En este modulo
- The AI Act risk pyramid
- Decision tree: step-by-step classification
- Annex III: detailed analysis by area
- Exceptions and exclusions under Article 6(3)
- Self-assessment process
- Borderline cases and grey areas
- Classification documentation
- Reclassification and lifecycle changes
- Ejercicio practico
- Puntos clave
The AI Act risk pyramid
The EU AI Act classifies AI systems into four risk levels. This classification determines the applicable obligations, and the difference between one level and another can mean anything from zero obligations to an absolute prohibition of the system.
Level 1: unacceptable risk (prohibited)
Systems covered by Article 5. There is no compliance pathway: the only option is to cease the activity. Social scoring, subliminal manipulation, untargeted facial scraping, emotion recognition in employment/education (with specifically defined exceptions).
Level 2: high risk
Systems covered by Article 6 and listed in Annexes I and III. Extensive requirements: risk management, data governance, technical documentation, transparency, human oversight, accuracy/robustness/cybersecurity. Mandatory conformity assessment.
Level 3: limited risk
Systems with transparency obligations (Article 50). Chatbots, deepfakes, generated content. The main obligation is to inform the user that they are interacting with AI or that the content is artificial.
Level 4: minimal risk
All other systems. No specific AI Act obligations, although the Regulation encourages voluntary codes of conduct. Examples: spam filters, video games with AI, content recommendation systems (unless they influence democratic processes).
Classification is not static
A system classified as minimal risk can become high-risk if it is given a different use than intended. A customer service chatbot (limited risk) that starts making decisions about benefit eligibility becomes high-risk. The classification must be reviewed whenever there is a substantial change in use.
Decision tree: step-by-step classification
This decision tree guides you from the initial question to the final classification. Follow each node in order:
Node 1: Is it an AI system?
Apply the definition in Article 3(1). The system must be "machine-based", operate with "varying levels of autonomy" and generate outputs such as predictions, content, recommendations or decisions. If the answer is no, the AI Act does not apply. Note: simple business rules (if/else) are not AI systems. Machine learning models, neural networks, logic-based systems and statistical approaches are.
Node 2: Is it excluded from scope?
Article 2 excludes: AI systems for military/defence purposes, systems used exclusively for scientific research (before placing on the market), open-source AI systems (with nuances, Art. 2(12)), and systems used by natural persons for purely personal activity. If excluded, the AI Act does not apply.
Node 3: Is it a prohibited practice?
Review the complete Article 5. If the system falls within any of the 8 prohibitions, the activity must cease. No level of compliance can make it legal.
Node 4: Is it a safety component of a regulated product?
Review Annex I. If the system is a safety component of a product covered by Union harmonisation legislation (medical devices, machinery, toys, etc.) and requires a third-party conformity assessment, it is high-risk through pathway 1 of Article 6(1).
Node 5: Is it listed in Annex III?
Review the 8 areas of Annex III. If the intended purpose of the system falls within any of the sub-areas, it is high-risk through pathway 2 of Article 6(2). Proceed to node 6 to verify exceptions.
Node 6: Does any exception under Article 6(3) apply?
Even if listed in Annex III, a system may not be high-risk if it meets the conditions of Article 6(3) (see exceptions section below). If the exception applies, the system is treated as limited or minimal risk, but the provider must document the justification.
Node 7: Does it have transparency obligations?
If the system is not high-risk, review Article 50. Chatbots, deepfake generators, text generators for public information and emotion recognition/biometric categorisation systems have transparency obligations. If applicable, it is limited risk.
Node 8: Minimal risk
If it does not fit into any previous category, the system is minimal risk. No specific AI Act obligations, although voluntary codes of conduct are recommended.
Annex III: detailed analysis by area
Annex III is the most relevant listing for most organizations. Each area requires a specific analysis to determine whether a particular system is covered.
Area 1: Biometrics
Covers remote biometric identification (not real-time), biometric categorisation of persons and emotion recognition. The difference from Article 5 prohibitions: deferred remote biometric identification (not real-time) is high-risk, not prohibited. The use of biometrics for verification (1:1, confirming you are who you say you are) is not covered. Only identification (1:N, searching for a person among many).
Area 2: Critical infrastructure
Safety components in the management and operation of critical digital infrastructure, traffic, and water, gas, heating and electricity supply. Key point: it must be a "safety component", not just any AI system used in the sector. A customer service chatbot for an electricity company is not high-risk under this area.
