Abstract representation of large language models and AI technology.

AI Act compliance: How to do the risk assessment

Determining the risk level of an AI system is essential for ensuring compliance with the EU AI Act. The Regulation distinguishes three risk categories – prohibited AI systems, high-risk AI systems, and limited-risk AI systems – each subject to specific compliance obligations.

1.     Prohibited AI systems

Article 5 of the AI Act sets out the prohibited AI practices. To determine whether an AI system shall be classified as “prohibited”, it is necessary to answer the following questions:

 

  • Does the AI system use subliminal techniques operating without a person’s awareness, or deliberately manipulative or deceptive techniques, with the objective or effect of materially distorting a person’s or a group’s behaviour?

  • Does the AI system exploit vulnerabilities of a natural person or a specific group of persons?

  • Is the AI system used for the assessment or classification of natural persons or groups of persons?

  • Is the AI system used for “social scoring” purposes?

  • Is the AI system used to evaluate or predict the risk of a natural person committing a criminal offence?

  • Does the AI system create or expand facial recognition databases through untargeted scraping of images from the internet or CCTV footage?

  • Does the AI system perform emotion recognition of natural persons in the workplace or educational institutions?

  • Is the AI system a biometric categorisation system?

If the answer to any of these questions is affirmative, the AI system shall be categorised as “prohibited” and will be banned from being placed on the Union market as of 2 February 2025.

If all answers are negative, the next step is to determine whether the system is to be classified as high-risk.

2.     High risk AI systems

To determine whether an AI system should be classified as “high risk”, it is necessary to answer the two questions contained in Article 6 of the AI Act.

  • Is the AI system intended to be used as a safety component of a product, or is it itself a product listed in Annex I of the AI Act? 

Annex I of the AI Act lists a series of directives concerning the following products for which EU law provides specific safety standards, which can be summarised as follows: 

machinery; interchangeable equipment, safety components, lifting accessories, chains, ropes and webbing, removable mechanical transmission devices, partly completed machinery, toys, recreational craft, personal watercraft, propulsion engines installed or specifically intended to be installed on or in recreational craft, recreational craft, lifts, lifting equipment, rack and pinion trains, escalators, equipment and protective systems intended for use in potentially explosive atmospheres, safety, control and regulation devices intended for use outside potentially explosive atmospheres but necessary or useful for the safe operation of equipment and protective systems with regard to explosion risks, components intended to be incorporated into the aforementioned equipment and protective systems, radio equipment, pressure equipment, cableway installations and components for cableway installations, personal protective equipment (PPE), appliances burning gaseous fuels used for cooking, refrigeration, air conditioning, space heating, hot water production, lighting or washing, as well as appliances such as forced-air burners and heaters that must be equipped with such burners; and medical devices for human use and accessories for such devices; medical diagnostic devices for human use and accessories for such devices; airports; air carriers; two-, three- or four-wheeled vehicles; systems, components and separate technical units, as well as parts and equipment, designed and manufactured for such vehicles; agricultural and forestry vehicles; components and separate technical units, as well as parts and equipment designed and manufactured for such vehicles; marine equipment; railway systems and vehicles; motor vehicles and trailers; systems, components and separate technical units intended for such vehicles; aircraft and aircraft components.

 

  • Does the AI system fall within one of the following sectors listed in Annex III of the AI Act?

Annex III of the AI Act concerns specific sectors, which can be summarised as follows:

biometrics; critical infrastructure (digital, traffic, water supply, gas, heating, electricity); education and vocational training; employment and access to work; essential private and public services (public assistance, healthcare, creditworthiness, risk assessment and pricing in relation to individuals in the case of life insurance and health insurance; assessment and classification of emergency calls made by natural persons or to dispatch emergency first response services or to prioritise the dispatch of such services, including police, fire and medical assistance, as well as for patient triage systems in relation to emergency healthcare), law enforcement; migration, asylum and border control management; administration of justice and democratic processes.

 

For each of the sectors mentioned above, Annex III of the AI Act sets out specific requirements for an AI system to be classified as high risk, as well as specific exceptions. In order not to overload this article, we will not list the specific requirements for each sector, but only a few examples. By way of example:

 

  • If the AI system concerns critical infrastructure, in order for it to be considered high risk, it must be intended for use as a safety component in the management and operation of critical digital infrastructure, road traffic or the supply of water, gas, heating or electricity.

N.B. The concept of “safety component” is defined in Article 3(14) as “a component of an AI product or system that performs a safety function for that AI product or system or whose failure or malfunction endangers the health and safety of persons or property”.

 

  • If the AI system relates to creditworthiness, in order for it to be considered high risk, it must be intended to be used to assess the creditworthiness of natural persons or to determine their credit rating. However, AI systems used for the purpose of detecting financial fraud are excluded.
If the AI system falls into one of the above categories, it would be categorised as “high risk”.

In this case, by 2 August 2026, the AI system will have to comply with specific obligations such as:

 

  • Indication of the supplier in the documentation accompanying the AI system (Article 16).
  • Registration of the system in the EU database (Article 49).
  • Conformity assessment covering, among other things: data quality (Art. 10), documentation (Art. 11) and traceability (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy, cybersecurity and robustness (Art. 15).
  • The implementation of quality and risk management systems to ensure compliance with requirements and minimise risks to users and data subjects (Articles 9 and 17).
  • The retention of documentation in accordance with the requirements of Article 18.
  • The retention of logs in accordance with the requirements of Article 19.
  • The adoption of the CE marking in accordance with Article 48.

If, on the other hand, the AI system does not fall into one of the above categories, it will be necessary to verify that it does not fall within the so-called “low-risk AI systems”.

3.     Exceptions to the ‘high risk’ classification

Article 6 of the AI Act also provides for exemptions, but only for AI systems covered by Annex IIIIn fact, an AI system covered by Annex III is not considered high risk if:

 

  1. It does not profile natural persons and
  2. It does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including in the sense of not materially influencing the outcome of the decision-making process i.e. if at least one of the following conditions is met:
    • the AI system is intended to perform a limited procedural task;
    • the AI system is intended to improve the outcome of a previously completed human activity;
    • the AI system is intended to detect decision-making patterns or deviations from previous decision-making patterns and is not intended to replace or influence human assessment previously completed without adequate human review; or
    • the AI system is intended to perform a preparatory task for an assessment relevant to the use cases listed in Annex III.

4.     Limited risk AI system

Although the AI Act does not provide a detailed definition, limited-risk AI systems are subject to specific transparency
obligations
(Art. 50).

To determine whether the AI system is subject to these specific obligations, the following questions must be answered:

 
  • Is the AI system intended to interact directly with natural persons (e.g. chatbots)?
  • Is the AI system capable of generating audio, image, video or text content?
  • Is the AI system capable of recognising emotions or performing biometric categorisation of individuals?
  • Is the AI system capable of generating “deepfakes”?

If the answer to any of the above questions is affirmative, the specific transparency requirements set out in Article 50 must be met by 2 August 2026.

 

In conclusion, AI risk assessment is not only a legal obligation but also a governance tool. An AI Act compliance roadmap enables businesses to reduce risks and improve user confidence.

Leave a Comment

Your email address will not be published. Required fields are marked *