EU-AI-Act-Classification-step-by-step-guide

How to Classify Your AI System Under the EU AI Act (Guide)

EU AI Act Risk Classification Step-by-Step

How Do I Classify My AI System Under the EU AI Act? (Step-by-Step)

Karan’s team spent three weeks building an AI feature that flags “prohibited behaviour” during online exams for an EdTech client in Spain. When it came time to launch, their compliance advisor asked one question that stalled the whole release: “Have you classified this under the EU AI Act?” Karan didn’t even know classification was a formal, documented step — he assumed “we’re not doing anything scary” was enough.

It isn’t. The EU AI Act does not ask you whether your AI system feels risky. It asks you to run a specific, structured test — and to write down the answer. This article walks through that test step by step, so you can classify your own AI system with confidence, without guessing and without a law degree.

EU AI Act Compliance at a Glance

  • Classification is a formal, documented exercise — not a gut feeling (Art. 6(4)).
  • Start with Article 5 (is it banned outright?), then Annex I (regulated products), then Annex III (the sector-based high-risk list).
  • Even an Annex III match can be exempted if it performs only a narrow, human-reviewed task — but you must document why (Art. 6(3)).
  • Profiling of natural persons is always high-risk, with no narrow-task exemption available (Art. 6(3), final subparagraph).
  • If nothing above applies, check Article 50 for transparency duties (chatbots, AI-generated content).
  • Re-run this test every time you ship a new AI feature or materially change an existing one.

Why This Problem Matters

Risk classification is the foundation everything else in the Regulation is built on. Your risk tier determines whether you need a full conformity assessment, technical documentation, and human oversight design (high-risk), a simple disclosure (limited-risk), or effectively nothing further (minimal-risk). Get the classification wrong, and everything downstream — your documentation, your vendor answers, your investor due-diligence responses — is built on a mistaken foundation.

This is not a hypothetical risk. Article 6(4) explicitly requires providers who conclude an Annex III-listed system is not high-risk to document that assessment before placing it on the market (European Union, 2024, Art. 6(4)). An undocumented judgment call offers no protection if a regulator, customer, or investor later disagrees with your conclusion. And the stakes are real: Article 99 sets fines of up to €15 million or 3% of global turnover for most substantive breaches of the Regulation (European Union, 2024, Art. 99).

Before running this test, make sure you’ve already confirmed the Regulation applies to you at all — see our guide, Does the EU AI Act Apply to My Company If I’m Not Based in Europe?

Who Is Affected

This step-by-step guide is for you if:

  • You’re about to ship a new AI feature and need to know what obligations attach to it.
  • You have existing AI features you’ve never formally classified.
  • You use a third-party GPAI model and aren’t sure how that affects your classification (see our companion article on ChatGPT integration compliance).
  • A customer, investor, or partner has asked for your risk classification and you don’t have a documented answer.

What Happens If You Skip Formal Classification

  • You can’t answer procurement or due-diligence questions with confidence, which stalls deals.
  • You risk applying the wrong obligation level — either under-complying (legal exposure) or over-engineering compliance for a low-risk feature.
  • You lose the benefit of available exemptions, because Article 6(3)’s narrow-task exemptions require documentation to actually apply (European Union, 2024, Art. 6(4)).

Step 1: Check Article 5 — Is Your AI System Prohibited Outright?

Before anything else, rule out the small set of AI practices banned entirely. Article 5 prohibits practices including certain manipulative or deceptive techniques that materially distort behaviour causing harm, exploitation of vulnerabilities, certain social scoring by public authorities, and specific uses of real-time remote biometric identification in publicly accessible spaces for law enforcement, among others (European Union, 2024, Art. 5). For the vast majority of ordinary SaaS and business-software features, this step ends quickly with “not applicable” — but it must be checked first, because no documentation or exemption can rescue a prohibited practice.

Official Resource: Regulation (EU) 2024/1689, Article 5 (Prohibited AI Practices) — EUR-Lex

Step 2: Check Annex I — Is Your AI System a Safety Component of a Regulated Product?

An AI system is automatically high-risk if it is used as a safety component of a product covered by specific EU product-safety legislation listed in Annex I (things like machinery, toys, medical devices, lifts), and that product requires third-party conformity assessment under that legislation (European Union, 2024, Art. 6(1)). Most SaaS and business-software companies will find this step doesn’t apply — it mainly catches embedded AI in physical, regulated products.

Step 3: Check Annex III — Does Your AI System Fall Into a High-Risk Use-Case Category?

