# HIGH-RISK AI SYSTEM CLASSIFICATION AND DECLARATION FORM

**Document code:** AIA-CLS-02 · **Version:** 1.0 · **Basis:** Regulation (EU) 2024/1689
**Assessment date:** ……/……/20……  ·  **Reassessment:** on every substantial modification

> Complete a **separate** form for each AI system. Where a system has more than
> one intended purpose, assess each intended purpose separately.

---

## PART A — SYSTEM RECORD

| Field | Value |
|---|---|
| A.1 System name / version | [……] |
| A.2 Intended purpose | [……] |
| A.3 Reasonably foreseeable misuse | [……] |
| A.4 Upstream technical provider | [……] |
| A.5 Model type (GPAI / bespoke / rule-based) | [……] |
| A.6 Geography where output is used | [……] |
| A.7 Effect on the decision | ☐ Determinative ☐ Advisory ☐ Preparatory |
| A.8 Human oversight in place | ☐ Yes ☐ No ☐ Partial |

---

## PART B — TERRITORIAL SCOPE

**B.1** Do you place the system on the EU market under your own name or brand? ☐ Y ☐ N
**B.2** Does the company have a branch/subsidiary/commercial presence in the EU? ☐ Y ☐ N
**B.3** Is the **output** of the system used within the EU? ☐ Y ☐ N
  → *Art. 2(1)(c). Establishment in a third country does not, on its own, place
  you outside scope.*

**B.4 Result:** If any of B.1–B.3 is "Yes", you are within scope. ☐ In scope ☐ Out of scope

**B.5 Justification (mandatory):** [……]

---

## PART C — ROLE DETERMINATION

| Role | Test | Result |
|---|---|---|
| C.1 Provider | You develop the system and place it under your own name/brand — Art. 3(3) | ☐ |
| C.2 Deployer | You use the system under your own authority — Art. 3(4) | ☐ |
| C.3 **Deemed** provider | One of the following has occurred — Art. 25 | ☐ |

**C.3 breakdown — circumstances triggering deemed-provider status under Art. 25:**
- **C.3.A** You place a third party's high-risk system on the market **under
  your own name or trademark**;
- **C.3.B** You make a **substantial modification** to a high-risk system
  already on the market;
- **C.3.C** You modify the **intended purpose** of a system that was not
  high-risk in such a way that it becomes high-risk.

> A significant share of white-labelled AI products fall under C.3.A without
> realising it. An incorrect role determination invalidates every subsequent part.

**C.4 Role determined:** [……] **Justification:** [……]

---

## PART D — PROHIBITED PRACTICE SCREEN (Art. 5)

If any answer below is "Yes", the system **may not be placed on the market**.

- **D.1** Subliminal or manipulative techniques materially distorting behaviour ☐ Y ☐ N
- **D.2** Exploitation of vulnerability due to age, disability or socioeconomic
  situation ☐ Y ☐ N
- **D.3** Social scoring ☐ Y ☐ N
- **D.4** Criminal-offence risk prediction based solely on profiling ☐ Y ☐ N
- **D.5** Untargeted scraping of facial images from the internet or CCTV to build
  databases ☐ Y ☐ N
- **D.6** Emotion recognition in the workplace or education ☐ Y ☐ N
- **D.7** Biometric categorisation inferring sensitive attributes ☐ Y ☐ N
- **D.8** Real-time remote biometric identification in publicly accessible spaces
  (exceptions reserved) ☐ Y ☐ N

**D.9 Result:** ☐ No prohibited practice ☐ **STOP — falls under Art. 5**

---

## PART E — HIGH-RISK CLASSIFICATION

### E.1 Product-safety route (Art. 6(1))

- **E.1.A** Is the system a safety component of, or itself, a product covered by
  the Annex I harmonisation legislation? ☐ Y ☐ N
- **E.1.B** Is third-party conformity assessment required for that product? ☐ Y ☐ N

→ If both are "Yes", the system is **high-risk**.

### E.2 Annex III route (Art. 6(2))

Is the system used in one of the following areas?

