risk Classification)
AI system name: ContractCheck AI - Contract Review Feature Version: v1.0 (pre-deployment assessment) Organisation: LegalEdge Ltd (Provider) Date: 10/06/2025 STEP 1: Prohibited system check - All answers NO. Proceed to Step 2. STEP 2: High-risk check: 2.1 Critical infrastructure: NO 2.2 Education: NO 2.3 Employment: NO - the system analyses contracts, not employment decisions 2.4 Essential services: NO - the system does not score creditworthiness; it reviews commercial contracts uploaded voluntarily by the user 2.5-2.8: All NO STEP 3: Classification: LIMITED RISK Rationale: ContractCheck AI is a B2B tool that analyses contract documents uploaded by the user and produces a plain-English risk summary. It does not make binding decisions about individuals, does not access personal data of third parties beyond what is included in user-uploaded documents, and does not fall within any Annex III high-risk category. As a conversational/analytical AI interface, it is subject to transparency obligations only. STEP 5: Transparency obligations: The system presents a disclosure banner at first use: 'ContractCheck uses AI to analyse your contracts. This is not legal advice. Always consult a qualified solicitor before signing.' This disclosure is also included in every generated report as a mandatory disclaimer. STEP 6: GDPR alignment: 6.1 YES - contracts uploaded may contain personal data of third parties (counterparty names, addresses, signatories) 6.2 DPIA completed 01/06/2025. Low-risk finding: data is processed transiently (not stored beyond session unless user saves report), no systematic monitoring of individuals, third-party data is incidental to the contract analysis purpose. 6.3 Lawful basis: Contract performance (user has contracted with LegalEdge for the service); Legitimate interests for incidental processing of third-party personal data in uploaded contracts.
EU AI Act Implementation Timeline
Understanding which obligations apply when is essential for compliance planning. 2 February 2025: Prohibited AI systems prohibited. GPAI (General Purpose AI) model obligations begin for providers of GPAI models. 2 August 2025: Obligations for GPAI model providers with systemic risk apply. Codes of practice for GPAI. All newly deployed AI systems must begin compliance efforts. 2 August 2026: Full application of most provisions, including all high-risk AI system obligations. High-risk systems already on the market before this date have a 2-year grace period from this point (until August 2028) to comply if no significant changes are made. 2 August 2027: High-risk AI systems used as safety components of products under other EU product safety directives must comply. For UK organisations: The UK has not adopted the EU AI Act directly. The UK government is taking a sector-led, proportionate approach via the AI Safety Institute and existing sector regulators (FCA, ICO, CMA). However, UK organisations selling into the EU market are subject to the EU AI Act for those deployments. UK organisations with GDPR compliance obligations via UK GDPR should also align AI practices with ICO AI guidance.
How SpeedMVPs Builds EU AI Act Compliance In By Default
Every AI system SpeedMVPs builds includes the following by default, at no additional cost: self-referencing transparency disclosures for conversational AI interfaces, human oversight hook points documented in the codebase, structured logging for post-market monitoring, data processing documentation for GDPR compliance, and risk classification review as part of the technical scoping process. For clients building systems that may fall under high-risk classification, we provide a paid EU AI Act compliance sprint that produces: a completed risk assessment document, a gap analysis against Article 9-15 obligations, a technical documentation pack meeting Annex IV requirements, and a conformity assessment preparation checklist. We also work with partner legal firms specialising in EU AI Act compliance for the legal opinion components that require qualified legal counsel.