Risk Classification Wizard - Classify AI Systems by Risk Tier
The Risk Classification Wizard guides you through a structured, seven-step process to determine the risk tier of an AI system under the EU AI Act. The classification result determines which compliance obligations apply to the system. This wizard implements the logic of Articles 5, 6 and 50 and Annexes I and III of Regulation (EU) 2024/1689 in an interactive questionnaire format. Every question includes explanatory text drawn directly from the regulation to help you make accurate classifications.
Launching the Wizard
The first step asks you to select the AI system you want to classify. If you launched the wizard from an AI system's detail page, the system is pre-selected. Otherwise, choose from a dropdown of all AI systems in your inventory that have a status of Draft or Active. Systems already classified will show their current classification with an option to reclassify. Retired systems cannot be classified.
The system selection step also displays a summary of the selected system's key attributes (name, description, intended purpose, role type, and environment) so you have the relevant context before answering classification questions. Review this information carefully - the accuracy of your classification depends on having a clear understanding of what the system does.
This critical step screens the AI system against the eight categories of prohibited AI practices defined in Art. 5 of the EU AI Act. You must answer each question honestly and accurately. If any question is answered "Yes", the system will be classified as Unacceptable Risk and the wizard will proceed directly to the results step with a recommendation to discontinue the system.
The eight screening questions are:
| # | Prohibited Practice | Question | Art. 5 Reference |
|---|---|---|---|
| 1 | Subliminal Manipulation | Does this AI system deploy subliminal techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting the behaviour of a person or group in a manner that causes or is reasonably likely to cause significant harm? | Art. 5(1)(a) |
| 2 | Vulnerable Exploitation | Does this AI system exploit any vulnerabilities of a specific group of persons due to their age, disability, or a specific social or economic situation, with the objective or effect of materially distorting their behaviour in a manner that causes or is reasonably likely to cause significant harm? | Art. 5(1)(b) |
| 3 | Social Scoring by Public Authorities | Is this AI system used by or on behalf of public authorities for the evaluation or classification of natural persons based on their social behaviour or known/predicted personal or personality characteristics, where the social score leads to detrimental or unfavourable treatment that is unjustified or disproportionate? | Art. 5(1)(c) |
| 4 | Real-Time Remote Biometric Identification | Is this AI system used for real-time remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement, except in narrowly defined exceptions (search for victims, prevention of imminent threat, identification of suspects of serious criminal offences)? | Art. 5(1)(d) |
| 5 | Public Authority Social Scoring | Does this AI system evaluate or classify natural persons or groups based on their social behaviour or known, inferred, or predicted personal or personality characteristics, where the resulting social score leads to detrimental treatment in social contexts unrelated to the context in which the data was originally generated or collected, or treatment that is unjustified or disproportionate to their social behaviour or its gravity? | Art. 5(1)(c)(i)-(ii) |
| 6 | Untargeted Facial Recognition Scraping | Does this AI system create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage? | Art. 5(1)(e) |
| 7 | Workplace/Education Emotion Inference | Does this AI system infer emotions of natural persons in the areas of workplace or education institutions, except where the AI system is intended to be put into service or placed on the market for medical or safety reasons? | Art. 5(1)(f) |
| 8 | Biometric Categorisation (Sensitive Attributes) | Does this AI system categorise natural persons individually based on their biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation? (Exception: labelling or filtering of lawfully acquired biometric datasets in the area of law enforcement.) | Art. 5(1)(g) |
An AI system is high-risk when both of these hold: it is a product, or a safety component of a product, covered by the Union harmonisation legislation listed in Annex I (for example machinery, toys, medical devices, in vitro diagnostics, radio equipment, lifts, civil aviation and motor vehicles), and that product has to undergo a third-party conformity assessment under that legislation. The second question only appears once the first is answered Yes.
A system that is high-risk through Annex I skips the Annex III and Article 6(3) steps: the derogation in Article 6(3) applies to Annex III systems only.