- **E.2.1** Biometrics (to the extent permitted) ☐
- **E.2.2** Critical infrastructure ☐
- **E.2.3** Education and vocational training ☐
- **E.2.4** Employment, worker management, access to self-employment ☐
- **E.2.5** Access to essential private and public services and benefits
  (including creditworthiness and health/life insurance pricing) ☐
- **E.2.6** Law enforcement ☐
- **E.2.7** Migration, asylum and border control ☐
- **E.2.8** Administration of justice and democratic processes ☐

### E.3 Derogation assessment (Art. 6(3))

A system within Annex III may nonetheless not be high-risk where it does not
materially influence the outcome of decision-making and falls within one of:

- **E.3.A** Performing a narrow procedural task;
- **E.3.B** Improving the result of a previously completed human activity;
- **E.3.C** Detecting decision-making patterns without being meant to replace or
  influence the human assessment absent proper human review;
- **E.3.D** Performing a preparatory task.

> **E.3.E — Absolute limit.** Where the system performs **profiling of natural
> persons**, the derogation is unavailable and the system is high-risk in all
> cases.

**E.3.F — If relying on the derogation:** the assessment must be documented
**before** the system is placed on the market, and a registration obligation
arises (Art. 6(4), Art. 49(2)). A derogation without written reasoning is not a
derogation.

**E.4 CLASSIFICATION RESULT:**
☐ High-risk ☐ Not high-risk (Art. 6(3) derogation — reasoning attached)
☐ Limited risk (Art. 50 transparency only) ☐ Minimal risk

**E.5 Justification (mandatory):** [……]

---

## PART F — IF HIGH-RISK: OBLIGATION CHECKLIST

| # | Obligation | Basis | Status |
|---|---|---|---|
| F.1 | Risk management system | Art. 9 | ☐ |
| F.2 | Data governance and data-set quality | Art. 10 | ☐ |
| F.3 | Technical documentation | Art. 11 + Annex IV | ☐ |
| F.4 | Automatic record-keeping (logging) | Art. 12 | ☐ |
| F.5 | Transparency and instructions for deployers | Art. 13 | ☐ |
| F.6 | Human oversight by design | Art. 14 | ☐ |
| F.7 | Accuracy, robustness, cybersecurity | Art. 15 | ☐ |
| F.8 | Quality management system | Art. 17 | ☐ |
| F.9 | Conformity assessment | Art. 43 | ☐ |
| F.10 | EU declaration of conformity | Art. 47 | ☐ |
| F.11 | CE marking | Art. 48 | ☐ |
| F.12 | Registration in the EU database | Art. 49 | ☐ |
| F.13 | Post-market monitoring | Art. 72 | ☐ |
| F.14 | Serious incident reporting | Art. 73 | ☐ |

**If you are a deployer:** the obligations under Art. 26 and — where applicable —
the fundamental rights impact assessment under Art. 27 must be assessed separately.

---

## PART G — TRANSPARENCY OBLIGATIONS (Art. 50)

These apply **irrespective of risk class**:

- **G.1** Direct interaction with a natural person → disclosure (Art. 50(1)) ☐
- **G.2** Synthetic content → machine-readable marking (Art. 50(2)) ☐
- **G.3** Emotion recognition / biometric categorisation → notification (Art. 50(3)) ☐
- **G.4** Deepfakes and public-interest text → disclosure (Art. 50(4)) ☐
- **G.5** Timing: at the latest at the first interaction (Art. 50(5)) ☐

---

## PART H — ADMINISTRATIVE FINE THRESHOLDS (Art. 99)

The ceiling depends on **which provision is infringed**. Using the correct
threshold is decisive for the accuracy of the risk assessment.

| Infringement | Ceiling | Basis |
|---|---|---|
| Prohibited practices (Art. 5) | EUR 35,000,000 **or** **7%** of worldwide annual turnover | Art. 99(3) |
| Other obligations (provider/deployer obligations, incl. Art. 50 transparency) | EUR 15,000,000 **or** **3%** of turnover | Art. 99(4) |
| Supplying incorrect, incomplete or misleading information to authorities | EUR 7,500,000 **or** **1%** of turnover | Art. 99(5) |

*Whichever is higher applies; for SMEs and start-ups, whichever is lower
(Art. 99(6)). Art. 101 is reserved for general-purpose AI model providers.*

---

## PART I — DECLARATION AND SIGNATURE

The undersigned declare that the information in this form is accurate as at the
assessment date and that the assessment will be renewed upon any substantial
modification of the system.

| | Name | Title | Date | Signature |
|---|---|---|---|---|
| Assessed by | | | | |
| Technical validation | | | | |
| Legal review | | | | |
| Approved by | | | | |

---

*This form is general in nature and does not constitute legal advice. The
classification outcome depends on the system's actual operation and intended
purpose, and must be confirmed against the legislation in force and Commission
guidance.*