Area 3: Education and vocational training
AI systems for determining access, admission or assignment to educational institutions. Systems for evaluating learning outcomes, including those that direct the learning process. Proctoring of examinations. Detection of prohibited behavior during examinations. Note: adaptive e-learning platforms that personalize content based on automated assessments may fall under this area.
Area 4: Employment, management of workers and access to self-employment
This area has the broadest impact. It covers:
- Recruitment and filtering of applications (ATS with AI, CV scoring).
- Targeted job advertisement publication (job ads targeting).
- Analysis and filtering of job applications.
- Evaluation of candidates in interviews or tests.
- Decisions on promotion, termination, task assignment based on individual profile or personality traits.
- Monitoring and evaluation of worker performance and behavior.
Area 5: Access to and enjoyment of essential public and private services
Assessment of eligibility for public benefits, public services and granting/revoking thereof. Credit scoring assessment. Risk assessment and pricing in life and health insurance. Assessment and classification of emergency calls. Prioritisation in dispatching emergency services (police, fire brigade, medical assistance, emergency rooms).
Areas 6-8: Law enforcement, migration and justice
These areas primarily affect public entities. They include AI polygraphs, assessment of reliability of evidence, recidivism prediction, assistance in legal research and application of the law to specific cases. Private providers selling these solutions to public entities assume the obligations of a high-risk system provider.
Exceptions and exclusions under Article 6(3)
Article 6(3), added during the final negotiation of the Regulation, introduces an important exception: a system listed in Annex III is not considered high-risk if it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons.
Conditions for the exception
The exception applies when the AI system meets at least one of these conditions:
- It performs a narrow procedural task.
- It improves the result of a previously completed human activity.
- It detects decision patterns or deviations from prior decision patterns and is not meant to replace or influence the previously performed human assessment without proper human review.
- It performs a preparatory task for an assessment relevant for the use cases listed in Annex III.
Critical limitation
The exception does not apply if the system performs profiling of natural persons (profiling within the meaning of Article 4(4) of the GDPR). This means that any system that creates individual profiles based on personal data for automated decision-making cannot benefit from this exception.
Mandatory documentation
If you invoke the Article 6(3) exception, you must document the assessment justifying that the system does not present a significant risk. This documentation must be available to the competent authority. If the authority disagrees, the system is reclassified as high-risk and you must comply with all requirements retroactively.
Self-assessment process
Risk classification requires a systematic process. It is not a decision that should be made by a single person or based on intuition. This is a 6-step self-assessment process:
Step 1: System inventory
Identify all systems using AI components in your organization. Include third-party SaaS tools. For each system, document: name, provider, function, data processed, internal users, persons affected by the decisions.
Step 2: Definition validation
For each system, verify whether it meets the definition in Article 3(1). Document the reasoning. Systems based exclusively on predetermined rules (no learning, no statistical inference) generally are not AI systems under the Regulation.
Step 3: Exclusion verification
Verify whether any system is excluded from the scope of Article 2 (military, pure research, personal use, open source with conditions).
Step 4: Prohibition screening
Pass each system through the Article 5 filter. This step has maximum priority because the prohibitions are already applicable. If a system falls within scope, the action is immediate: cease the activity.
Step 5: Risk classification
Apply the decision tree for each system: Annex I (safety component), Annex III (high-risk areas), Article 6(3) exception, transparency obligations of Article 50, or minimal risk.
Step 6: Validation and documentation
Review the classification with the DPO, the legal officer and, if possible, an external expert. Document the complete reasoning for each system. This documentation is the first line of defence in an inspection.
Borderline cases and grey areas
Classification is not always black and white. These are the most common borderline cases and how to approach them:
Chatbots with decision-making capability
A customer service chatbot that only answers questions is limited risk (transparency obligation, Art. 50). But if that chatbot can approve or deny claims, authorise refunds, or route to an agent based on a customer score, it may cross the line into high-risk (Annex III area 5: access to essential services). The criterion: does the chatbot influence the customer's access to a service in a way that significantly affects their rights?
AI-powered productivity tools
Microsoft Copilot in Word is minimal risk. Microsoft Copilot in an employee performance evaluation process could be high-risk (Annex III area 4). The tool is the same; what changes is the use. The criterion is always the intended or reasonably foreseeable purpose, not the tool in the abstract.
