The Week in One Line

The risk category of each AI system your company uses determines everything else:

• documentation burden

• oversight requirements

• legal exposure

What the Act Actually Says

The EU AI Act classifies AI systems into four risk levels.

The category determines what obligations apply.

Unacceptable-Risk Systems

These are prohibited outright under Article 5.

Examples include:

• AI manipulating people psychologically

• social scoring by public authorities

• emotion recognition in workplaces and schools

• certain forms of real-time biometric surveillance in public spaces

These prohibitions have already applied since February 2025.

High-Risk Systems

These systems are regulated but still permitted.

They are defined in two ways:

• AI used as a safety component in products already covered by EU product safety law

• AI used in the eight domains listed in Annex III

The eight domains are:

• biometrics

• critical infrastructure

• education and vocational training

• employment and worker management

• access to essential services

• law enforcement

• migration and border control

• justice and democratic processes

If your system falls into one of those categories, it is considered high-risk by default.

Limited-Risk Systems

These face lighter transparency obligations.

This mainly involves informing users they are interacting with AI.

Chatbots and deepfake tools generally fall into this category.

Minimal-Risk Systems

These face no specific obligations under the Act.

One misconception many companies still have is assuming the vendor determines the classification.

Operationally, that is not how the Act works.

The deployer must understand and document how the system is being used inside the business.

Source:

artificialintelligenceact.eu — Article 5, Article 6, Annex III

What This Means for Your Business

Most companies currently do not have a complete inventory of AI systems being used internally.

Individual teams are already deploying AI capabilities inside:

• HR systems

• CRMs

• analytics platforms

• support tooling

• internal workflows

...without central visibility.

In many organisations, governance teams are discovering AI usage after deployment rather than before it.

That creates a major governance problem:

You cannot govern systems you cannot identify.

A sales team using AI lead scoring inside a CRM platform may already be operating a system requiring documented oversight and monitoring obligations.

A recruitment team using AI-assisted ranking inside an ATS may already be deploying a high-risk system under Annex III.

The classification responsibility sits with the deployer.

If you cannot classify a system, that itself becomes a compliance finding.

There is also an important exemption many organisations overlook.

Certain Annex III systems may not qualify as high-risk if they perform only narrow preparatory tasks without materially influencing a final decision.

But this exemption is not automatic.

The rationale must be documented before deployment.

Risk status can also change over time.

Expanding an existing AI tool into a new workflow or adding additional decision-making capability may trigger reassessment obligations.

Most organisations are still treating AI governance like a procurement exercise.

In practice, this is an operational governance problem.

This Week’s Action Point

Go to:

artificialintelligenceact.eu/annex/3

Read the eight Annex III categories.

Then create a simple spreadsheet listing every AI-enabled tool currently used across your business.

Include:

• the department using it

• the purpose of the system

• whether it influences decisions

• whether it touches any Annex III domain

• who internally owns it

That inventory becomes the foundation of your entire compliance process.

Further Reading

Annex III — High-Risk AI Systems

artificialintelligenceact.eu/annex/3

Article 5 — Prohibited AI Practices

artificialintelligenceact.eu/article/5

AI Act Explorer

artificialintelligenceact.eu/ai-act-explorer

#EUAIAct #AIGovernance #EnterpriseAI #ResponsibleAI #AICompliance