Skip to main content

Is My AI System High-Risk? A Decision Tree

Interactive EU AI Act risk classification decision tree. Covers Article 5 prohibited practices, all 8 Annex III high-risk categories, GPAI model obligations, and Article 50 transparency.

The EU AI Act (Regulation (EU) 2024/1689) classifies AI systems into four risk levels: prohibited, high-risk, limited-risk, and minimal-risk. Each level carries different compliance obligations, from outright bans to voluntary codes of conduct.

Use this interactive decision tree to determine where your AI system falls. The classification follows the logic laid out in Articles 5, 6, 50, and 51 of the regulation, plus Annexes I and III. Answer each question based on your system's actual functionality, not its intended use alone.

Interactive Decision Tree

Step 1|0 questions answered

Does your AI system perform any practice listed under Article 5?

Article 5 prohibits social scoring, subliminal manipulation, exploitation of vulnerabilities, real-time remote biometric identification in public spaces (with limited exceptions), predictive policing based solely on profiling, untargeted scraping for facial recognition databases, emotion recognition in workplaces/schools, and biometric categorisation inferring sensitive attributes.

Understanding the Risk Classification Framework

The EU AI Act establishes a proportionate, risk-based approach to AI regulation. The higher the risk an AI system poses to fundamental rights and safety, the stricter the requirements. This framework applies to providers, deployers, importers, distributors, and authorized representatives operating in or affecting the EU market.

Prohibited (Unacceptable Risk)

AI practices that pose an unacceptable risk to fundamental rights. These are banned outright under Article 5, with fines up to EUR 35 million or 7% of global turnover. Includes social scoring, subliminal manipulation, exploitation of vulnerable groups, and certain biometric practices.

High-Risk

AI systems used in critical areas listed in Annex III (biometrics, critical infrastructure, employment, education, law enforcement, etc.) or as safety components of products under Annex I legislation. Subject to comprehensive requirements including risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, and robustness. Full compliance required from August 2026; an EU Digital Omnibus proposal (pending legislative approval) may extend this to December 2027.

Limited-Risk

AI systems that interact with natural persons, generate synthetic content, or perform emotion recognition or biometric categorisation. Subject to transparency obligations under Article 50 from August 2026: chatbots must disclose their AI nature at first interaction, synthetic content must carry machine-readable watermarks or visible labels, and emotion recognition disclosures must be provided to the person being assessed (not just the system purchaser).

Minimal-Risk

The majority of AI systems fall into this category. No mandatory requirements, but voluntary codes of conduct per Article 95 are encouraged. Examples include spam filters, AI-powered games, and inventory management systems.

Common Classification Mistakes

Classifying by intent, not capability

The regulation classifies based on what an AI system can do, not just what it is intended to do. An HR screening tool is high-risk regardless of whether the employer claims to only use it as a suggestion engine.

Ignoring the Article 6(3) exception

Not all Annex III systems are automatically high-risk. If your system only performs narrow procedural tasks, improves prior human work, or prepares assessments for human review, it may qualify for the Article 6(3) exception. But you must document this before market placement. Critical: the exception does not apply if your system performs profiling of natural persons. Even when the exception applies, registration in the EU database is still required under Article 49.

Forgetting downstream classification

A GPAI model used as a component in a high-risk system triggers high-risk obligations for the downstream provider. Classification must consider the full deployment context, not just the model in isolation.

People Also Ask

Related Guides


How Scanara Helps

Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.