AI Act risk classes, classification step by step
Prohibited, high risk, transparency risk or minimal risk. This guide follows the order in Regulation (EU) 2024/1689, with the article and reviewed matrix row supporting each step.
Short answer
Which AI Act risk class applies to an AI system?
NovaCopilot tests the system in the order used by Regulation (EU) 2024/1689. It starts with prohibited practices, then high risk, transparency duties and general-purpose models with systemic risk. What remains is commonly described as minimal risk. Every reviewed step carries its article and reading date.
Regulation (EU) 2024/1689
A source reference, not legal advice.
Classification order
- Start with the prohibitions. A practice listed in Chapter II cannot be made lawful through procedures or consent.
- Then test whether the system falls within a high-risk area or is a safety component of a regulated product.
- Test the transparency duties. Some systems are not high risk but must disclose that a person is interacting with AI.
- Determine whether a general-purpose model is involved and whether it carries systemic risk.
- Document any remaining minimal-risk conclusion, including the reasoning and sources used.
Risk rows in the matrix
- R1prohibited practicesprohibited practicesArticle 5
Chapter II identifies the prohibited practices.
- R2high riskhigh-risk systems under Annex IIIArticle 6
Article 6 determines when a system is classified as high risk.
- R3transparency risktransparency duties under Chapter IVArticle 50
Chapter IV sets the transparency duties for certain AI systems.
- R4systemic riskgeneral-purpose model with systemic riskArticle 55
Article 55 sets the additional duties for systemic-risk models in Chapter V.
- R5minimal risknot yet read
Minimal risk has no separate legal basis in the Regulation.
What each class leads to
- Prohibited
- The practice must stop. Compliance measures cannot make it lawful
- High risk
- Risk management, data governance, documentation, logging, robustness and assessment
- Transparency risk
- Disclosure duties towards people interacting with the system
- Systemic risk
- Additional model duties beyond the general model requirements
- Minimal risk
- No specific mandatory duties, but the assessment should be documented
Machine surfaces for the same assessment
- Risk-class simulator/api/public/v1/ai-act/simulate
- Run by role/api/public/v1/ai-act/agent/run?role=provider&system_type=high-risk-system
- Verification view/api/public/v1/ai-act/agent/verify
- Derived data points/api/public/v1/open/derived?dimension=risk-class&act=ai-act
Related pages
Reservation
This material supports compliance work and is not legal advice. The official wording prevails over every derived row.
Ready-made pack
AI Act compliance pack
€199, one-time purchase
The AI Act as working material: the articles, the high-risk requirements, the documentation duties and a structure for the risk assessment.
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.