The Week in One Line
The risk category of each AI system your company uses determines everything else:
• documentation burden
• oversight requirements
• legal exposure
What the Act Actually Says
The EU AI Act classifies AI systems into four risk levels.
The category determines what obligations apply.
Unacceptable-Risk Systems
These are prohibited outright under Article 5.
Examples include:
• AI manipulating people psychologically
• social scoring by public authorities
• emotion recognition in workplaces and schools
• certain forms of real-time biometric surveillance in public spaces
These prohibitions have already applied since February 2025.
High-Risk Systems
These systems are regulated but still permitted.
They are defined in two ways:
• AI used as a safety component in products already covered by EU product safety law
• AI used in the eight domains listed in Annex III
The eight domains are:
• biometrics
• critical infrastructure
• education and vocational training
• employment and worker management
• access to essential services
• law enforcement
• migration and border control
• justice and democratic processes
If your system falls into one of those categories, it is considered high-risk by default.
Limited-Risk Systems
These face lighter transparency obligations.
This mainly involves informing users they are interacting with AI.
Chatbots and deepfake tools generally fall into this category.
Minimal-Risk Systems
These face no specific obligations under the Act.
One misconception many companies still have is assuming the vendor determines the classification.
Operationally, that is not how the Act works.
The deployer must understand and document how the system is being used inside the business.
Source:
artificialintelligenceact.eu — Article 5, Article 6, Annex III
What This Means for Your Business
Most companies currently do not have a complete inventory of AI systems being used internally.
Individual teams are already deploying AI capabilities inside:
• HR systems
• CRMs
• analytics platforms
• support tooling
• internal workflows
...without central visibility.
In many organisations, governance teams are discovering AI usage after deployment rather than before it.
That creates a major governance problem:
You cannot govern systems you cannot identify.
A sales team using AI lead scoring inside a CRM platform may already be operating a system requiring documented oversight and monitoring obligations.
A recruitment team using AI-assisted ranking inside an ATS may already be deploying a high-risk system under Annex III.
The classification responsibility sits with the deployer.
If you cannot classify a system, that itself becomes a compliance finding.
There is also an important exemption many organisations overlook.
Certain Annex III systems may not qualify as high-risk if they perform only narrow preparatory tasks without materially influencing a final decision.
But this exemption is not automatic.
The rationale must be documented before deployment.
Risk status can also change over time.
Expanding an existing AI tool into a new workflow or adding additional decision-making capability may trigger reassessment obligations.
Most organisations are still treating AI governance like a procurement exercise.
In practice, this is an operational governance problem.
This Week’s Action Point
Go to:
artificialintelligenceact.eu/annex/3
Read the eight Annex III categories.
Then create a simple spreadsheet listing every AI-enabled tool currently used across your business.
Include:
• the department using it
• the purpose of the system
• whether it influences decisions
• whether it touches any Annex III domain
• who internally owns it
That inventory becomes the foundation of your entire compliance process.
Further Reading
Annex III — High-Risk AI Systems
artificialintelligenceact.eu/annex/3
Article 5 — Prohibited AI Practices
artificialintelligenceact.eu/article/5
AI Act Explorer
artificialintelligenceact.eu/ai-act-explorer
#EUAIAct #AIGovernance #EnterpriseAI #ResponsibleAI #AICompliance