Product teams launch AI features faster than legal teams can classify them. A customer support AI chatbot that routes tickets looks low risk until it influences credit decisions. A AI transcription tool that summarizes HR interviews may fall under employment-related high-risk categories. Without a consistent classification method, governance becomes reactive and audit evidence arrives too late.
High-risk AI use case classification maps each internal deployment to regulatory tiers defined by the EU AI Act, starting with Article 6 high-risk determinations and Annex III category references, then layering your internal taxonomy for documentation depth and legal escalation. This guide helps compliance, product, and platform owners classify use cases now rather than waiting for final national enforcement guidance.
Regulatory Tier Definitions
The EU AI Act organizes AI systems into four practical tiers for deployers: prohibited practices, high-risk systems under Article 6, limited-risk transparency obligations, and minimal-risk systems with no specific AI Act requirements. Your internal register should use the same vocabulary regulators use so evidence maps cleanly to external filings and customer questionnaires.
| Tier | EU AI Act basis | Deployer action |
|---|---|---|
| Prohibited | Article 5 banned practices | Do not deploy; document ban and monitoring |
| High-risk | Article 6 plus Annex III categories | Full conformity workflow, registration, oversight logs |
| Limited risk | Transparency obligations (e.g., chatbot disclosure) | User notices, labeling, interaction design |
| Minimal risk | No specific AI Act deployer duties | Internal policy baseline, inventory entry |
Article 6 High-Risk Triggers
Article 6 classifies AI as high-risk when it is a safety component of a regulated product, appears on the Annex III list in specified contexts, or when profiling of natural persons occurs in Annex III use cases. Many SaaS tools your organization deploys are not high-risk in isolation but become high-risk when embedded in Annex III workflows. Classification must describe the full decision chain, not just the vendor product category.
Prohibited Practices Screen
Run every proposed use case through an Article 5 screen before tier assignment: social scoring by public authorities, exploitative manipulation, certain real-time biometric identification in public spaces, emotion inference in workplaces and education, biometric categorization to infer sensitive attributes, and scraping of facial images from the internet or CCTV for recognition databases. A prohibited classification ends the evaluation. Document the rejection rationale for audit trails if business units resubmit similar ideas.
Annex III Eight Categories
Annex III lists eight high-risk domains; map each internal use case to the closest category and record whether your deployment meets the contextual conditions described in each Annex III paragraph. Legal counsel should validate final mappings. Product teams supply factual descriptions of inputs, outputs, and decision impact.
| Annex III area | Example internal use cases | Classification notes |
|---|---|---|
| 1. Biometrics | Identity verification, access control matching | Distinguish one-to-one verification from identification |
| 2. Critical infrastructure | Grid load forecasting, pipeline anomaly detection | Applies when AI is safety component of regulated infra |
| 3. Education and training | Automated exam scoring, admission ranking assists | Human-only drafting may still be limited risk |
| 4. Employment | Resume screening, interview analysis, shift scheduling | Transcription of hiring calls can trigger this category |
| 5. Essential services | Creditworthiness, insurance pricing, emergency dispatch triage | Chatbots that gate access to services need careful review |
| 6. Law enforcement | Risk scoring for investigations, evidence prioritization | Typically public-sector; vendors may still assist |
| 7. Migration and border | Visa eligibility assists, document authenticity checks | Government deployers; contractors map subprocessors |
| 8. Justice and democracy | Judicial research assists, influence operation detection | High scrutiny; legal must lead classification |
Contextual Conditions
Annex III high-risk status often depends on context: whether the AI materially influences outcomes for natural persons, whether significant harm is possible, and whether the use case falls within the Annex paragraph scope. A general-purpose AI chatbot for FAQ deflection is typically limited risk. The same model recommending loan denials without meaningful human review may be high-risk under essential services categories.
Internal Use Case Taxonomy
Build an internal taxonomy with three layers: business domain, AI function (generate, classify, rank, recommend, transcribe), and decision impact (informational, advisory, automated with human review, automated binding). Regulatory tier assignment sits on top of this taxonomy. Consistent labels let you search the inventory when Annex III guidance updates or when new case law emerges.
- Domain: HR, finance, customer support, product engineering, legal, operations.
- Function: summarization, extraction, scoring, generation, translation, transcription.
- Data subjects: employees, customers, applicants, patients, minors, general public.
- Decision impact: none, suggest-only, human approves, auto-executes with override window.
- Geography: EU deployers, US-only, global with EU data subjects.
Classification Worksheet
Each worksheet row captures use case ID, plain-language description, Annex III category candidate, Article 5 screen result, proposed tier, evidence links, and reviewer sign-off. Product managers complete factual fields; compliance assigns tier; legal resolves disputes. Block production launch in change management until the worksheet status is approved or explicitly accepted as provisional with a remediation date.
