AI Governance, Compliance & Regulation

How to assess model risks according to the EU AI Act

September 24, 2025

Accurate risk classification is the foundation of compliance with the EU AI Act. The EU AI Act imposes different obligations depending on risk level, with penalties up to €35 million or 7% of global annual turnover for non-compliance.

Understanding your risk level helps allocate compliance resources effectively, avoiding over-engineering low-risk systems or under-protecting high-risk ones.

How the EU AI Act classifies risk

The AI Act organizes AI systems into four risk categories, with requirements increasing based on potential harm. This risk-based approach means your compliance obligations depend entirely on what your AI system does and how it’s used.

Proper risk classification drives all subsequent compliance requirements and determines whether your AI system can legally operate in the EU.

EU AI Act risk categories

AI risk classification challenges

Organizations frequently encounter obstacles when classifying AI systems:

How Deeploy helps with AI risk classification

Deeploy’s risk classification assessment removes guesswork from EU AI Act compliance. Our guided questionnaire walks you through the regulatory criteria, ensuring accurate classification for your AI models.

The assessment guides you through several key questions to determine:

After completing all questions, you’ll receive a recommended risk classification. Applying this classification allows you to implement specific technical and organizational controls that address identified risks.


Frequently Asked Questions

About risk assessment for the EU AI Act

What happens if I classify my AI system incorrectly under the EU AI Act?

Incorrect classification can result in non-compliance penalties up to €35 million or 7% of global turnover. If you classify a high-risk system as minimal-risk and fail to implement required safeguards, you face both regulatory fines and potential liability for harms caused. Deeploy’s guided assessment helps prevent misclassification by systematically evaluating all regulatory criteria.

Yes. Risk classification can change if the system’s purpose evolves, new capabilities are added, or it’s deployed in different contexts. If a deployer uses AI for high-risk purposes the provider didn’t intend, the deployer becomes the provider with full compliance obligations. Deeploy enables reassessment whenever system use cases change.

Absolutely. An AI system classified as minimal-risk by its provider becomes high-risk if a deployer uses it for applications listed in Annex III of the AI Act (like employment decisions or law enforcement). In these cases, the deployer assumes provider obligations.

Deeploy implements the EU AI Act’s risk framework through a structured questionnaire based on the Algorithm Audit Implementation Tool. The assessment evaluates whether your system meets AI definitions, matches prohibited use cases, falls within high-risk application domains, or triggers specific regulatory criteria. Recommendations align with official EU guidance.

Deeploy’s assessment provides the foundational risk classification required for compliance planning. While it doesn’t replace conformity assessments for high-risk systems, it establishes the correct risk category that determines which requirements apply. The documented assessment serves as evidence of due diligence in your compliance framework.

Reassess risk classification whenever you modify the AI’s purpose, add significant functionality, deploy in new contexts, or update underlying models. Regulatory guidance may also evolve, requiring periodic review. Deeploy makes reassessment straightforward by allowing you to save previous classification results and re-assess risk at anytime. 

Assess your EU AI Act risk

Classify your AI systems with confidence and implement the right controls from day one.

More news

Whitepaper: AI Governance & Control Framework
August 26, 2026
Introducing the EU AI Act Hub: a reference for a moving target
July 21, 2026
AI agent governance is no longer optional: Why accountability matters
June 22, 2026

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one