TREN
Guide · Risk classification

Is your software high-risk? The answer is in the intended purpose.

The same model can be minimal-risk in one product and high-risk in another. What decides it is not the technology but what the system is used for. Download the blank classification and declaration form below, free of charge.

High-risk AI system classification
Download the classification form Reserve your spot for an online call
§ 01 — The logic of classification

The Regulation classifies use, not technology.

“Is our software high-risk?” cannot be answered by looking at the size or architecture of the model. Regulation (EU) 2024/1689 determines the risk class by the system's intended purpose. Classification is therefore performed separately for each intended purpose.

Two separate routes

Product-safety route (Art. 6(1)). Where the system is a safety component of — or is itself — a product covered by the Annex I harmonisation legislation, and that product requires third-party conformity assessment, the system is high-risk.

Annex III route (Art. 6(2)). A system is high-risk as a rule where it is used in: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services and benefits (including creditworthiness assessment and health/life insurance pricing); law enforcement; migration and border control; administration of justice and democratic processes.

The derogation is not an automatic exit

Article 6(3) provides that a system within Annex III may nonetheless not be high-risk where it does not materially influence the outcome of decision-making: a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns, or a preparatory task.

This derogation has two hard limits:

Two determinations come first

The form's parts are deliberately ordered: scope (Art. 2 — establishment in a third country does not on its own place you outside scope), then role (provider, deployer, or deemed provider under Art. 25), then classification. If the role is wrong, everything assessed after it is void.

§ 02 — Fine thresholds

“7% of turnover” does not apply to every infringement.

One figure circulates in public discussion, but Article 99 sets three separate ceilings, and which applies depends on the provision infringed. For the accuracy of a risk assessment this distinction is decisive.

InfringementCeilingBasis
Prohibited practicesEUR 35M / 7%Art. 99(3)
Provider & deployer obligations, Art. 50 transparencyEUR 15M / 3%Art. 99(4)
Incorrect or misleading information to authoritiesEUR 7.5M / 1%Art. 99(5)

Whichever is higher applies; for SMEs and start-ups, whichever is lower (Art. 99(6)). Art. 101 is reserved for general-purpose AI model providers. Figures reflect the text as at the date this page was prepared.

Practical note In practice what arrives first is usually not a fine but a commercial consequence: EU corporate buyers' supplier-audit forms ask for the classification and a declaration of conformity. A supplier without one drops off the purchasing list before any enforcement process begins.
§ 03 — Form

Classification and declaration form — blank template.

Complete a separate form for each system. Copy it or download it as markdown. No sign-up.

AIA-CLS-02 · Version 1.0 · Free Download .md ↓
# HIGH-RISK AI SYSTEM CLASSIFICATION AND DECLARATION FORM

Document code: AIA-CLS-02 · Version 1.0 · Basis: Regulation (EU) 2024/1689
Assessment date: ……/……/20……   Reassessment: on every substantial modification
Complete a SEPARATE form for each AI system.

PART A — SYSTEM RECORD
A.1 System name / version: [……]
A.2 Intended purpose: [……]
A.3 Reasonably foreseeable misuse: [……]
A.4 Upstream technical provider: [……]
A.5 Model type (GPAI / bespoke / rule-based): [……]
A.6 Geography where output is used: [……]
A.7 Effect on the decision: ( ) Determinative ( ) Advisory ( ) Preparatory
A.8 Human oversight: ( ) Yes ( ) No ( ) Partial

PART B — TERRITORIAL SCOPE
B.1 Do you place the system on the EU market under your own name/brand? ( ) Y ( ) N
B.2 Branch/subsidiary/commercial presence in the EU?                    ( ) Y ( ) N
B.3 Is the OUTPUT of the system used within the EU?                     ( ) Y ( ) N
    -> Art. 2(1)(c). Establishment in a third country is not an exemption.
B.4 Result: any "Yes" means you are in scope. ( ) In scope ( ) Out of scope
B.5 Justification (mandatory): [……]