Recommendation systems
A product recommendation system in e-commerce is minimal risk. A recommendation system that suggests candidates for a job position is high-risk. An educational content recommendation system that determines the student's learning pathway may be high-risk if it "directs the learning process" (area 3).
AI embedded in products
A household appliance with AI to optimize energy consumption is not necessarily high-risk. But if the AI controls a safety component (for example, the temperature of an industrial oven), it enters through pathway 1 of Article 6(1) if the product is covered by Union harmonisation legislation listed in Annex I.
Use outside the intended purpose
If your organization uses an AI system in a way not intended by the provider (for example, using a general LLM for candidate scoring), you become the de facto provider of the new system. You assume all the obligations of a high-risk system provider.
Precautionary principle
In case of doubt about the classification, apply the higher risk level. It is safer (and cheaper in the long run) to comply with high-risk requirements for a system that might not be high-risk, than to assume minimal risk and discover in an inspection that the system was high-risk.
Classification documentation
Risk classification documentation is a critical deliverable. It must be a formal, dated, versioned document approved by the person responsible for AI governance.
Recommended document structure
- Section 1: system identification. Name, version, provider, acquisition/development date, internal owner, functional description, data processed, persons affected.
- Section 2: definition validation. Reasoning on whether it meets the Art. 3(1) definition. If it is not an AI system, the analysis ends here with the justification.
- Section 3: exclusion verification. Analysis of each Art. 2 exclusion and reasoned conclusion.
- Section 4: prohibition screening. Analysis against each of the 8 Art. 5 prohibitions with reasoned conclusion.
- Section 5: risk classification. Detailed analysis: pathway 1 (Annex I), pathway 2 (Annex III with specific sub-area), Art. 6(3) exception (if applicable), transparency obligations (Art. 50). Classification conclusion.
- Section 6: implications. Obligations arising from the classification, identified gaps, action plan with deadlines.
- Section 7: approval. Signature of the AI governance officer, date, next scheduled review.
Versioning and updates
The document must be reviewed at least annually and whenever there is a substantial change in the system (new functionalities, new data, new use, new organisational context) or a relevant regulatory change (Annex III update by delegated act, new harmonised standard, guidance from AESIA or the AI Office).
Reclassification and lifecycle changes
Risk classification is not a one-time exercise. Several events can trigger reclassification:
Reclassification triggers
- Change of use: a financial data analytics system (minimal risk) that begins to be used for automated credit scoring (high-risk).
- Substantial modification: a change in the algorithm, training data or decision logic that alters the system's risk profile.
- Annex III update: the Commission may add new high-risk areas through a delegated act. A system classified as minimal risk today could be high-risk tomorrow.
- Organisational change: an acquisition, merger or restructuring that changes the context of use of the system.
- Incidents: a serious incident may reveal that a system had a higher risk profile than initially classified.
Reclassification process
When a trigger is identified, the AI governance officer must initiate a reclassification process within a maximum of 30 days. The process includes: new assessment following the decision tree, documentation update, identification of new compliance gaps, action plan with deadlines (if the level increases) and notification to the competent authority (if the system was already registered in the EU database).
Ejercicio practico
- Select 5 AI systems from your organization (or use these examples: customer service chatbot, ATS with CV scoring, fraud detection system, machine translation tool, employee performance monitoring system).
- For each system, walk through the complete decision tree documenting each node.
- Identify whether any of the 5 systems could benefit from the Article 6(3) exception. Document the reasoning.
- For each system classified as high-risk, identify the specific Annex III area and the derived obligations.
- Draft section 5 (risk classification) of the classification document for at least 2 of the 5 systems.
Output: partial classification documentation for 5 systems, with complete decision tree analysis and at least 2 formal sections drafted.
Puntos clave
Puntos clave from TG02
- Risk classification is the first step of AI Act compliance. Without a correct classification, you cannot know which obligations apply to you.
- The decision tree has 8 nodes: AI definition, exclusions, prohibitions, Annex I, Annex III, Art. 6(3) exceptions, transparency, minimal risk. It must be walked through completely for each system.
- Annex III area 4 (employment) is where most organizations will have high-risk systems. Any AI in recruitment, evaluation or worker monitoring is high-risk.
- The Art. 6(3) exception does not apply if there is profiling of natural persons. And it requires formal documentation of the justification.
