Purpose, Process, Inclusions, Exclusions, and Link to EN 18286
Risk classification is the foundational gatekeeping mechanism of the EU AI Act. Article 6 requires providers to determine whether an AI system is high-risk before market placement or putting into service. This classification directly determines the applicable obligations - including the mandatory Quality Management System (Article 17), risk management system (Article 9), technical documentation (Annex IV), conformity assessment (Article 43), and post-market monitoring (Article 72). This article articulates the risk classification requirement, its purpose, the classification process, inclusions and exclusions, and the link to EN 18286, from regulatory, operational, practical, and strategic perspectives.
The EU AI Act adopts a horizontal, risk-based approach rather than blanket rules or sector-specific regulation alone. The primary purposes of risk classification are:
Incorrect or undocumented classification carries significant risk: authorities may re-classify a system as high-risk during market surveillance, triggering retroactive obligations and potential fines (up to €35 million or 7% global turnover).
Article 6 defines a two-step process for determining whether an AI system is high-risk:
Practical example: An AI tool that ranks CVs for recruiters (Annex III point 4) is high-risk because it significantly influences access to employment. However, an internal AI chatbot that merely suggests interview questions (no decision-making power) may fall outside if human recruiters retain full control and override capability.
Inclusions (presumptively high-risk):
Exclusions (not high-risk):
Edge case: General-purpose AI models (Chapter V) are not automatically high-risk unless placed on the market or put into service as part of a high-risk system (then downstream provider bears obligations). Providers must document exclusion reasoning for audit.
EN 18286 is explicitly scoped to providers of high-risk AI systems - it does not apply to minimal-, limited-, or prohibited-risk systems. The standard's product- and lifecycle-centric framework (Clauses 6-8) assumes the system has already been classified as high-risk. Key linkages include:
Example: A provider classifies an AI credit-scoring tool as high-risk (Annex III point 5). This classification triggers full EN 18286 QMS implementation (risk management, post-market monitoring, audit programme), while a low-risk internal analytics tool requires only transparency or no obligations - illustrating how classification directly gates regulatory burden.
Risk classification integrates with the QMS (Article 17) and technical documentation (Annex IV) as the first compliance step; incorrect classification invalidates downstream conformity assessment. Nuances: Proportionality for SMEs (simpler documentation of classification); delegated acts may refine Annex III or add exclusions; deployers must verify provider classification and may face obligations if they substantially modify systems (Article 25).
Strategic implications: Accurate, well-documented classification minimises regulatory burden, avoids retroactive obligations, and enables focused resource allocation. Misclassification risks market exclusion, fines, and reputational damage. Best practice: Conduct classification early, document rationale with legal/regulatory input, review periodically (new delegated acts, system changes), and align with EN 18286 draft for future-proofing.
In essence, risk classification under the EU AI Act serves as the gateway that determines whether - and to what extent - the full suite of regulatory safeguards (including the EN 18286 QMS) must be applied. Correctly executed, it achieves the Act's core goal: proportionate protection of health, safety, and fundamental rights while enabling innovation in low-risk domains.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 6-7, Annex III, and EN 18286 draft status and publicly available analyses as of March 10, 2026. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions become fully applicable on 2 August 2026.