What risk class is my AI system?
Five questions, in this order. Each answer leads to a category of the AI Act and to a specific date. Checked against the Official Journal text on 1 August 2026.
The decision tree
1Is it an AI system in the sense of the regulation at all?
A machine-based system that operates with varying levels of autonomy and infers from its input how to generate outputs: predictions, content, recommendations or decisions. A spreadsheet with formulas is not one. A language model, an image classifier or a recommender engine is.
If not, the regulation does not apply and you stop here. If it does, go to question 2.
Art. 3(1)2Is it on the prohibited list in Article 5?
Eight grounds: subliminal or manipulative techniques; exploiting the vulnerability of a person or group; social scoring; assessing the risk of a person committing a criminal offence based on their profile; untargeted scraping of facial images; inferring emotions at work and in education; biometric categorisation by sensitive attributes; and real-time remote biometric identification in public spaces for law enforcement, outside the narrow exceptions. From 2 December 2026 two more are added: generating intimate imagery of identifiable people without their explicit consent, and child sexual abuse material.
If it fits, it is prohibited and there is no compliance path. If not, go to question 3.
Art. 5(1), (1a) and (1b)3Is it a safety component of an already regulated product?
Annex I lists Union harmonisation legislation: medical device, machinery, toy, lift, vehicle, radio equipment. If your AI is a safety component of such a product, or is that product, and requires third-party conformity assessment, it is high-risk via Annex I. The Omnibus clarified this: systems used solely for non-safety aspects such as usability or performance optimisation do not count as safety components.
If it fits: high-risk, deadline 2 August 2028. If not, go to question 4.
Art. 6(1) and (1a), Annex I4Does it fall into one of the eight areas of Annex III?
Biometrics; critical infrastructure; education and vocational training; employment, worker management and access to self-employment; access to essential services, public and private, including creditworthiness; law enforcement; migration, asylum and border control; administration of justice and democratic processes. Watch the filter in Article 6(3): if the system only performs a narrow procedural task, merely improves a previously completed human result, detects patterns without replacing human assessment, or performs a preparatory task, it may fall outside. With one hard limit: an Annex III system that performs profiling of natural persons is always high-risk, with no exception available. And a provider relying on the exemption must document that assessment before placing the system on the market.
If it fits and the exemption does not apply: high-risk, deadline 2 December 2027. If not, go to question 5.
Art. 6(2) and (3), Annex III5Does it interact with people or generate content?
Three cases: the system talks to people, a chatbot for instance; it generates or manipulates image, audio, video or text with external effect; or it performs emotion recognition or biometric categorisation. This does not depend on any risk class and catches companies with nothing in Annex III.
If it fits: transparency obligations from 2 August 2026. If none of the above applies: minimal risk, no product-specific obligations.
Art. 50What applies in every case
Whatever the category, Article 4 applies as soon as your organisation uses AI systems: you must take measures to support the development of AI literacy among your staff. Since the Omnibus this is a best-efforts obligation, not one of result, and it has applied since 2 February 2025. Article 4 carries no penalty of its own, so what matters is being able to evidence the measures taken.
The dates, with their article
| 2 February 2025 | Chapters I and II: AI literacy (Art. 4) and prohibitions (Art. 5) | Art. 113(3)(a) |
| 2 August 2025 | Governance, authorities and the penalty regime. Not postponed | Art. 113(3)(b) |
| 2 August 2026 | General application, in practice the transparency of Art. 50 | Art. 113, second paragraph |
| 2 December 2026 | New Art. 5 prohibitions and Art. 50(2) for pre-existing systems | Art. 113(3)(a); Art. 111(4) |
| 2 December 2027 | High-risk under Annex III | Art. 113(3)(c)(i) |
| 2 August 2028 | High-risk under Annex I | Art. 113(3)(c)(ii) |
Where most people get it wrong
Three recurring confusions. First, assuming supervision starts in August 2026; it has applied since August 2025. Second, treating Article 50 as minor because it is not high-risk; it catches far more companies than Annex III. Third, mixing up Article 50(2), a provider obligation with a transition until December 2026 for pre-existing systems, with paragraphs 1, 3 and 4, which fall on the deployer and have no transition.
Frequently asked questions
Is a customer service chatbot high-risk?
Does using ChatGPT or Copilot make me a provider?
Does the postponement to December 2027 cover everything?
Can an Annex III system still not be high-risk?
When the classification is not clear-cut
The most contested point is regularly the exemption in Article 6(3), because it requires documenting why an Annex III system is not high-risk after all. That assessment is exactly what an authority will want to see in writing.