Accurate risk classification is the foundation of compliance with the EU AI Act. The EU AI Act imposes different obligations depending on risk level, with penalties up to €35 million or 7% of global annual turnover for non-compliance.
Understanding your risk level helps allocate compliance resources effectively, avoiding over-engineering low-risk systems or under-protecting high-risk ones.
How the EU AI Act classifies risk
The AI Act organizes AI systems into four risk categories, with requirements increasing based on potential harm. This risk-based approach means your compliance obligations depend entirely on what your AI system does and how it’s used.
Proper risk classification drives all subsequent compliance requirements and determines whether your AI system can legally operate in the EU.
EU AI Act risk categories
- Prohibited AI Systems: AI practices that pose unacceptable risks and are completely banned under Article 5.
- High-Risk AI Systems: Systems that require strict compliance based on their potential impact on safety and fundamental rights (Articles 6-7).
- Limited-Risk Systems: AI requiring transparency obligations like disclosure of AI interaction.
- Minimal-Risk Systems: AI with no specific regulatory requirements beyond voluntary codes of conduct.
AI risk classification challenges
Organizations frequently encounter obstacles when classifying AI systems:
- Dual-Use Systems: AI with multiple applications may span risk categories. A chatbot used for customer service (minimal risk) versus mental health support (high risk) requires separate classifications.
- Purpose Drift: Systems deployed beyond original intent change risk profiles. Deployers using AI for unintended high-risk purposes become providers with full compliance obligations.
- Component vs. System Classification: Distinguishing between AI components and complete systems affects requirements. An AI model embedded in regulated medical devices follows different paths than standalone diagnostic software.
- Evolving Capabilities: Systems gaining new functions through updates may shift risk categories, triggering additional compliance requirements mid-lifecycle.
How Deeploy helps with AI risk classification



Deeploy’s risk classification assessment removes guesswork from EU AI Act compliance. Our guided questionnaire walks you through the regulatory criteria, ensuring accurate classification for your AI models.
The assessment guides you through several key questions to determine:
- Whether your system falls under the EU AI Act's definition of an AI system
- The intended purpose and application domain of your system
- Potential prohibited uses under Article 5
- High-risk criteria as defined in Articles 6-7
- Specific use cases that automatically qualify as high-risk
After completing all questions, you’ll receive a recommended risk classification. Applying this classification allows you to implement specific technical and organizational controls that address identified risks.
Frequently Asked Questions
About risk assessment for the EU AI Act
What happens if I classify my AI system incorrectly under the EU AI Act?
Incorrect classification can result in non-compliance penalties up to €35 million or 7% of global turnover. If you classify a high-risk system as minimal-risk and fail to implement required safeguards, you face both regulatory fines and potential liability for harms caused. Deeploy’s guided assessment helps prevent misclassification by systematically evaluating all regulatory criteria.
Can an AI system's risk classification change after deployment?
Yes. Risk classification can change if the system’s purpose evolves, new capabilities are added, or it’s deployed in different contexts. If a deployer uses AI for high-risk purposes the provider didn’t intend, the deployer becomes the provider with full compliance obligations. Deeploy enables reassessment whenever system use cases change.
Can low-risk AI become high-risk through deployment decisions?
Absolutely. An AI system classified as minimal-risk by its provider becomes high-risk if a deployer uses it for applications listed in Annex III of the AI Act (like employment decisions or law enforcement). In these cases, the deployer assumes provider obligations.
How does Deeploy determine risk classification recommendations?
Deeploy implements the EU AI Act’s risk framework through a structured questionnaire based on the Algorithm Audit Implementation Tool. The assessment evaluates whether your system meets AI definitions, matches prohibited use cases, falls within high-risk application domains, or triggers specific regulatory criteria. Recommendations align with official EU guidance.
Does Deeploy's risk assessment satisfy EU AI Act compliance requirements?
Deeploy’s assessment provides the foundational risk classification required for compliance planning. While it doesn’t replace conformity assessments for high-risk systems, it establishes the correct risk category that determines which requirements apply. The documented assessment serves as evidence of due diligence in your compliance framework.
How often should we reassess our AI system's risk classification?
Reassess risk classification whenever you modify the AI’s purpose, add significant functionality, deploy in new contexts, or update underlying models. Regulatory guidance may also evolve, requiring periodic review. Deeploy makes reassessment straightforward by allowing you to save previous classification results and re-assess risk at anytime.