Edge Cases and Dual Use
One vendor subscription may power multiple use cases at different tiers; classify each use case separately rather than inheriting the vendor's marketing category. AI transcription for public podcast production differs from transcription that feeds automated performance ratings. Dual-use tools need guardrails (separate workspaces, data boundaries, feature flags) documented in the classification record.
Documentation Requirements Per Tier
Documentation depth scales with tier: minimal-risk entries need inventory metadata; limited-risk adds transparency artifacts; high-risk requires conformity assessments, risk management systems, data governance, logging, human oversight procedures, and registration preparation. Prohibited use cases require a written ban reference and monitoring plan for policy violations.
| Tier | Required documentation | Review cadence |
|---|---|---|
| Minimal | Inventory entry, owner, data class, vendor model version | Annual attestation |
| Limited | User disclosure text, UI mockups, training for staff | Semi-annual or on material UI change |
| High-risk | DPIA, oversight logs, bias testing, incident playbooks, Article 49 draft | Quarterly council review minimum |
| Prohibited | Policy citation, alternative approved path, detection controls | Continuous monitoring |
Linking to Inventory
Store classification worksheets as evidence attachments on the AI tool inventory register entry so auditors trace from system catalog to regulatory tier in one click. When tier changes, version the worksheet and trigger downstream updates to oversight sampling rates, retention schedules, and vendor contract clauses.
Legal Review Escalation Paths
Escalate to legal when any use case is candidate high-risk, processes special category personal data, affects legally protected decisions, or spans jurisdictions with conflicting AI rules. Define SLAs: provisional tier within five business days for pilots, final tier before production traffic. Emergency launches require documented exception with executive sponsor and remediation deadline.
- Product submits classification worksheet with factual use case narrative.
- Privacy reviews data categories and DPIA need.
- Compliance maps Annex III and Article 5 results.
- Legal issues written tier opinion for high-risk and disputed cases.
- Governance council records disputes and exception approvals in minutes.
Reclassification Triggers
Reclassify when scope expands (new user population, new data type, new automated decision), when vendor model capabilities change materially, or when regulator guidance narrows Annex III exceptions. Model upgrades that improve persuasion or scoring accuracy can bump a limited-risk chat interface into high-risk territory if it starts ranking applicants or credit applicants without process changes you documented.
Customer and Audit Requests
Enterprise customers increasingly ask for tier summaries per subprocessors; export classification worksheets redacted for confidential decision logic but showing tier, Annex III mapping, and oversight summary. Prepare a standard appendix mapping your taxonomy to EU AI Act vocabulary to reduce bespoke questionnaire cycles.
Frequently Asked Questions
Should we wait for final enforcement dates before classifying?
No. Classify now using published text of the EU AI Act and Annex III; treat national guidance as refinements that may adjust edge cases but rarely eliminate inventory obligation. Early classification surfaces prohibited ideas before engineering investment and prepares high-risk documentation lead times measured in months.
How do GPAI provider obligations differ from deployer obligations?
General-purpose AI model providers face transparency, copyright, and systemic risk duties under the GPAI chapter; deployers remain responsible for how they integrate models into Annex III workflows and for human oversight, logging, and registration when their use case is high-risk. Your classification worksheet should list both vendor role and your organization as deployer. Contract reviews should allocate conformity evidence requests to the party best positioned to supply them.
Can one AI tool appear at multiple tiers?
Yes. Classify each use case separately; the same AI chatbot platform may be minimal risk for internal IT FAQs and limited risk for customer-facing support with disclosure obligations. Inventory systems should support multiple use case rows per vendor subscription.
Do non-EU companies need Annex III mapping?
If you offer AI-affected products or services to EU residents or deploy AI in the EU, Annex III analysis applies regardless of headquarters location; many multinationals adopt EU tiers globally for consistency. US sector rules (EEOC, FTC, state laws) may impose parallel classification labels.
Limited-Risk Transparency Obligations
Limited-risk systems under the EU AI Act include AI that interacts directly with natural persons without high-risk classification, such as chatbots and certain emotion recognition systems outside prohibited contexts. Deployers must ensure users know they interact with AI unless obvious from context. Classification worksheets should note required disclosure copy, UI placement, and accessibility of notices for screen reader users.
A customer-facing AI chatbot that deflects support tickets typically lands here when it does not materially determine access to essential services. Document the transparency artifact version linked to the inventory entry. Re-evaluate when the chatbot gains payment handling or account closure recommendations that could shift tier upward.