This is the step that catches most SaaS features. Annex III lists specific high-risk areas (European Union, 2024, Art. 6(2); Annex III):

Annex III CategoryExamples Relevant to SaaS/Business Software
1. BiometricsRemote biometric identification, biometric categorisation, emotion recognition
2. Critical infrastructureSafety components managing digital infrastructure, water, gas, electricity, road traffic
3. Education & vocational trainingAdmission/access decisions, evaluating learning outcomes, detecting prohibited exam behaviour
4. Employment & workers managementRecruitment/selection tools, performance evaluation, task allocation, promotion/termination decisions
5. Access to essential servicesCredit scoring, insurance risk assessment, eligibility for public benefits
6. Law enforcementRisk assessment tools, evidence evaluation (narrow, specialized use cases)
7. Migration, asylum, border controlRisk assessment, examination of applications
8. Administration of justice & democratic processesAssisting judicial research/interpretation, influencing elections

If your feature matches any category — even loosely — proceed to Step 4. Karan’s exam-monitoring feature is a direct match to category 3(d): “monitoring and detecting prohibited behaviour of students during tests” (European Union, 2024, Annex III, point 3(d)).

Official Resource: Regulation (EU) 2024/1689, Annex III (full list of high-risk use cases) — EUR-Lex

Step 4: Apply the Narrow-Task Exemptions — Does Article 6(3) Take You Back Out?

Matching an Annex III category isn’t automatically the end of the story. Article 6(3) allows you to determine that your specific system does not pose a significant risk of harm — including by not materially influencing the outcome of decision-making — if any of these apply (European Union, 2024, Art. 6(3)):

(a) the AI system performs only a narrow procedural task; (b) the AI system improves the result of a previously completed human activity; (c) the AI system detects decision-making patterns or deviations without replacing or influencing the prior human assessment, without proper human review; or (d) the AI system performs a preparatory task to an assessment relevant to an Annex III use case.

Critical exception: none of these exemptions apply if the AI system performs profiling of natural persons — that always remains high-risk, no matter how narrow the task seems (European Union, 2024, Art. 6(3), final subparagraph).

If you conclude an exemption applies, you are not finished — Article 6(4) requires you to document that assessment before the system is placed on the market, and you become subject to a registration obligation under Article 49(2) (European Union, 2024, Art. 6(4)).

Official Resource: Regulation (EU) 2024/1689, Article 6(3)–(4) — EUR-Lex

Mini Case Study: An EdTech Feature Works Through the Full Test

Consider a scenario : an EdTech SaaS company builds a feature that flags unusual behaviour patterns during online exams — pausing, tab-switching, unusual typing cadence — for a human proctor to review. Running the test: Step 1 (Article 5) — not a prohibited practice. Step 2 (Annex I) — not a regulated product safety component. Step 3 (Annex III) — a direct match to category 3(d), monitoring prohibited behaviour during tests. Step 4 (Article 6(3)) — the team considers exemption (c), since the system detects deviations from expected patterns without replacing the human proctor’s final decision, and no proper decision is taken without human review.

Because the system does not perform profiling of individual students beyond flagging the specific test session, the team documents this reasoning and treats the feature as exempt from high-risk status — while noting that if the feature were ever changed to auto-fail students without human review, the classification would need to be redone. This is illustrative of how the same underlying feature can land differently based on design choices; your own classification should be documented and verified against the official Regulation text.

Step 5: If Not High-Risk, Check Article 50 — Transparency Obligations

If your AI system clears Steps 1–4 without landing in high-risk territory, check whether it still triggers transparency duties under Article 50 — most commonly relevant for chatbots and AI-generated content. You must generally disclose that a person is interacting with an AI system, or that content is AI-generated, unless this is obvious from the context (European Union, 2024, Art. 50).

Step 6: If None of the Above Apply, You’re Likely Minimal-Risk

Most everyday SaaS features — internal analytics, spam filtering, basic recommendation engines, simple automation — will land here. The Regulation does not impose specific obligations on minimal-risk AI systems, though voluntary codes of conduct are encouraged (European Union, 2024, Recital 5-6 area; general minimal-risk framing). Even here, it’s good practice to keep a short written note of why you reached this conclusion.

Official Resource: European Commission — AI Act FAQs — digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act

AspirixWriters Framework: The Six-Gate Classification Ladder

We built the Six-Gate Classification Ladder to turn the scattered provisions above into one linear, repeatable process any product team can run without legal training:

  1. Gate 1 — Prohibited? (Art. 5) → Stop if yes.
  2. Gate 2 — Regulated product safety component? (Annex I) → High-risk if yes.
  3. Gate 3 — Annex III match? → Proceed to Gate 4 if yes; otherwise skip to Gate 5.
  4. Gate 4 — Narrow-task exemption available and no profiling involved? (Art. 6(3)) → Document and exit if yes; otherwise high-risk.
  5. Gate 5 — Transparency trigger? (Art. 50) → Disclose if yes.
  6. Gate 6 — None of the above? → Minimal-risk; document briefly and move on.