PART C — ROLE DETERMINATION
C.1 Provider — you develop and place it under your own name/brand (Art. 3(3)) ( )
C.2 Deployer — you use it under your own authority (Art. 3(4))                ( )
C.3 DEEMED provider — Art. 25:                                                ( )
    C.3.A Placing a third party's high-risk system on the market under your
          own name or trademark,
    C.3.B Making a SUBSTANTIAL MODIFICATION to a high-risk system already on
          the market,
    C.3.C Changing the INTENDED PURPOSE of a non-high-risk system so that it
          becomes high-risk.
    Note: a significant share of white-labelled products fall under C.3.A.
C.4 Role determined: [……]  Justification: [……]

PART D — PROHIBITED PRACTICE SCREEN (Art. 5)
Any "Yes" means the system may not be placed on the market.
D.1 Subliminal/manipulative techniques distorting behaviour       ( ) Y ( ) N
D.2 Exploiting age, disability or socioeconomic vulnerability     ( ) Y ( ) N
D.3 Social scoring                                                ( ) Y ( ) N
D.4 Criminal risk prediction based solely on profiling            ( ) Y ( ) N
D.5 Untargeted scraping of facial images to build databases       ( ) Y ( ) N
D.6 Emotion recognition in the workplace or education             ( ) Y ( ) N
D.7 Biometric categorisation inferring sensitive attributes       ( ) Y ( ) N
D.8 Real-time remote biometric identification in public spaces
    (exceptions reserved)                                         ( ) Y ( ) N
D.9 Result: ( ) No prohibited practice  ( ) STOP — falls under Art. 5

PART E — HIGH-RISK CLASSIFICATION
E.1 Product-safety route (Art. 6(1)):
    E.1.A Safety component of / a product under Annex I legislation? ( ) Y ( ) N
    E.1.B Third-party conformity assessment required for it?        ( ) Y ( ) N
    -> Both "Yes" = HIGH-RISK.
E.2 Annex III route (Art. 6(2)) — area of use:
    ( ) E.2.1 Biometrics          ( ) E.2.5 Access to essential services
    ( ) E.2.2 Critical infrastructure     (creditworthiness, insurance pricing)
    ( ) E.2.3 Education / vocational  ( ) E.2.6 Law enforcement
    ( ) E.2.4 Employment / worker mgmt ( ) E.2.7 Migration, asylum, borders
                                       ( ) E.2.8 Justice & democratic processes
E.3 Derogation (Art. 6(3)) — if it does not materially influence the outcome:
    E.3.A A narrow procedural task,
    E.3.B Improving the result of a completed human activity,
    E.3.C Detecting decision-making patterns (not replacing human assessment
          without proper human review),
    E.3.D A preparatory task.
    E.3.E ABSOLUTE LIMIT: if the system performs PROFILING of natural persons,
          the derogation is unavailable — high-risk in all cases.
    E.3.F If relying on it, document the assessment BEFORE placing on the
          market; a registration obligation arises (Art. 6(4), Art. 49(2)).
          A derogation without written reasoning is not a derogation.
E.4 RESULT: ( ) High-risk  ( ) Not high-risk (Art. 6(3), reasoning attached)
            ( ) Limited risk (Art. 50 only)  ( ) Minimal risk
E.5 Justification (mandatory): [……]

PART F — IF HIGH-RISK: OBLIGATION CHECKLIST
F.1  Risk management system ............................... Art. 9        ( )
F.2  Data governance and data-set quality ................. Art. 10       ( )
F.3  Technical documentation .............................. Art. 11+Ann.IV( )
F.4  Automatic record-keeping (logging) ................... Art. 12       ( )
F.5  Transparency and instructions for deployers .......... Art. 13       ( )
F.6  Human oversight by design ............................ Art. 14       ( )
F.7  Accuracy, robustness, cybersecurity .................. Art. 15       ( )
F.8  Quality management system ............................ Art. 17       ( )
F.9  Conformity assessment ................................ Art. 43       ( )
F.10 EU declaration of conformity ......................... Art. 47       ( )
F.11 CE marking ........................................... Art. 48       ( )
F.12 Registration in the EU database ...................... Art. 49       ( )
F.13 Post-market monitoring ............................... Art. 72       ( )
F.14 Serious incident reporting ........................... Art. 73       ( )
If you are a deployer: Art. 26 obligations and, where applicable, Art. 27 FRIA.

