Risk classification is how you decide which AI systems need heavy controls and which need almost none. It is the step that turns a list of AI tools into a governed one: without it, you either over-govern everything and grind to a halt, or under-govern the systems that can actually hurt someone. Both ISO 42001 and the EU AI Act are built around it, so it is not optional if either applies to you.
Most organisations get as far as a register of their AI and then stall, because a flat list of forty tools tells you nothing about where to spend your attention. Classification is what makes the list actionable. Here is a method you can apply.
Two kinds of risk, kept separate
The single most useful thing to get right is that there are two classifications, and they answer different questions.
- Legal risk (the EU AI Act tier). Which statutory obligations apply to this system. This is defined for you by law; you do not get to choose it.
- Operational risk (your own impact assessment). How much this system could harm your business, your customers or your staff, regardless of what any regulation says.
They overlap but they are not the same. A system can be minimal-risk under the Act yet high-impact for you (an internal tool that quietly drives a big financial decision), or high-risk under the Act but well contained in your particular use. Run both lenses on every system and take the stricter result.
The legal lens: the EU AI Act tiers
If you place AI on the EU market or your AI output is used in the EU, the Act sorts every system into one of four levels:
| Tier | What it means | Examples |
|---|---|---|
| Prohibited | Banned outright | Social scoring, most real-time biometric surveillance, manipulative AI |
| High-risk | Allowed but heavily regulated | AI in recruitment, credit scoring, medical devices, critical infrastructure |
| Limited-risk | Transparency duties only | Chatbots, AI-generated content that must be labelled |
| Minimal-risk | No specific obligations | Spam filters, most productivity and analytics AI |
Your legal duties follow directly from the tier. We covered what those duties actually are in the EU AI Act for deployers, and when they bite in the EU AI Act deadlines. The classification job here is simple in principle: work out which tier each system falls into, and document why.
The operational lens: scoring your own risk
The legal tier does not tell you how much a system matters to you. For that, score each system against a handful of factors. These are the questions that actually predict harm:
- What does it decide or do? Does it inform a human, or does it act on its own? An assistant that drafts is very different from an agent that executes.
- Who does it affect? Internal staff only, or customers, applicants, patients, the public? The more it touches people’s rights or livelihoods, the higher the risk.
- How autonomous is it? Is there a human checking the output before anything happens, or does it run unattended?
- How sensitive is the data? Personal data, financial data, health data and confidential material all raise the stakes.
- How reversible is a mistake? A wrong draft you can bin. A wrong payment, a rejected application or a published falsehood is far harder to undo.
- What is the scale? A tool used once a week by one team is not the tool making ten thousand automated decisions a day.
You do not need a heavy scoring model. Rating each factor low, medium or high, then letting the highest factors pull the overall rating up, is enough to be consistent and defensible.
Turn scores into tiers
Scoring is only useful if each result attaches to a defined set of controls. Three or four internal tiers is the sweet spot:
| Your tier | Roughly | What it gets |
|---|---|---|
| Critical | High-impact or high-risk under the Act | Full controls: human oversight, documented risk assessment, monitoring, sign-off before launch |
| Elevated | Meaningful impact on people or money | Named owner, oversight on outputs, periodic review |
| Standard | Limited impact, contained use | Registered, basic usage rules, light review |
| Minimal | Trivial, low-stakes | Registered and left alone |
The tier is the whole point: it decides how much governance a system gets, so you spend your effort where the risk actually is. This is exactly what an AI Management System uses to stay proportionate rather than drowning every tool in the same paperwork.
The process, step by step
- Start from the register. You cannot classify what you cannot see, so begin with a complete inventory, including the shadow AI you had to go looking for.
- Apply the legal lens. Assign each system an EU AI Act tier, if the Act is in scope for you.
- Apply the operational lens. Score each system against the factors above.
- Take the stricter result and assign an internal tier.
- Attach the controls that tier requires, and note any gaps between what the tier demands and what is actually in place.
- Record the reasoning. The classification and the why behind it are part of your evidence trail, and the first thing an auditor or regulator will ask to see.
- Re-run it on change. A new data source, a new use, or more autonomy can move a system up a tier. Classification is a standing process, not a one-off.
Common mistakes
- Classifying by tool, not by use. The same model can be minimal-risk in one workflow and critical in another. Classify the use, not the vendor.
- Letting one person decide by feel. Without a defined method, two people classify the same system differently. Score against fixed factors so it is consistent and repeatable.
- Confusing the two lenses. Assuming “minimal-risk under the Act” means “safe to ignore” is how high-impact internal systems slip through ungoverned.
- Never revisiting it. Systems drift. A tool that was an experiment last quarter may now be making real decisions at scale.
The short version
Risk classification is the step that makes an AI inventory worth having. Run two lenses on every system, the EU AI Act’s legal tiers and your own operational impact score, take the stricter of the two, and assign an internal tier that attaches a defined set of controls. Document the reasoning, and re-run it when things change. Done well, it means the systems that can cause harm get real oversight and the ones that cannot are left to do their job.
Want a fast read on where your systems land? The free EU AI Act check classifies your systems against the Act’s tiers, and the free AI governance readiness assessment shows how much of this you already have in place, each in about ten minutes with no email required. When you want to turn the classification into a working set of controls, talk to us.
For the full picture, see the AI governance guide.
Frequently asked questions
What does it mean to classify an AI system by risk?
It means deciding, in a consistent way, how much harm an AI system could do and therefore how much oversight and control it needs. You score each system against factors such as what it decides, who it affects, how autonomous it is, and how reversible its actions are, then assign it a risk tier that sets the level of governance it gets.
What are the EU AI Act risk categories?
The EU AI Act sorts AI into four levels: prohibited (banned outright, such as social scoring), high-risk (allowed but heavily regulated, such as AI used in recruitment or credit), limited-risk (transparency duties, such as telling people they are talking to a chatbot), and minimal-risk (most other AI, with no specific obligations). Your legal duties follow from which tier a system falls into.
Is the EU AI Act classification the same as my own risk assessment?
No, and it helps to keep them separate. The EU AI Act tiers are a legal classification that decides which statutory obligations apply. Your own risk assessment is an operational judgement of how much a system could hurt your business, customers or staff. A system can be low-risk under the Act but still high-impact for you, so you run both lenses and take the stricter result.
How many risk tiers should we use?
Three or four internal tiers is usually enough: something like critical, elevated, standard and minimal. Fewer than three and the classification stops being useful; many more and it becomes hard to apply consistently. The point of tiers is to attach a defined set of controls to each, so keep the number small enough that each tier means something.
Who should classify our AI systems?
The system owner does the initial classification, using a defined method so it is consistent across the organisation, and whoever is accountable for AI governance reviews and signs it off. The key is that classification is a documented, repeatable process rather than one person's opinion, because the tier drives the controls and you may have to justify it to an auditor or regulator.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert