AI Risk Classification
Classify AI systems into the correct EU AI Act risk tier.
What Is AI Risk Classification?
The EU AI Act sorts systems into four tiers, and the tier decides the obligations. Get the classification wrong and you either ship something banned or spend months on compliance a minimal-risk tool never needed. You'll classify real use cases across the tiers, working out which are prohibited outright, which are high-risk and carry strict duties, which need only transparency, and which can operate freely.
What You'll Learn in AI Risk Classification
- Identify the four risk tiers defined by the EU AI Act
- Classify AI systems into the correct risk tier based on their function and impact
- Recognize prohibited AI practices under Article 5
- Understand Annex III high-risk categories including employment and creditworthiness
- Distinguish between Limited Risk transparency obligations and High Risk compliance requirements
AI Risk Classification — Training Steps
-
The Four Risk Tiers
The EU AI Act classifies every AI system into one of four risk tiers, and the classification determines everything that follows: Unacceptable Risk (Banned) - AI practices that are prohibited outright. These systems cannot be deployed in the EU under any circumstances. High Risk - AI systems in sensitive areas like employment, credit scoring, and law enforcement. Permitted, but subject to strict compliance obligations. Limited Risk - AI systems that interact with people. The main obligation is transparency - users must know they are dealing with AI. Minimal Risk - The vast majority of AI systems. No specific obligations under the Act.
-
Email from the CCO
An email arrives from the Chief Compliance Officer with an urgent classification assignment.
-
Open the Assessment Portal
Alice clicks the link in the email to open the Velox GRC Portal where the six AI systems are waiting for classification.
-
Review the Risk Tier Reference
The portal landing page summarizes the four risk tiers Alice will use to classify each AI system. Each tier carries different compliance obligations - getting the classification right determines what work follows.
-
Start the Assessment
To begin classifying, Alice needs to sign in to the GRC portal with her Velox credentials.
-
Sign In to the GRC Portal
Alice signs in with her corporate credentials. After authentication, the portal will load the six AI systems queued for classification.
-
Case 1: Email Spam Filter
The first AI system to classify is an email spam filter. It uses machine learning to detect and filter spam based on content patterns and sender reputation.
-
Case 2: Resume Screening Tool
The next system scores and ranks job applicants' resumes, automatically filtering out candidates before a human ever reviews them.
-
Case 3: Employee Productivity Scorer
This system monitors keystrokes, mouse movements, and break frequency to produce a 0-100 productivity score for each employee. Scores are shared with department heads quarterly and influence performance reviews.
-
Why the Productivity Scorer Is Banned
The Employee Productivity Scorer is one of those systems that sounds like a reasonable management tool but crosses a legal line under the EU AI Act.
Security Framework Coverage
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
EU AI Act
- Art. 6 Classification rules for high-risk AI systems
- Annex III High-risk AI systems referred to in Article 6(2)