How to classify an AI system under the EU AI Act
Dana Okafor · · 6 min read
The EU AI Act sorts systems into tiers. The tier decides how much work you have to do, so getting it right early saves a lot of back and forth later.
Start with what the system does
Classification is about use, not technology. A model is not high risk on its own. It becomes high risk when you point it at something the Act lists in Annex III, like screening job applicants or judging creditworthiness.
The four tiers
Prohibited uses are off the table, for example social scoring. High risk uses carry the full set of duties: risk management, data governance, logging, human oversight, and technical documentation. Limited risk mostly means transparency, so people know they are dealing with AI. Minimal risk carries no specific duties, though good practice still applies.
Write down your reasoning
Whatever tier you land on, record why. An auditor will ask. A short paragraph that points to the specific Annex III entry, or explains why none apply, is usually enough. Veydria does this step for you and keeps the reasoning next to the system.