Risk classification is the foundational gatekeeping mechanism of the EU AI Act. Article 6 requires providers to determine whether an AI system is high-risk before market placement or putting into service. This classification directly determines the applicable obligations - including the mandatory Quality Management System (Article 17), risk management system (Article 9), technical documentation (Annex IV), conformity assessment (Article 43), and post-market monitoring (Article 72). This article articulates the risk classification requirement, its purpose, the classification process, inclusions and exclusions, and the link to prEN 18286, from regulatory, operational, practical, and strategic perspectives.
Purpose of Risk Classification under the EU AI Act
The EU AI Act adopts a horizontal, risk-based approach rather than blanket rules or sector-specific regulation alone. The primary purposes of risk classification are:
- Proportionality: Tailor regulatory burden to the severity of potential harm - minimal obligations for low-risk systems, stringent requirements for high-risk ones.
- Preventive Protection: Ensure systems that could significantly affect health, safety, or fundamental rights are subject to lifecycle controls before deployment.
- Legal Certainty & Predictability: Provide clear, objective criteria so providers can determine obligations in advance and authorities can enforce consistently.
- Enabling Innovation with Trust: Light-touch rules for most AI uses while imposing safeguards where risks are highest - balancing competitiveness with rights protection.
Incorrect or undocumented classification carries significant risk: authorities may re-classify a system as high-risk during market surveillance, triggering retroactive obligations and potential fines (up to €35 million or 7% global turnover).
The Classification Process: Step-by-Step Application
Article 6 defines a two-step process for determining whether an AI system is high-risk:
Step 1 - Annex III Check
Determine whether the AI system falls within one of the eight high-risk areas listed in Annex III (as amended by delegated acts):
- Biometric identification/verification (point 1)
- Critical infrastructure management (point 2)
- Education & vocational training (point 3)
- Employment, workers management & access to self-employment (point 4)
- Access to essential private & public services & benefits (point 5)
- Law enforcement (point 6)
- Migration, asylum & border control (point 7)
- Administration of justice & democratic processes (point 8)
Step 2 - Significant Risk Filter
Even if listed in Annex III, the system is not high-risk if it is:
- purely preparatory (e.g., AI improving database search without decision-making impact);
- intended to improve previous human activities without replacing or influencing them significantly;
- subject to human oversight with effective ability to override or correct;
- explicitly excluded by delegated acts or implementing acts (expected clarifications).
Practical example: An AI tool that ranks CVs for recruiters (Annex III point 4) is high-risk because it significantly influences access to employment. However, an internal AI chatbot that merely suggests interview questions (no decision-making power) may fall outside if human recruiters retain full control and override capability.
Inclusions and Exclusions: Scope and Boundaries
Inclusions (presumptively high-risk):
- Any AI system listed in Annex III that performs profiling, scoring, prediction, classification, recommendation, or decision support that significantly affects natural persons in the listed domains.
- AI systems that replace or augment human decision-making with limited or no effective human override.
- Systems used in sensitive contexts (biometrics, law enforcement, migration) even if accuracy is high - due to potential for systemic harm or rights infringement.
Exclusions (not high-risk):
- Minimal-risk AI (vast majority of current uses - e.g., spam filters, chatbots without decision impact).
- Limited-risk AI (transparency obligations only - e.g., deepfakes, emotion recognition, generative AI with disclosure duties).
- Prohibited AI (Article 5 - banned outright, e.g., social scoring, real-time remote biometric ID in public spaces except narrow exceptions).
- Systems explicitly carved out by the significant-risk filter (Step 2) or future delegated acts.
Edge case: General-purpose AI models (Chapter V) are not automatically high-risk unless placed on the market or put into service as part of a high-risk system (then downstream provider bears obligations). Providers must document exclusion reasoning for audit.
Link to prEN 18286: How Classification Drives QMS Requirements
prEN 18286 is explicitly scoped to providers of high-risk AI systems - it does not apply to minimal-, limited-, or prohibited-risk systems. The standard's product- and lifecycle-centric framework (Clauses 6-8) assumes the system has already been classified as high-risk. Key linkages include:
- QMS Scope: Only high-risk systems require the full Article 17 QMS (13 elements); classification decision must be documented in the QMS compliance strategy (Clause 5).
- Risk Management Integration: The RMS (Article 9) is calibrated to the high-risk classification - higher scrutiny and documentation for Annex III systems.
- Conformity Assessment: Classification determines the applicable route (Annex VI internal control vs. Annex VII notified-body assessment); prEN 18286 alignment provides presumption only for high-risk QMS.
- Documentation Obligation: Providers must maintain a documented classification rationale (rationale, evidence, date, responsible person) as part of technical documentation and QMS records.
Example: A provider classifies an AI credit-scoring tool as high-risk (Annex III point 5). This classification triggers full prEN 18286 QMS implementation (risk management, post-market monitoring, audit programme), while a low-risk internal analytics tool requires only transparency or no obligations - illustrating how classification directly gates regulatory burden.
Integration, Nuances, and Strategic Implications
Risk classification integrates with the QMS (Article 17) and technical documentation (Annex IV) as the first compliance step; incorrect classification invalidates downstream conformity assessment. Nuances: Proportionality for SMEs (simpler documentation of classification); delegated acts may refine Annex III or add exclusions; deployers must verify provider classification and may face obligations if they substantially modify systems (Article 25).
Strategic implications: Accurate, well-documented classification minimises regulatory burden, avoids retroactive obligations, and enables focused resource allocation. Misclassification risks market exclusion, fines, and reputational damage. Best practice: Conduct classification early, document rationale with legal/regulatory input, review periodically (new delegated acts, system changes), and align with prEN 18286 draft for future-proofing.
In essence
Risk classification under the EU AI Act serves as the gateway that determines whether - and to what extent - the full suite of regulatory safeguards (including the prEN 18286 QMS) must be applied. Correctly executed, it achieves the Act's core goal: proportionate protection of health, safety, and fundamental rights while enabling innovation in low-risk domains.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 6-7, Annex III, and prEN 18286 draft status and publicly available analyses as of March 10, 2026. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions become fully applicable on 2 August 2026.