How businesses can correctly classify their AI systems under the AI Act — while deliberately minimizing regulatory, ethical, and security-related risks.

What Is a Risk Analysis in the Context of the AI Act?

Risk analysis is the foundation of any AI compliance effort under the AI Act. It's used to systematically assess what dangers an AI system poses to people, society, and fundamental rights — for example, discrimination, lack of transparency, faulty decisions, or power imbalances.
It includes, among other things:

  • Identifying risks: What harm could occur, and to whom?
    Assessing probability and impact: How severe is the risk?
  • Assessing the risk class: Which category does the system fall into under the AI Act?
  • Deriving protective measures: What concrete steps do we take to minimize risks?

Example: An HR tool that automatically pre-sorts candidate profiles could systematically disadvantage people based on age, origin, or gender — without any malicious intent, but with serious consequences. Risk analysis identifies and addresses such issues early on.
 

Why Classifying AI Systems Matters

The risk classification determines everything that follows:

  • What obligations do I have to meet (transparency, audits, documentation)?
  • What technical and organizational measures do I need?
  • How do I prove to authorities and partners that my system is operated responsibly?

Correct classification prevents:

  • Fines and liability risks
  • Reputational damage from misconduct
  • Wasted investment in systems that later turn out to be non-approvable

In short: Without a clear classification, there's no safe future for AI systems in your business.

The AI Act's Four Risk Classes at a Glance

The AI Act sorts AI systems into four categories — based on their area of use, impact on people, and potential danger:

1. Unacceptable Risk

Prohibited applications, for example:

  • Social scoring systems
  • Emotion recognition in the workplace or in schools
  • Covert manipulation of behavior

→ May not be used in the EU.

2. High Risk

Areas of use with a significant impact on human rights or safety, for example:

  • Biometric identification
  • Creditworthiness checks
  • HR decisions
  • Critical infrastructure

→ Strict requirements for documentation, data quality, monitoring, and human oversight.

3. Limited Risk

Systems that don't decisively interfere with fundamental rights, but that trigger transparency obligations, for example:

  • Chatbots
  • AI-based recommendation systems

→ Users must be able to recognize that they're interacting with AI.

4. Minimal Risk

For example, spam filters, AI text recognition, or spellcheckers.
→ No concrete obligations, but voluntary standards and best practices are recommended.

Key Components of the EU AI Act for Risk Analysis

According to the EU AI Act, the following aspects are central to conducting a legally compliant risk analysis:

  • Purpose-specific system description: What is the system meant to do? For whom?
  • Analysis of the data foundation: Where does the training data come from, and how was it prepared?
  • Model behavior & result interpretation: Are the results traceable and fair?
  • Technical security: How is the system protected against manipulation or malfunction?
  • Governance & control: Who's responsible, and how is operation organized?

→ Also required: comprehensive documentation, e.g., technical documents, risk reports, and audit logs — especially for high-risk systems.

Methods for Conducting an Effective Risk Analysis

Depending on company size and system type, different methods can be combined. Recommended approaches include:

  • Scenario analysis: What happens if the system makes a wrong decision? Who's affected?
  • FMEA (Failure Mode and Effects Analysis): What failures could occur, and how severe would the consequences be?
  • FTA (Fault Tree Analysis): A visual breakdown of failure chains and cause-and-effect relationships
  • AI Impact Assessment / DPIA: Data Protection Impact Assessment (particularly for personal data)
  • Questionnaire-based self-assessment: Templates and tools help with structured initial evaluations

Tools like the heyData AI Compliance Tool or open-source frameworks (e.g., from the OECD or NIST) offer practical templates for businesses.

Challenges and Solutions in Classifying AI Systems

Challenges:

  • Rapid technological development: risk can shift with new features
  • Borderline cases in classification: not every system can be clearly categorized
  • Lack of internal expertise: especially at mid-sized companies without an in-house AI specialist

Solutions:

  • Developing an internal AI governance process
  • Setting up an AI classification team spanning tech, legal, and ethics
  • Using regularly updated assessment guides and tools
  • Working with specialized compliance partners like heyData

Practical Example: How to Analyze an AI System Step by Step

Case: an AI-powered application-screening tool for SMEs

  1. System definition
    → Automates the pre-selection of candidate profiles based on résumés
  2. Risk identification
    → Potential discrimination based on gender, origin, or age
    → Opaque rejection criteria
  3. Classification under the AI Act
    → High-risk system (HR decisions under Annex III)
  4. Risk assessment
    → What criteria does the model use?
    → How traceable are the decisions?
  5. Risk mitigation measures
    → Human-in-the-loop review
    → Fairness audits of the training data
    → Documentation & regular model review
  6. Monitoring & reporting
    → Using a monitoring dashboard
    → Mandatory documentation for regulators
     

Best Practices for AI Act Compliance

  • Start early
    Embed risk analysis into product development from the outset (privacy & ethics by design)
  • Document instead of improvise
    Every AI system should have a "digital risk dossier"
  • Train your team
    Build understanding of compliance, ethical principles, and classification criteria
  • Bring in outside expertise
    Especially for high-risk systems, an external perspective pays off
  • Connect technology and compliance
    Involve tech teams in regulatory responsibility (DevOps → DevComOps)

Conclusion: Risk-Based Compliance Is the Key to Responsible AI

The future of AI in Europe depends on trust — and trust only comes from transparency and security. The AI Act sets clear guardrails. Businesses that analyze, document, and continuously monitor their systems in a structured way are on the safe side.

Classification isn't just a bureaucratic exercise — it's a strategic tool. It protects against missteps, strengthens product quality, and builds trust with customers, partners, and regulators.

Businesses that act now don't just gain legal certainty — they gain a real competitive edge.