This is AspirixWriters analysis and original methodology, not an official EU AI Act requirement — it is a practical operating model for applying Articles 5, 6, 50, and Annexes I and III in sequence.

Startup Approach vs. Enterprise Approach to Classification

Small StartupEnterprise
Runs the Six-Gate Ladder manually per feature at release timeUses a formal AI governance platform or classification tool across many systems
One-page documented reasoning per featureMulti-page classification reports reviewed by legal and compliance teams
Re-classifies when a feature changes materiallyContinuous classification review as part of change management processes
Founder or product lead makes the final callCross-functional risk committee makes the final call
Uses Art. 6(3) exemptions where genuinely applicableOften builds systems too complex for narrow-task exemptions to apply

Common Mistakes Teams Make When Classifying AI Systems

  • Skipping straight to “is this high-risk?” without checking Article 5 first. Prohibited practices aren’t rescued by any exemption.
  • Assuming an Annex III match automatically means heavy obligations with no way out. Article 6(3) genuinely can apply — but only if documented.
  • Missing the profiling override. Teams sometimes claim a narrow-task exemption for a system that profiles individuals, which is never allowed under Art. 6(3)’s final subparagraph.
  • Classifying once and never revisiting. A feature that starts as “human reviews every output” can silently become high-risk the moment automation increases.

Checklist: Have I Properly Classified My AI System?

Initial Screening

  • [ ] I have checked whether my system matches any Article 5 prohibited practice.
  • [ ] I have checked whether my system is a safety component of an Annex I regulated product.
  • [ ] I have checked my system against all eight Annex III categories.

Exemption Analysis

  • [ ] If I matched Annex III, I have assessed whether an Art. 6(3) narrow-task exemption genuinely applies.
  • [ ] I have confirmed my system does not perform profiling of natural persons before relying on any exemption.
  • [ ] I have written documentation of my classification reasoning, dated before market release.

Ongoing Governance

  • [ ] I have checked Article 50 transparency triggers if not high-risk.
  • [ ] I have a process to re-run this classification when the feature changes materially.
  • [ ] I have named one internal owner for classification decisions.
  • [ ] I check EUR-Lex or the European Commission’s AI Act page quarterly for updates.
EU AI Act Risk Classification Step-by-Step Guide

FAQs

Do I really need to write down my classification, or is a mental note enough?

Write it down. Article 6(4) requires documented reasoning for any Annex III system you conclude is not high-risk — an undocumented judgment call provides no legal protection.

What if my feature matches more than one Annex III category?

Document your reasoning against each matching category separately; the exemption analysis in Article 6(3) applies system-by-system, not just once overall.

Can a feature change risk tier over time without me changing any code?

Yes — if you change how the feature is used (for example, removing human review), its risk classification can change even without a code change. Re-run the test whenever usage changes materially.

Does using a third-party GPAI model affect this classification process?

The classification steps above apply to your own AI system regardless of which model powers it — see our companion article on ChatGPT integration compliance for how GPAI use layers on top of this.

Key Takeaways

  • Classification is a documented, step-by-step legal exercise, not an instinct call (Art. 6(4)).
  • Run the test in order: Article 5 (prohibited) → Annex I (regulated products) → Annex III (sector-based high-risk list) → Article 6(3) exemptions → Article 50 (transparency) → minimal-risk.
  • Annex III matches are not automatically high-risk if a genuine narrow-task exemption applies — but you must document your reasoning.
  • Profiling of natural persons always overrides the narrow-task exemptions.
  • Re-classify whenever a feature’s design or usage changes materially, not just when it’s first built.

Conclusion

Karan’s team wasn’t careless — they simply didn’t know classification was a formal, written step rather than a feeling. Once they ran the Six-Gate Ladder against their exam-monitoring feature, the answer became clear, defensible, and fast to produce for their next customer questionnaire. Classification isn’t the hardest part of EU AI Act compliance — it’s the part that, done properly and documented once, makes everything that follows dramatically easier.

This article is for general informational purposes and does not constitute legal advice. Founders should consult their qualified legal counsel for advice specific to their AI system and market exposure.

About the Author

Dr. Rekha Khandelwal is the Founder of AspirixWriters and a legal researcher and writer specializing in AI Governance, AI Regulation, AI Compliance, AI Ethics, and Responsible AI. Her work focuses on translating complex legal and technical frameworks — including the EU AI Act — into practical guidance for businesses, professionals, researchers, and students navigating the global AI governance landscape.

Explore more AspirixWriters

Official Sources: EUR-Lex — Regulation (EU) 2024/1689, European Commission — Regulatory Framework for AI, European Commission — AI Act FAQs

Scroll to Top