Deciding which 'risk bucket' an AI system falls into so you know what rules and safeguards apply to it.
Deciding which 'risk bucket' an AI system falls into so you know what rules and safeguards apply to it.
The EU AI Act establishes a four-tier risk classification: unacceptable risk (prohibited practices under Article 5), high risk (Annex III systems and safety-component AI under Article 6), limited risk (transparency obligations under Article 50), and minimal risk (no mandatory requirements beyond GPAI obligations). Internal AI governance frameworks often apply finer-grained classification systems that map to regulatory tiers while adding organisation-specific risk considerations (reputational risk, sector-specific obligations). Risk classification is a precondition for applying appropriate governance controls and must be documented and justified.
Organisations should establish a risk classification process as the entry point to their AI governance programme — classifying each AI system before development begins and reassessing at significant lifecycle milestones.
Like classifying chemical substances under REACH — the classification determines which safety data, labelling, and registration requirements apply, with higher-hazard substances facing proportionally stricter controls.
Deciding which 'risk bucket' an AI system falls into so you know what rules and safeguards apply to it.
The EU AI Act establishes a four-tier risk classification: unacceptable risk (prohibited practices under Article 5), high risk (Annex III systems and safety-component AI under Article 6), limited risk (transparency obligations under Article 50), and minimal risk (no mandatory requirements beyond GPAI obligations). Internal AI governance frameworks often apply finer-grained classification systems that map to regulatory tiers while adding organisation-specific risk considerations (reputational risk, sector-specific obligations). Risk classification is a precondition for applying appropriate governance controls and must be documented and justified.
Organisations should establish a risk classification process as the entry point to their AI governance programme — classifying each AI system before development begins and reassessing at significant lifecycle milestones.