Home / Risk classification

How the Act classifies your system

The classification isn't a verdict — it's a filter over the obligations graph. A system can carry more than one class: a high-risk system with a chatbot layer also owes Art. 50 transparency. GPAI classification stacks independently at the model level.

The decision path

0
Is it an "AI system" at all?
Machine-based, operates with autonomy, infers from inputs to generate outputs influencing environments (Art. 3(1)). If not — out of scope, though GPAI model rules may still apply upstream.
OUT OF SCOPE if no Art. 3(1)
1
Does it match a prohibited practice?
Social scoring, manipulation exploiting vulnerabilities, untargeted face scraping, real-time remote biometric ID in public — plus, from Dec 2, 2026, NCII/CSAM generation. If yes: it cannot be placed or used. Stop.
PROHIBITED Art. 5 · in force (+Dec 2026)
2
Is it a general-purpose AI model?
Trained at scale, significant generality, wide task range. ≥10²⁵ FLOP or Commission-designated → systemic-risk tier. Stacks independently with the system-level classes below.
GPAI / GPAI-SYSTEMIC Art. 3(63), 51–55 · in force
3
Is it high-risk?
Safety component in an Annex I product needing third-party assessment → high-risk (Annex I, Aug 2028). In an Annex III area and not exempt under Art. 6(3) → high-risk (Annex III, Dec 2027).
HIGH-RISK Art. 6 + Annexes I, III
4
Does it face people or generate content?
Chatbots, generative output, deepfakes, emotion recognition, biometric categorisation — Art. 50 transparency duties stack on top of any class above. Otherwise: minimal risk, voluntary codes only.
+ TRANSPARENCY / MINIMAL Art. 50 · Aug 2, 2026
Exempt ≠ exempt from everything. A system self-assessed out of high-risk under Art. 6(3) still needs (lighter) EU-database registration — the Omnibus reinstated this. Profiling of natural persons always stays high-risk. Verified 2026-07-16