WHAT EXACTLY IS THE AI SYSTEM?
Start by defining the system boundary, intended purpose, model dependencies, product integration, version, deployment context, and what decisions or outputs the system can produce.
Before building a compliance program, classify the actual system. EU AI Act obligations depend on intended purpose, operator role, product context, use case, territorial scope and the facts supporting each classification route.
The Commission describes the AI Act as risk-based and confirms that only a limited set of systems are classified as high-risk. Current Commission guidance supports practical Article 6 classification, but the Regulation itself remains the controlling legal text.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
Start by defining the system boundary, intended purpose, model dependencies, product integration, version, deployment context, and what decisions or outputs the system can produce.
Determine whether you are acting as provider, deployer, importer, distributor, product manufacturer, GPAI provider, or another operator. Different roles carry different duties.
Check prohibited practices, high-risk routes under Article 6 and Annex I/III, transparency duties under Article 50, GPAI obligations, and other relevant system-specific requirements.
Preserve the evidence supporting intended purpose, actor role, use case, exclusions, customer context, product category, and any Article 6(3) assessment. Classification should be reviewable, not just asserted.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
Do not classify a vendor name or a generic technology category. Classify the actual AI system as placed on the market or used in the organization.
Establish who develops, brands, places, imports, distributes or deploys the system and whether the EU AI Act’s territorial scope is engaged.
Evaluate prohibited-use rules, Article 6 high-risk criteria, Annex III use cases, Article 50 transparency obligations, GPAI layers and any applicable exclusions or special conditions.
Keep the facts, evidence, version and source state that support the result. Re-run classification after material changes to intended purpose, model, workflow, authority, market exposure or legal guidance.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
START EVIDENCE PASSPORT →Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.
START COMPLIANCE WORKSPACE →Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.
START GOVERNANCE PRO →Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.
START INSTITUTION →Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
The Act uses a risk-based and obligation-based structure. Some practices are prohibited, some systems are high-risk under Article 6 and Annex I or Annex III, some are subject to transparency obligations, and many systems carry limited or minimal regulatory burden under the Act.
No. The practical classification is more nuanced. A system may be prohibited for a particular use, high-risk, subject mainly to transparency duties, affected by GPAI obligations at another layer, or fall outside those categories while still being subject to other legal duties.
Article 6 identifies high-risk systems connected to certain regulated products in Annex I and systems used for certain sensitive purposes listed in Annex III. The Commission has also published current guidance and examples to support practical classification.
In limited circumstances, yes. Article 6(3) provides conditions under which some Annex III systems may not be considered high-risk where they do not pose a significant risk of harm. Providers relying on that route must document the assessment before market placement or putting into service.
Yes. Article 50 transparency obligations can apply to certain systems that interact directly with people or generate or manipulate content, independently of high-risk classification.
No. It provides a structured governance classification pathway based on the facts supplied. It does not replace legal advice, conformity assessment, certification or regulatory authority.
TA-14 Exchange Activity
Live cumulative activity recorded across the public Exchange surface.
···
Visitors
Recorded public visitors
···
Page Views
Recorded Exchange views