The common EU AI Act risk pyramid is useful for orientation and poor as a final classification record. It can suggest that every system receives one permanent color. The Act instead asks questions about scope, prohibited practices, high-risk uses, transparency cases, general-purpose models, operator roles, and timing.

Use a decision tree for one system and intended purpose. Save the reasoning, source text, reviewer, and version. This framework requires legal validation.

Question 1: is the activity and system in scope?

Identify the machine-based system, how it infers outputs, the degree of autonomy and adaptation, and the output it produces. Use the Commission's AI-system-definition guidelines rather than treating every automation as AI.

Then review Article 2 scope. Record where the provider and deployer are established, where the system is placed on the market or used, and where its output is used. Note exclusions and special treatment for research, development, prototyping, military or personal activity only when the exact facts support them.

Question 2: does Article 5 prohibit the practice?

Screen the intended and reasonably foreseeable use against the current prohibited-practices list. A positive result is a stop-and-escalate decision, not a request for compensating controls.

The 2026 AI Omnibus added another prohibition and changed parts of the framework. Use the consolidated text and current Commission prohibited-practices guidance. Keep a prohibited-use register in system intake and contracts, then enforce the relevant limits in access and tool design.

Question 3: does Article 6 classify the system as high-risk?

Check both routes:

  1. an AI product or safety component covered by specified Annex I legislation and subject to third-party conformity assessment.
  2. an intended purpose listed in Annex III, subject to its conditions and applicable exclusions.

Write down the relationship between the output and the consequential decision. Profiling, ranking, recommendation, identification, or task allocation can matter depending on the category. Human oversight may be required and can reduce risk. It does not provide an automatic change of classification.

The separate high-risk systems guide covers this branch in detail.

Questions 4 and 5: do transparency or GPAI duties apply?

Article 50 contains several transparency cases. An AI system interacting directly with a person raises a different duty from a provider generating synthetic content or a deployer publishing a deepfake. Test each paragraph and its exceptions.

Then identify whether the organization provides a general-purpose AI model. Most enterprises using an external model will not be that model's provider, but they still need to assess the downstream AI system and their value-chain role. A company significantly modifying or developing a model needs a separate legal review under the current GPAI guidance.

These tracks can overlap with high-risk duties. The tree should allow more than one result.

Question 6: which other duties still apply?

A system outside prohibited, high-risk, or specified transparency cases is not outside every obligation. Operator-wide duties, contract terms, GDPR, employment law, consumer law, intellectual-property rules, cybersecurity duties, and internal governance may still apply.

Replace “minimal risk, no action” with a precise conclusion:

No high-risk or Article 50 category identified for version 1.3 under the stated internal briefing purpose. Provider and deployer roles recorded. Article 4 measures, GDPR assessment, supplier controls, and change monitoring continue. Reclassify before adding worker ranking or external publication.

Apply the tree to one Skybridge-supported system

Consider a hypothetical project-change brief used by event-production managers. The system reads approved project sources, flags conflicts, and prepares an internal draft. It cannot evaluate workers, make employment decisions, or send messages.

The classification record first confirms system scope and operator roles. It screens the use against Article 5 and Annex III, assesses whether the interface directly interacts with people under Article 50, records the upstream model provider, and lists other applicable duties. The named legal decision owner approves the conclusion.

Skybridge supplies technical facts such as the model route, user access, sources, tools, and release. The system's intended purpose comes from the contracted production perimeter. Classification needs both.

If the customer later adds freelancer ranking based on performance data, the old conclusion expires. The release process must route that purpose change to review before the feature reaches production.

The saved conclusion should be readable without reopening the whole legal file. A compact record can state: system version, intended purpose, affected people, output, operator roles, Article 5 result, Article 6 result, Article 50 result, GPAI dependency, remaining duties, legal reviewer, and review trigger. Link the supporting opinion and tests.

Keep separate fields for legal category and internal operational risk. A system outside a high-risk category can still be commercially sensitive, insecure, unreliable, or unsuitable for production. An organization may impose stricter internal controls where the consequence warrants them. The two assessments inform each other while retaining different meanings.

This separation also helps a board. Leaders can see which systems create regulatory duties and which create material business exposure without forcing both into one color.

Risk-classification questions

Is “limited-risk AI” a formal certificate?

No certificate follows from the label. Article 50 sets specified transparency duties for specified systems and uses. Record the exact paragraph and evidence.

Can one system have several AI Act duties?

Yes. Transparency duties can sit alongside high-risk requirements, and downstream system duties can coexist with upstream GPAI obligations.

How often should classification be repeated?

Review after material changes to purpose, people, data, output, model, authority, market, or law. Set these triggers in the system record.

Primary references

  1. Regulation (EU) 2024/1689, the Artificial Intelligence ActEUR-Lex
  2. Regulation (EU) 2026/1744, the 2026 AI OmnibusEUR-Lex
  3. AI Act regulatory framework and implementation timelineEuropean Commission
  4. Guidelines for providers and deployers of AI high-risk systemsEuropean Commission

Continue reading: EU AI Act 2026: What Businesses Must Do Now.