Is Your AI Product High-Risk Under the EU AI Act? A Quick Self-Assessment
Every AI Act conversation I have with a founder lands on the same question: “So, are we high-risk or not?”
It’s the right question. Classification is the first domino. Your documentation burden, your deadlines, and whether the Act meaningfully applies to you at all depend on this one legal determination. Here is the short version of the walk-through I use with clients.
The map: four tiers
| Tier | What it means | Key date |
|---|---|---|
| Prohibited | Banned outright | In force since Feb 2025 |
| High-risk | Heavy obligations, conformity assessment | Dec 2, 2027 (standalone) / Aug 2, 2028 (in products) |
| Transparency tier | Disclosure duties for chatbots and AI-generated content | Dec 2, 2026 |
| Minimal risk | No new obligations | None |
Step 1: Are you in scope at all?
The Act covers providers (you develop or brand the system) and deployers (you use it professionally). Two traps hide here. First, you don’t need an EU office to be covered: if your system or even its output is used in the EU, you’re in. Second, if you substantially modify a general-purpose model or ship it under your own brand, you can become a provider with a provider’s obligations. “We build on OpenAI” is a supply-chain position, not an exemption.
Step 2: Rule out the banned category
Prohibited practices have applied since February 2025: social scoring, exploitative manipulation, untargeted facial-image scraping, emotion recognition at work and in schools, and a few others. Most products clear this screen quickly, but clear it in writing.
Step 3: The high-risk test
There are two doors into high-risk status.
Door A: your AI is a safety component of a regulated product (medical devices, machinery, toys and similar). Your deadline is August 2, 2028.
Door B: your system operates in one of the Annex III areas. The list includes biometrics, critical infrastructure, education, employment and HR tools, credit scoring and insurance pricing, law enforcement, migration, and justice. Deadline: December 2, 2027.
Notice how ordinary some of these sound. An HR tool ranking candidates, a fintech scoring loans, an ed-tech platform grading students: that’s the centre of Annex III, not an edge case.
There is an escape hatch. If your system only does narrow procedural or preparatory work in those areas, without materially influencing decisions, it can avoid high-risk status. But you must document that assessment. An undocumented “we decided we’re fine” is worth the paper it isn’t written on.
Step 4: The deadline nobody’s watching
Not high-risk? If your product includes a chatbot people could mistake for a human, or generates text, images, audio or video, disclosure and content-marking duties apply from December 2, 2026. That’s months away, and it covers a large share of today’s AI products.
What to do with your result
If you’re plausibly high-risk, start the gap assessment this year: the obligations realistically take 12 to 18 months to build, and December 2027 is one funding cycle away. If you’re transparency tier, scope the work now and ship it by autumn. If you’re minimal risk, write down why in a short dated memo. That memo is what turns “we think we’re fine” into an answer that satisfies enterprise procurement in one email.
This article is general information, not legal advice on your specific system. Mike Nimród is an IT and data protection lawyer (AIGP, CIPT, CIPP) and researcher at Corvinus University of Budapest. If you want your classification answered properly, by a human and not a prompt, get in touch.