How to approach prohibited practices, high-risk AI, transparency obligations and lower-risk uses without assuming a label from a single feature.
Prohibited practices
Article 5 identifies specific unacceptable uses. Review the exact legal wording and official guidance before deciding whether a practice falls within a prohibition.
Read the regulation ↗High-risk systems
Certain product safety components and specified use cases can be high-risk. Classification turns on intended purpose, the applicable Annex and relevant conditions, not on whether a system seems “powerful”.
Examine high-risk guidance ↗Transparency and lower-risk uses
Specific situations, including some human interaction and synthetic content, trigger disclosure or marking rules. Many other AI uses do not carry the high-risk system requirements, though other laws and internal governance can still matter.
How to screen a use case
Write down the task the system is intended to perform, the people affected and the environment in which it operates. Test Article 5 first, then Article 6 and the relevant Annex I or Annex III pathway. Assess Article 50 separately, along with any general-purpose model role. A broad industry label is not enough: an education provider may use AI for several unrelated purposes with different treatment.
- Purpose and affected group
- Prohibition screen
- High-risk route and relevant Annex
- Transparency and model-provider questions
When is an Annex III system not high-risk?
Article 6 includes a narrow route under which a listed Annex III system may not be treated as high-risk if it does not pose a significant risk of harm and performs specified limited tasks. The Act sets documentation and registration consequences, and profiling of natural persons changes the analysis. This is not a blanket exemption for low-impact claims. Review the full conditions and record a defensible rationale before relying on it.
Read Article 6 classification rules ↗What about “minimal risk”?
Minimal risk is a useful explanatory phrase, but it is not a universal legal category that switches off every other law. A system outside the high-risk route may still face a targeted transparency duty, data protection requirements, consumer rules, employment law or contractual controls. Conversely, a powerful model is not automatically a high-risk system merely because it has broad capability. State which provision was considered and why.
Review transparency situations ↗Keep a decision record
A useful classification record names the version of the system, intended purpose, deployment geography, relevant provision, evidence examined, conclusion, reviewer and revisit trigger. Reassess when the purpose, users, model behaviour or integration changes. If the system is a high-risk candidate, continue to the provider and deployer duties rather than treating the classification label as the final action.
Plan a high-risk assessment ↗This guide is an orientation, not a legal determination. Check the current legal text and official implementation guidance for your system.
Read the AI Act ↗European Commission overview ↗