AI Risk Classification
Putting each use case in the right box
Sorting an AI use case into a risk tier based on the harm it could cause to people and to the organisation; the tier decides which controls, documentation and approvals are required.
The same model is a harmless writing aid in one place and a tool that decides someone's loan or job in another. Risk belongs to the use case, not the model. AI risk classification puts each use case into a tier by its potential for harm, and the tier decides the controls.
The EU AI Act (Regulation (EU) 2024/1689) sets up four layers: - Unacceptable risk (Article 5): Prohibited practices such as harmful manipulation or social scoring. Applies since 2 February 2025. - High risk (Article 6): Two routes. Safety components of products covered by the product-safety laws in Annex I, and the eight areas in Annex III: biometrics, critical infrastructure, education and vocational training, employment and workers' management, access to essential private and public services (e.g. credit scoring), law enforcement, migration/asylum/border control, and administration of justice and democratic processes. - Transparency obligations (Article 50): Chatbots, systems that generate synthetic content and similar; people must know they are dealing with AI. - Minimal risk: Spam filters, game AI; no extra obligations.
An Annex III system may fall outside high risk if it only performs a narrow procedural task or merely prepares a human decision (Article 6(3)), but it is always high-risk if it profiles natural persons. A provider relying on that exception must document its assessment (Article 6(4)).
Timeline (as of October 2026): the Digital Omnibus on AI (Regulation (EU) 2026/1744), adopted in 2026, moved the Annex III high-risk obligations to 2 December 2027 and the Annex I ones to 2 August 2028. The Article 50 transparency rules have applied since 2 August 2026.
Two complementary approaches sit next to the law. The NIST AI RMF (January 2023) is voluntary; its MAP function asks you to map the context, the affected people and the potential impacts. Most organisations turn both into internal tiers: Tier 0 (internal productivity), Tier 1 (customer-facing content), Tier 2 (supports decisions about people), Tier 3 (prohibited or needs board approval).
In practice this is an intake and triage process: every new AI idea is logged through a short form, a handful of screening questions yields its tier, and the tier automatically assigns controls such as a DPIA, a model card, bias testing and human sign-off.
Like triage in a hospital emergency room. Not everyone who walks in gets the same examination; a nurse asks a few questions and sends each person to the green, yellow or red zone. Red-zone patients get specialists, tests and continuous monitoring; green-zone patients get a prescription and leave. Skip triage and either everyone waits in the red zone and the system jams, or the real emergency slips through.
A retailer receives three AI ideas in the same week:
1. Product description assistant: The content team drafts copy; a human edits and publishes. No decisions about people. Result: Tier 0, minimal risk. Registering it is enough. 2. Customer-service chatbot: Talks to customers directly. Result: Tier 1. Under Article 50 users must be told they are talking to AI; a PII guardrail and logging are mandatory. 3. CV pre-screening tool: Scores and ranks applicants. It falls under Annex III point 4 (employment) and profiles applicants, so the Article 6(3) exception is off the table. Result: Tier 2, high risk. No launch without a bias audit, model card, human oversight, log retention and legal sign-off.
Triage took fifteen minutes; for the third idea the plan is no longer "build and ship" but "prepare the compliance pack first".
# ai-intake/2026-041-cv-screening.yaml
id: AI-2026-041
name: "CV pre-screening and ranking"
owner: "hr@company.example"
submitted: 2026-10-05
description: >
Scores incoming CVs against the job requirements and lists
the top 50 candidates for an HR specialist.
role: deployer # provider | deployer | both
model:
source: third-party-api # in-house | open-weights | third-party-api
vendor: "Example AI Ltd."
affected_people: [job_applicants]
screening:
prohibited_practice: false # Article 5 list
annex_iii_area: employment # Annex III point 4
profiling_natural_persons: true # rules out the Art. 6(3) exception
decides_about_people: true
human_review_before_effect: true
personal_data: true
special_category_data: false
external_users_interact: false
generates_synthetic_content: false
result:
tier: 2
eu_ai_act: high-risk
required_controls:
- dpia
- model_card
- bias_audit_before_launch
- human_oversight_procedure
- log_retention_6m
- legal_signoff
reviewers: [legal, dpo, ai-governance-board]- When an organisation runs several AI initiatives and nobody knows how much control each one needs
- When you ship to the EU market or produce outputs about people in the EU
- When AI touches decisions that shape people's lives: hiring, credit, insurance, education
- When buying an AI product, to decide which documents to demand from the vendor
- Treating classification as a one-off form; when the purpose changes, the tier changes
- Declaring everything high-risk and pushing every team through the heavy process; teams start routing around it
- Using the triage result as a substitute for legal advice; borderline cases go to legal
Classifying the model, forgetting the use case
There's no such thing as 'low risk because it's GPT-based'. The same model is minimal risk when summarising text and high risk when screening candidates. Fill the form per use case, not per model.
Scope creep
A tool that only summarises slowly starts 'recommending', then effectively deciding. A change of purpose should trigger re-triage, and the inventory needs a review at least once a year.
Leaning too hard on the exception
The 'narrow procedural task' exception in Article 6(3) does not apply if the system profiles people, and the assessment has to be documented. 'A human makes the final call' is not enough on its own.
Reading dates from stale sources
As of October 2026, the Annex III high-risk obligations moved to 2 December 2027 via the Digital Omnibus. Blog posts from 2024 still say 2 August 2026; check the official text. This page is informational, not legal advice.