If Step 3 did not already make the system high-risk, the wizard proceeds to assess whether the AI system falls into one of the high-risk categories defined in Annex III of the EU AI Act. You are presented with eight category groups, each containing specific use cases. Select all categories that apply to your AI system:
| Category | Description & Examples | Annex III Ref |
|---|---|---|
| Biometric Identification & Categorisation | Remote biometric identification, categorisation by sensitive attributes, emotion recognition. Examples: facial recognition access control, biometric onboarding, voice ID. | Annex III, §1 |
| Critical Infrastructure | Safety components of critical digital/physical infrastructure. Examples: water treatment AI, electricity grid management, traffic systems. | Annex III, §2 |
| Education & Vocational Training | Admission, assignment, learning evaluation, exam monitoring. Examples: automated essay grading, admission screening, exam proctoring. | Annex III, §3 |
| Employment & Workers Management | Recruitment, CV screening, performance monitoring, promotion/termination decisions. Examples: automated CV screening, AI performance reviews. | Annex III, §4 |
| Essential Private & Public Services | Credit scoring, insurance risk pricing, emergency call classification, public benefits eligibility. Examples: credit models, triage systems. | Annex III, §5 |
| Law Enforcement | Risk profiling, polygraphs, evidence evaluation, predictive policing, crime analytics. Examples: recidivism prediction, suspect profiling. | Annex III, §6 |
| Migration, Asylum & Border Control | Immigration polygraphs, migrant risk assessment, asylum examination, border surveillance. Examples: document verification, asylum analysis. | Annex III, §7 |
| Administration of Justice & Democratic Processes | Judicial research, law application, election influence. Examples: legal research AI, sentencing tools, campaign targeting. | Annex III, §8 |
If one or more categories are selected, the system is provisionally classified as High Risk, subject to the Article 6(3) test in Step 5. If none is selected, the wizard goes straight to the transparency step.
An Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, which the Act ties to any one of four conditions being met. The step first asks whether the system performs profiling of natural persons: if it does, it stays high-risk whatever else is true, and the conditions are not asked. Otherwise the four conditions are:
| Condition | What it means |
|---|---|
| (a) Narrow procedural task | A routine, well-defined operation with limited discretion, for example turning unstructured data into structured data or classifying incoming documents. |
| (b) Improves a completed human activity | It refines the result of work a person has already done, for example improving the language of a drafted document. |
| (c) Detects patterns without replacing review | It flags decision-making patterns or deviations from prior patterns, and is not meant to replace or influence the previously completed human assessment without proper human review. |
| (d) Preparatory task | It performs a task preparatory to an assessment relevant to an Annex III use case, for example file handling or translation ahead of a human decision. |
Four questions cover the Article 50 duties: a system that interacts directly with people (for example a chatbot), one that generates synthetic audio, image, video or text, emotion recognition or biometric categorisation, and deep fakes or AI-generated text published on matters of public interest. These duties are not a separate tier. They make an otherwise minimal system Limited, and they apply on top of High Risk as well; the result lists them either way.
The result shows the risk tier, the rationale naming the articles that decided it, any transparency duties, and, for a derogated system, the Article 6(4) and 49(2) duties. The classification is saved to the system record, visible on its detail page and on the dashboard risk distribution, together with the answers and the version of the classification rules that produced it.
Classification Logic Summary
The wizard follows the order of the Act:
- If any Article 5 prohibited practice applies → Unacceptable Risk
- Else if the system is an Annex I product or safety component that needs third-party conformity assessment → High Risk (Article 6(1))
- Else if an Annex III area applies and the system profiles natural persons → High Risk
- Else if an Annex III area applies and none of conditions (a) to (d) is met → High Risk (Article 6(2))
- Else if an Annex III area applies and one of (a) to (d) is met → not high-risk: Limited with Article 50 duties, otherwise Minimal, plus the Article 6(4) and 49(2) duties
- Else if any Article 50 duty applies → Limited Risk
- Else → Minimal Risk
Regulatory documents generated from the system record
Once a system is classified, its detail page offers the documents the classification calls for, built from what the platform already holds: the system record, its datasets, oversight measures, monitoring plans, the FRIA, the conformity assessment and your company profile.
| Document | When | What is filled in |
|---|---|---|
| Technical documentation (Annex IV) | High Risk | All nine Annex IV sections; intended purpose, provider and version, datasets with provenance and bias status, oversight measures, risk and FRIA findings, monitoring plans. |
| EU declaration of conformity (Annex V) | High Risk | All eight Annex V items; identification, provider name and address, the responsibility and conformity statements, the personal data statement, the notified body where one is recorded. |
| Article 6(4) assessment | Annex III system taken out of high-risk | The area, the conditions met, the profiling answer, the reasoning and the obligations that follow. |