- Classification is not static. Changes of use, system modifications, Annex III updates or incidents can trigger reclassification. Review at least annually.
Guia de estudio — Conceptos clave de TG02
La piramide de riesgos del AI Act
- La clasificacion no es estatica: Un sistema clasificado como riesgo minimo puede convertirse en alto riesgo si se le da un uso diferente al previsto. Un chatbot de atencion al cliente (riesgo limitado) que empiece a tomar decisiones sobre la elegibilidad de prestaciones se convierte en alto riesgo. La clasificacion debe revisarse ante cualquier cambio sustancial en el uso.
Anexo III: analisis detallado por area
- Seleccion y filtrado de candidaturas (ATS con IA, scoring de CVs).
- Publicacion de ofertas de empleo dirigidas (job ads targeting).
- Analisis y filtrado de solicitudes de empleo.
- Evaluacion de candidatos en entrevistas o pruebas.
- Decisiones sobre promocion, terminacion, asignacion de tareas basada en perfil individual o rasgos de personalidad.
- Monitorizacion y evaluacion del rendimiento y comportamiento de trabajadores.
Excepciones y exclusiones del articulo 6.3
- Realiza una tarea procedimental estricta (narrow procedural task).
- Mejora el resultado de una actividad humana previamente completada.
- Detecta patrones de decision o desviaciones de patrones de decision anteriores y no sustituye ni influye en la evaluacion humana previamente realizada sin revision humana adecuada.
- Realiza una tarea preparatoria para una evaluacion relevante a efectos de los casos de uso listados en el Anexo III.
- Documentacion obligatoria: Si invocas la excepcion del articulo 6.3, debes documentar la evaluacion que justifica que el sistema no presenta un riesgo significativo. Esta documentacion debe estar disponible para la autoridad competente. Si la autoridad discrepa, el sistema se reclasifica como alto riesgo y debes cumplir con todos los requisitos retroactivamente.
Casos limite y zonas grises
- Principio de precaucion: En caso de duda sobre la clasificacion, aplica el nivel de riesgo superior. Es mas seguro (y mas barato a largo plazo) cumplir los requisitos de alto riesgo para un sistema que podria no serlo, que asumir riesgo minimo y descubrir en una inspeccion que el sistema era de alto riesgo.
Documentacion de la clasificacion
- Seccion 1: identificacion del sistema.Nombre, version, proveedor, fecha de adquisicion/desarrollo, responsable interno, descripcion funcional, datos procesados, personas afectadas.
- Seccion 2: validacion de definicion.Razonamiento sobre si cumple la definicion del art. 3.1. Si no es un sistema de IA, el analisis termina aqui con la justificacion.
- Seccion 3: verificacion de exclusiones.Analisis de cada exclusion del art. 2 y conclusion motivada.
- Seccion 4: screening de prohibiciones.Analisis frente a cada una de las 8 prohibiciones del art. 5 con conclusion motivada.
- Seccion 5: clasificacion de riesgo.Analisis detallado: via 1 (Anexo I), via 2 (Anexo III con subarea especifica), excepcion art. 6.3 (si aplica), obligaciones de transparencia (art. 50). Conclusion de clasificacion.
- Seccion 6: implicaciones.Obligaciones derivadas de la clasificacion, gaps identificados, plan de accion con plazos.
Reclasificacion y cambios en el ciclo de vida
- Cambio de uso:un sistema de analisis de datos financieros (riesgo minimo) que empieza a usarse para scoring crediticio automatizado (alto riesgo).
- Modificacion sustancial:un cambio en el algoritmo, los datos de entrenamiento o la logica de decision que altera el perfil de riesgo del sistema.
- Actualizacion del Anexo III:la Comision puede anadir nuevas areas de alto riesgo mediante acto delegado. Un sistema clasificado como riesgo minimo hoy podria ser alto riesgo manana.
- Cambio organizativo:una adquisicion, fusion o reestructuracion que cambie el contexto de uso del sistema.
- Incidentes:un incidente grave puede revelar que un sistema tenia un perfil de riesgo superior al clasificado inicialmente.
Siguiente: TG03 - GDPR and AI: Practical Interaction
With systems classified, the next step is to integrate AI Act compliance with the GDPR. Coordinated DPIAs, joint documentation and the DPO's role in AI governance.
Ir al modulo TG03