Transcription and Limited-Risk Boundaries
Pure transcription without automated decision-making often remains minimal or limited risk, but AI transcription pipelines that feed scoring, discipline, or performance systems inherit the tier of the downstream decision. Map the full data flow on the classification worksheet, not only the transcription SaaS category. Legal escalation triggers when transcripts contain special category data or minors.
GPAI and Downstream Modification
When your use case builds on general-purpose AI with retrieval augmentation, fine-tuning, or agentic tool chains, classification must address whether modifications create substantial new risk beyond the base model. Document RAG corpora sensitivity, tool permissions (database write, email send), and autonomy level. A GPAI chat wrapper with read-only FAQ retrieval differs from an agent that files insurance claims.
- Base model provider tier obligations: transparency docs, systemic risk for largest models.
- Your deployer tier: driven by Annex III use case, not model size alone.
- Fine-tunes on proprietary data: update inventory and reassess if training data shifts decision boundaries.
- Agent tools: each tool permission may introduce high-risk adjacent behavior.
Multi-Jurisdiction Labels
Organizations operating globally may maintain parallel labels (EU high-risk, US state algorithmic accountability, sector-specific FDA or medical device classifications) on the same worksheet row. A single use case can be minimal in one jurisdiction and high in another. Customer contracts may reference EU tiers even for US-only deployments when buyers are EU entities.
Training and Operating Rhythm
Train product managers, engineering leads, and procurement on classification triggers during onboarding and refresh annually. Include worked examples from your industry: approved limited-risk chatbot, rejected prohibited social scoring idea, escalated employment screening assist. Workshops beat policy PDFs nobody reads.
Run classification office hours monthly for teams designing pilots. Early engagement prevents demo-to-production launches without worksheets. Track metrics: time from pilot proposal to tier decision, percentage of production systems with current classification, count of disputed tiers resolved by council.
Integration With Vendor Due Diligence
Procurement questionnaires should ask vendors to describe intended Annex III adjacency, not only SOC 2 status. A vendor marketing "HR AI" expects employment category scrutiny. Capture vendor answers as attachments on the classification worksheet before contract signature. Mismatch between vendor claims and your actual use case is a recurring audit finding.
Implementation Roadmap
Month one: publish tier definitions and Article 5 screen; month two: classify all production use cases with worksheets; month three: close documentation gaps per tier and train product managers on the taxonomy. Revisit quarterly as enforcement milestones approach. Classification is a living process, not a one-time legal memo archived in email.
Quarter four and beyond: automate worksheet submission in your service catalog, link classification status to deployment pipelines, and publish executive dashboards showing tier distribution and overdue reclassifications. Boards increasingly request AI risk summaries; classification data feeds those reports without manual rework each quarter.
Worksheet Template Fields
A complete classification worksheet includes: use case ID, business owner, plain-language description, data subjects affected, automated versus advisory role, Annex III category analysis, Article 5 screen result, proposed tier, documentation checklist status, legal reviewer, review date, and next reclassification trigger. Optional fields capture vendor model, integration type, geographic scope, and linked DPIA ID. Standard templates prevent each product manager from inventing incompatible formats.
Store worksheets in your GRC platform with version history. When legal opinion changes tier, retain prior versions showing evolution of understanding. Auditors appreciate transparent correction more than silent relabeling after incidents.
Common Classification Mistakes
Teams routinely under-classify by describing tools instead of decisions, over-classify to avoid paperwork, or copy vendor marketing tiers without legal validation. Another failure mode is classifying at procurement time but never updating when product teams expand scope. Governance councils should review a quarterly sample of "minimal risk" systems for scope creep into Annex III territories.
- Tool-centric labels: "We use GPT" tells auditors nothing about hiring impact.
- Assuming SaaS vendor conformity covers deployer duties for your integration.
- Treating internal-only deployment as automatically minimal when employees are data subjects.
- Ignoring third-party plugins that add biometric or scoring capabilities to base chat products.
Documentation Samples for Customers
Prepare redacted classification summaries for enterprise security reviews: tier, Annex III mapping rationale, oversight model, and last review date without exposing confidential decision logic. Consistent customer-facing language reduces bespoke questionnaire cycles and demonstrates mature AI governance to procurement teams evaluating your organization as vendor or partner.
Classify Early, Document Proportionately
High-risk AI use case classification succeeds when teams map every deployment to prohibited, high-risk, limited, or minimal tiers using Article 6 and Annex III references, maintain an internal taxonomy for decision impact, scale documentation to tier, escalate legal review on schedule, and distinguish GPAI provider duties from deployer accountability. Start with honest use case descriptions; regulators and customers reward clarity over optimistic labeling.