PART G — TRANSPARENCY (Art. 50) — irrespective of risk class
G.1 Direct interaction with a person -> disclosure (Art. 50(1))         ( )
G.2 Synthetic content -> machine-readable marking (Art. 50(2))          ( )
G.3 Emotion recognition / biometric categorisation (Art. 50(3))         ( )
G.4 Deepfakes and public-interest text -> disclosure (Art. 50(4))       ( )
G.5 Timing: at the latest at the first interaction (Art. 50(5))         ( )

PART H — ADMINISTRATIVE FINE THRESHOLDS (Art. 99)
Prohibited practices (Art. 5) ...... EUR 35,000,000 or 7% of turnover [Art. 99(3)]
Other obligations (incl. Art. 50) .. EUR 15,000,000 or 3% of turnover [Art. 99(4)]
Incorrect/misleading information ... EUR  7,500,000 or 1% of turnover [Art. 99(5)]
Whichever is higher; for SMEs whichever is lower (Art. 99(6)). GPAI: Art. 101.

PART I — DECLARATION AND SIGNATURE
Assessed by / Technical validation / Legal review / Approved by
Name, Title, Date, Signature

This form is general in nature and does not constitute legal advice.
§ 04 — Filling it in

The three parts most often got wrong.

  1. Part C — role determination. Offering an off-the-shelf model under your own brand can make you a provider under Art. 25. If this is wrong, every obligation in Part F has been assigned to the wrong party.
  2. Part E.3 — the derogation. “Ours only makes a recommendation” is a very common and usually premature conclusion. Where a human approves the recommendation without genuinely interrogating it, you cannot argue the system does not materially influence the outcome.
  3. Part A.2 — intended purpose. Drafted too broadly, the system is pulled into the high-risk class unnecessarily; drafted too narrowly, actual use contradicts the declaration. The gap between declaration and actual use is the fastest inconsistency to surface in an audit.
Note This form is a general framework and does not substitute for a conformity assessment. Part C (role), Part E.3 (derogation) and Part A.2 (intended purpose) turn on how your company actually operates, and an incorrect declaration in any of the three invalidates everything assessed after it. You can book a preliminary call to adapt the form to your system and put the reasoning in writing.
§ 05 — Frequently asked

Questions.

How is a high-risk system determined?

Two routes. Under the product-safety route (Art. 6(1)) a system is high-risk where it is a safety component of, or is itself, a product under the Annex I legislation requiring third-party conformity assessment. Under the Annex III route (Art. 6(2)), use in biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and justice is high-risk as a rule.

Is the fine really 7% of turnover?

The 7% ceiling applies only to the prohibited practices in Art. 5 (EUR 35M or 7% — Art. 99(3)). For provider/deployer obligations and Art. 50 transparency breaches the ceiling is EUR 15M or 3% (Art. 99(4)). For incorrect information to authorities, EUR 7.5M or 1% (Art. 99(5)).

Is every Annex III system high-risk?

No. Art. 6(3) provides a narrow derogation. But where the system performs profiling of natural persons the derogation does not apply. If you rely on it, you must document the assessment before placing the system on the market and meet the registration obligation (Art. 6(4), Art. 49(2)).

We only use an off-the-shelf model — are we a provider?

If you place a third party's high-risk system on the market under your own name or trademark, make a substantial modification, or change the intended purpose so that it becomes high-risk, you are deemed a provider under Art. 25.

We're outside the EU with no EU entity. Does it bind us?

The Regulation applies even where the provider or deployer is established in a third country, provided the system's output is used within the Union (Art. 2(1)(c)). That is why scope is the first part of the form.

Related

Read next.

Let's work out the classification together.

In a twenty-minute preliminary call we establish scope, role and classification for your specific system. If you're out of scope, we tell you that clearly too.

Reserve your spot for an online call The call is online · the form is yours either way