AI Risk Classification Agent Compliance Agents EU AI Act On-premise Updated August 2026
AI Risk Classification Agent

The AI Risk Classification Agent

Classify an AI system under the EU AI Act risk framework — unacceptable, high, limited, or minimal — with an Annex III category mapping and a defensible rationale citing the relevant provisions, on infrastructure you control.

Explore VDF AI Agents
4 tiers Unacceptable → minimal
Annex III Category mapping
Cited Provisions referenced
On-prem System details stay inside
Grounded in
EU AI Act Annex III Article 6 Risk tiers Rationale Audit trail

What is an AI risk classification agent?

An AI risk classification agent assigns each of your AI systems to an EU AI Act risk tier — prohibited, high risk, limited risk or minimal risk — and records the reasoning behind the assignment. It works from how a system is actually used rather than how it is marketed, and produces the written justification the Act expects you to hold.

What it does

Tiers each system against Annex III Separates provider from deployer duties Records the reasoning behind each tier Flags prohibited practices explicitly Re-classifies when a use case changes

What it is not

Not legal advice Not a substitute for a conformity assessment Not a one-time exercise
The Classification Problem

Risk tiering is the first EU AI Act step — and the easiest to get wrong

Every EU AI Act obligation flows from one question: what risk tier is this system? Get it wrong and you either over-invest in compliance you don’t need or miss high-risk duties entirely. Doing it by hand means re-reading Annex III for every system.

Everything depends on the tier

High-risk systems carry the heavy obligations; misclassify and your whole compliance posture is built on sand.

Annex III is dense

Mapping a real system to Annex III categories and Article 6 takes legal-grade reading every single time.

Inconsistent judgments

Different reviewers reach different tiers for similar systems, and none of it is documented defensibly.

No paper trail

When a regulator asks "why did you classify it this way?", an undocumented gut call is not an answer.

The VDF AI Governance Opportunity

Defensible risk classification, grounded in the regulation

Classify

A Tier With a Reason

Unacceptable, high, limited, or minimal.

From a structured description of the system, the agent assigns an EU AI Act risk tier and explains why — not just a label but the reasoning that supports it, ready for review by your compliance function.

  • Four-tier EU AI Act classification
  • Reasoning, not just a label
  • Consistent across systems
  • Built for human review and sign-off
4 tiers
Risk Classification

With reasoning

UnacceptableHighLimitedMinimal

Map

Annex III Category Mapping

Pinpoint the relevant high-risk use.

For systems that may be high-risk, the agent maps to the specific Annex III categories and Article 6 conditions that apply, so the classification is precise rather than a vague "probably high".

Annex III
Category Mapping

Article 6 conditions

Annex IIIArticle 6Use caseScope

Defend

A Citation-Backed Rationale

Ready for an auditor.

Every classification comes with a rationale citing the relevant EU AI Act provisions — a defensible record you can put in front of an auditor or regulator. It runs on-premise so system details never leave your control, with the full trail logged.

Cited
Defensible Record

Provisions referenced

RationaleCitationsAudit-readyOn-prem
Run sequence

How the AI Risk Classification Agent runs a task

  1. STEP 01

    Inventory the system

    Classification starts from a described system, not a name: what it decides or recommends, whose data it touches, which humans act on its output, and where in a business process it sits. Vague entries are pushed back rather than guessed at.

    System descriptionUse-case capture
  2. STEP 02

    Establish your role

    The same model carries different duties depending on whether you built it, badged it, or merely deployed it. The agent settles provider versus deployer status first, because almost every downstream obligation depends on that answer.

    Provider / deployer test
  3. STEP 03

    Test against the tiers

    The described use is checked against prohibited practices first, then the Annex III high-risk categories, then transparency-only cases. Each test records which criterion was met or missed and on what evidence, rather than emitting a bare label.

    Annex IIIProhibited practicesTransparency tests
  4. STEP 04

    Write the justification

    The output is a reasoned classification: the tier, the criteria applied, the evidence relied on, the obligations that follow, and the points a reviewer might reasonably contest. That document is the artefact regulators and auditors ask to see.

    Classification recordObligation list
  5. STEP 05

    Watch for drift

    A minimal-risk assistant becomes a high-risk system the moment someone points it at CV screening. Re-classification is triggered by changes in described use, data scope or affected population, and the previous classification is retained rather than overwritten.

    Change triggersVersion history
Integrations

Systems the AI Risk Classification Agent connects to

Scoped, per-tenant credentials Every call written to the audit log No data copied to a third party

Regulatory reference

EU AI Act text Retrieve Annex III and Article criteria
Internal policy Apply your own risk appetite thresholds
Prior classifications Compare against precedent decisions
Specification

Inputs, outputs and runtime

Ingests
System descriptionsUse-case statementsData-flow notesModel cardsExisting risk registers
Produces
Risk tier with reasoningObligation checklistProvider/deployer findingContestable pointsRe-classification trigger list
Triggered by
New system intakeUse-case changeScheduled reviewAudit request
Human oversight
A compliance owner signs every classification
Models
Open-weight LLMs you host, pinned per classification
Typical latency
Minutes per system once the description is complete
Deployment
On-premise, sovereign cloud or air-gapped
Data residency
System inventory and findings never leave your estate
Where it pays back

Where risk classification pays back

AI System Inventory

Classify every AI system in your estate so you know which carry high-risk obligations and which don’t.

