EU AI Act · Compliance tooling

EU AI Act Risk Assessment — Is Your AI System High-Risk?

Everything in the EU AI Act flows from one question: which risk tier is your AI system in? Prohibited, high-risk, limited-risk, or minimal-risk. Getting the classification wrong — especially under-calling high-risk — is the most expensive mistake you can make. Here is how to assess your tier, and how to verify it with a scan.

The four tiers at a glance

Prohibited: practices banned outright — social scoring, manipulative deception, real-time public biometric identification, and the 2026 additions for non-consensual intimate imagery and CSAM. High-risk: AI in critical infrastructure, education, employment, essential services, law enforcement, migration and other Annex III areas, or AI that is a safety component of regulated products. Limited-risk: transparency duties only, e.g. chatbots and deepfakes. Minimal-risk: the rest — no mandatory obligations.

How to tell if you are high-risk

Ask two questions. First: does your system fall under Annex I (a safety component of, or itself, a regulated product)? Second: does it fall under Annex III (a listed sensitive use, e.g. credit scoring, CV screening, biometric identification, education scoring)? If either is yes, you are high-risk unless an exception applies — and the burden of proving an exception sits with you.

Verify your tier with evidence

A spreadsheet guess is not evidence. Scan the codebase so the classification is backed by the actual system: what risk-management hooks exist, what data feeds the model, what automated decisions it makes, and how outputs are logged and overridden.

Free EU AI Act Compliance Scan

See your score in 2 minutes. No signup, no code stored.

Scan Your Codebase Now

Frequently Asked Questions

Can a tool classify my tier?

A scanner gives you an evidence-backed initial classification based on your code, config and use-case patterns. Final classification for regulated products still needs professional sign-off.

Is limited-risk really safe?

Limited-risk means transparency duties — and chatbot disclosure and deepfake labelling are enforceable now, so 'not high-risk' is not 'no obligations'.

When do high-risk rules apply?

Under the 2026 omnibus, Annex III high-risk systems face obligations from December 2027 (Annex I products from August 2028). That gap is your runway to comply.