Risk classification is the step that turns the EU AI Act from abstract into a to-do list: once you know which class a use case falls into, you know which obligations apply. The catch most SMEs miss is that the class follows the use case, not the software - so classification has to be done per use, not per tool. This guide walks through the four classes with SME examples and shows how to classify your own systems. For the wider context, see the EU AI Act compliance pillar.
- Four classes: minimal, limited, high-risk, unacceptable - the class sets the obligations.
- Classification depends on the use case, not the tool - classify each use separately.
- Most SME uses are limited-risk; HR and scoring uses are where high-risk appears.
The Four Risk Classes
How does the AI Act classify AI systems?
| Risk class | Typical SME examples | Key obligation |
|---|---|---|
| Minimal risk | Spam filters, basic recommendations | No specific requirements |
| Limited risk | Chatbots, AI-generated text | Transparency (Art. 50) |
| High-risk | AI in hiring, credit scoring, safety | Full documentation, human oversight, FRIA |
| Unacceptable risk | Social scoring, biometric mass surveillance | Prohibited |
For most SMEs, day-to-day AI use - drafting, summarising, support chat - sits in limited risk. High-risk appears in specific, consequential uses, above all in HR and any scoring of people.
Why Classification Follows the Use Case
The same tool, two different classes?
Yes. ChatGPT drafting internal documents is limited-risk. The same model used to screen job applicants is high-risk, with far stricter requirements - full technical documentation, demonstrable human oversight, and as a rule a Data Protection Impact Assessment under Art. 35 GDPR (a FRIA under Art. 27 AI Act would only be added if you are a public body or use the system for creditworthiness or insurance risk assessment). This is why "we only use ChatGPT" doesn't settle the question: what matters is what you use it for. Classify each use case on its own.
How to Classify Your AI Systems
What's the practical method?
1. Start from your AI inventory - every tool, and every distinct way you use it.
2. For each use, ask: does it make or prepare a decision about a person? Hiring, credit, access to services and similar uses point to high-risk.
3. Check the limited-risk triggers - does it interact with people or generate content? Then Article 50 transparency applies.
4. Record the class per use case in your documentation, so obligations follow automatically.
AI Risk Classification Checklist (PDF)
What Each Class Means for Your Timeline
When do these obligations apply?
AI literacy (Art. 4) and the ban on unacceptable-risk uses are enforceable now. Transparency obligations (Art. 50) apply from 2 August 2026. The high-risk obligations, for deployers as well as providers, were postponed to 2027-2028 under the Digital Omnibus - your classification and documentation work is still what's needed near-term. See the pillar timeline for the full picture.
ETHYX classifies each AI use case alongside your ROPA and carries the class through to the right obligations and documentation automatically - so classification isn't a one-off exercise you redo by hand.