New-System Intake

Tier each new or procured AI system at intake, before it ships, so obligations are known up front.

Procurement Screening

Assess vendor AI systems against the EU AI Act risk framework as part of due diligence.

Annex III Mapping

Pinpoint exactly which Annex III high-risk category a system falls under, and why.

Audit Preparation

Produce a defensible, citation-backed rationale for each classification ahead of an audit.

Re-classification

Re-tier systems when their purpose or context changes, keeping the inventory current.

Comparison

AI Risk Classification Agent vs chatbots and SaaS copilots

Classification is not the hard part of the EU AI Act — defending it is. A tier without recorded reasoning is an opinion, and an opinion is what fails an audit two years after the person who formed it has left.

  Generic chatbot SaaS copilot VDF AI
Reads your real estate No Vendor cloud only Indexes your own inventory
Provider vs deployer Conflated Not addressed Settled before tiering
Recorded reasoning None None Criteria and evidence per tier
Prohibited practices Missed Missed Tested first, flagged plainly
Re-classification Manual Manual Triggered by described change
Where findings live Third-party model Vendor cloud Inside your estate
Audit artefact None None Signed classification record
Controls

Governance and controls

This agent is itself an AI system used in a compliance process, so it is built to the standard it applies: a stated basis for every finding, a named human owner, a pinned model, and a history that cannot be quietly rewritten.

Limited risk — transparency obligations apply to this agent EU AI ActISO/IEC 42001ISO/IEC 23894NIST AI RMFGDPR

Role-based access

Only compliance owners can sign a classification

Immutable audit log

Superseded classifications retained, not replaced

Mandatory sign-off

No tier stands without a named human owner

Stated basis

Every finding cites the criterion it applied

Contestability

Weak points surfaced rather than smoothed over

Model pinning

Version recorded against each classification

Evidence it leaves behind

Signed classification record Criteria applied Evidence cited Version history Obligation checklist
ROI snapshot

What changes after rollout

Consistent Tiering across systems
Cited Defensible rationale
Faster Inventory classification
On-prem System details stay inside
Audience

Who runs the AI Risk Classification Agent

Chief compliance officer

Can answer the board question — how many high-risk AI systems do we operate, and on what basis — with a register whose every entry carries recorded reasoning rather than a colleague’s recollection.

Data protection officer

Gets classification aligned with existing GDPR work, because provider versus deployer status and affected-population analysis feed straight into impact assessments instead of being redone separately.

AI programme lead

Learns which proposed use cases fall into high risk before engineering starts, so obligations are designed in rather than discovered during a conformity assessment that was already scheduled.

FAQ

Questions about the AI Risk Classification Agent

What is an AI risk classification agent?

It is an AI governance agent that classifies AI systems under the EU AI Act risk framework — unacceptable, high, limited, or minimal — maps high-risk systems to the relevant Annex III categories and Article 6 conditions, and produces a defensible rationale citing the regulation. VDF’s agent runs on your own infrastructure so system details stay private.

Why does risk classification matter so much?

Every other EU AI Act obligation depends on the tier. High-risk systems trigger the heavy duties — risk management, documentation, transparency, record-keeping. Getting the tier right is the foundation of the whole compliance program.

Does it replace legal review?

No — it accelerates it. The agent produces a consistent, citation-backed first-pass classification and rationale that your compliance and legal functions review and sign off, rather than re-reading Annex III from scratch each time.

How is the classification defensible?

Each output includes a rationale citing the relevant EU AI Act provisions and an Annex III mapping where applicable, giving you an auditable record to show a regulator instead of an undocumented judgment.

Is it part of a larger toolkit?

Yes. It’s one of VDF’s EU AI Act agents alongside governance policy, Annex IV documentation, transparency notices, record-keeping, training, and code scanning — see the AI Governance Agents hub.

Is this legal advice?

No, and it should not be presented as such. The agent applies the Act’s published criteria to the systems you describe and records the reasoning, which is what makes a classification reviewable by your own counsel or an external assessor. It is a way of doing the work consistently and defensibly, not a substitute for legal judgement.

What if we are a deployer rather than a provider?

That distinction is settled before tiering, because it changes almost everything downstream. Deployers carry obligations around human oversight, input data quality, monitoring and informing affected people; providers additionally carry conformity assessment, technical documentation and post-market monitoring. Badging someone else’s model as your own can make you a provider.

How does it handle a general-purpose model we fine-tuned?

Classification follows the use, not the base model. A fine-tuned general-purpose model deployed into a hiring, credit or safety process is assessed against Annex III on that use. Substantial modification can also move you from deployer to provider, so the agent tests that question explicitly and records the finding.

What triggers a re-classification?

A change in described use, in the data the system touches, in the population affected, or in how much human review sits between output and consequence. Those are the changes that move a tier. The previous classification is retained alongside the new one, so the register shows when the assessment changed and why.

Can it classify systems we bought rather than built?

Yes, and that is the common case. It works from how you use the system, drawing on vendor model cards and documentation where they exist and flagging where they are insufficient. A vendor claiming their product is minimal risk does not settle your position as a deployer, and the agent records that gap rather than accepting the claim.

Start your EU AI Act program with a defensible classification

See the AI Risk Classification Agent tier your systems with an Annex III mapping and cited rationale.

Try this agent free Deploy this agent in-house