AI risk classification

BusinessSafety and governancePublished By Simon Budziak

AI risk classification is the assignment of an AI system or use case to a defined risk category based on its purpose, affected people, decisions, data, and potential harm. The classification determines which controls, evidence, approvals, and legal obligations apply, and it must change when the use changes.

Classification is not a universal label attached to a model. It is a documented conclusion about a concrete system and the organization’s role in providing or deploying it. The European Commission’s guidelines for high-risk AI systems explain the classification rules and practical examples under the EU AI Act.

An AI use case moving through prohibited, high-risk, transparency, and other-duty classification gates before controls are assigned

What information is needed to classify an AI system?

Start with intended purpose, users, affected people, decisions supported or made, data involved, deployment context, and potential harm. Record whether the system influences access to employment, education, credit, essential services, safety, or legal rights. Classify the use case and organizational role, not the model brand.

The same foundation model may power an internal writing assistant and a system used in a consequential decision. Those implementations can have different classifications because their purposes and effects differ.

How does classification work under the EU AI Act?

The EU AI Act applies a risk-based framework that includes prohibited practices, high-risk systems, transparency obligations, and uses without those specific duties. Exact classification also depends on whether the organization acts as provider, deployer, importer, distributor, or another regulated role. A legal category follows the facts of deployment, not a marketing description.

Teams should use the regulation and current Commission guidance, then obtain legal advice where the classification is consequential or unclear. A glossary can explain the framework but cannot classify a particular system without its facts.

How should companies operationalize the result?

Record the system, owner, purpose, classification, rationale, jurisdiction, role, and review date in an AI inventory. Connect the result to AI compliance controls, documentation, human oversight, logging, testing, and approvals. A classification is useful only when it changes what the organization must do.

Maintain links to the evidence used for the decision. That lets reviewers see whether a later change invalidates the original reasoning.

When must the classification change?

Review it when the purpose, user group, affected population, data, autonomy, integration, geography, or organizational role changes. AI risk management should also assess operational risks inside any legal category. A new customer or decision can change the classification without changing the code.

Classification is a starting point, not a complete safety assessment. A system outside a high-risk legal class can still create material commercial, security, or reputational harm. Apply controls proportionate to the actual risk and keep the legal analysis current as guidance and system facts evolve.

Frequently asked questions

What is AI risk classification used for?

It maps a specific AI use and organizational role to the controls, evidence, approvals, and legal duties that apply.

Can one AI model have several risk classifications?

Yes. Classification depends on each intended use and role, so the same model can support low-impact and regulated systems.

When should an AI risk classification be reviewed?

Review it when purpose, users, affected people, data, autonomy, deployment region, or organizational role changes.

Summarize this page with

See this working in a system we built