The AI Risk Classification Agent
Classify an AI system under the EU AI Act risk framework — unacceptable, high, limited, or minimal — with an Annex III category mapping and a defensible rationale citing the relevant provisions, on infrastructure you control.
What is an AI risk classification agent?
An AI risk classification agent assigns each of your AI systems to an EU AI Act risk tier — prohibited, high risk, limited risk or minimal risk — and records the reasoning behind the assignment. It works from how a system is actually used rather than how it is marketed, and produces the written justification the Act expects you to hold.
What it does
What it is not
Risk tiering is the first EU AI Act step — and the easiest to get wrong
Every EU AI Act obligation flows from one question: what risk tier is this system? Get it wrong and you either over-invest in compliance you don’t need or miss high-risk duties entirely. Doing it by hand means re-reading Annex III for every system.
Everything depends on the tier
High-risk systems carry the heavy obligations; misclassify and your whole compliance posture is built on sand.
Annex III is dense
Mapping a real system to Annex III categories and Article 6 takes legal-grade reading every single time.
Inconsistent judgments
Different reviewers reach different tiers for similar systems, and none of it is documented defensibly.
No paper trail
When a regulator asks "why did you classify it this way?", an undocumented gut call is not an answer.
Defensible risk classification, grounded in the regulation
Classify
A Tier With a Reason
Unacceptable, high, limited, or minimal.
From a structured description of the system, the agent assigns an EU AI Act risk tier and explains why — not just a label but the reasoning that supports it, ready for review by your compliance function.
- Four-tier EU AI Act classification
- Reasoning, not just a label
- Consistent across systems
- Built for human review and sign-off
With reasoning
Map
Annex III Category Mapping
Pinpoint the relevant high-risk use.
For systems that may be high-risk, the agent maps to the specific Annex III categories and Article 6 conditions that apply, so the classification is precise rather than a vague "probably high".
Article 6 conditions
Defend
A Citation-Backed Rationale
Ready for an auditor.
Every classification comes with a rationale citing the relevant EU AI Act provisions — a defensible record you can put in front of an auditor or regulator. It runs on-premise so system details never leave your control, with the full trail logged.
Provisions referenced
How the AI Risk Classification Agent runs a task
- STEP 01
Inventory the system
Classification starts from a described system, not a name: what it decides or recommends, whose data it touches, which humans act on its output, and where in a business process it sits. Vague entries are pushed back rather than guessed at.
System descriptionUse-case capture - STEP 02
Establish your role
The same model carries different duties depending on whether you built it, badged it, or merely deployed it. The agent settles provider versus deployer status first, because almost every downstream obligation depends on that answer.
Provider / deployer test - STEP 03
Test against the tiers
The described use is checked against prohibited practices first, then the Annex III high-risk categories, then transparency-only cases. Each test records which criterion was met or missed and on what evidence, rather than emitting a bare label.
Annex IIIProhibited practicesTransparency tests - STEP 04
Write the justification
The output is a reasoned classification: the tier, the criteria applied, the evidence relied on, the obligations that follow, and the points a reviewer might reasonably contest. That document is the artefact regulators and auditors ask to see.
Classification recordObligation list - STEP 05
Watch for drift
A minimal-risk assistant becomes a high-risk system the moment someone points it at CV screening. Re-classification is triggered by changes in described use, data scope or affected population, and the previous classification is retained rather than overwritten.
Change triggersVersion history
Systems the AI Risk Classification Agent connects to
System inventory sources
Regulatory reference
Inputs, outputs and runtime
- Ingests
- System descriptionsUse-case statementsData-flow notesModel cardsExisting risk registers
- Produces
- Risk tier with reasoningObligation checklistProvider/deployer findingContestable pointsRe-classification trigger list
- Triggered by
- New system intakeUse-case changeScheduled reviewAudit request
- Human oversight
- A compliance owner signs every classification
- Models
- Open-weight LLMs you host, pinned per classification
- Typical latency
- Minutes per system once the description is complete
- Deployment
- On-premise, sovereign cloud or air-gapped
- Data residency
- System inventory and findings never leave your estate
Where risk classification pays back
AI System Inventory
Classify every AI system in your estate so you know which carry high-risk obligations and which don’t.
New-System Intake
Tier each new or procured AI system at intake, before it ships, so obligations are known up front.
Procurement Screening
Assess vendor AI systems against the EU AI Act risk framework as part of due diligence.
Annex III Mapping
Pinpoint exactly which Annex III high-risk category a system falls under, and why.
Audit Preparation
Produce a defensible, citation-backed rationale for each classification ahead of an audit.
Re-classification
Re-tier systems when their purpose or context changes, keeping the inventory current.
AI Risk Classification Agent vs chatbots and SaaS copilots
Classification is not the hard part of the EU AI Act — defending it is. A tier without recorded reasoning is an opinion, and an opinion is what fails an audit two years after the person who formed it has left.
| Generic chatbot | SaaS copilot | VDF AI | |
|---|---|---|---|
| Reads your real estate | No | Vendor cloud only | Indexes your own inventory |
| Provider vs deployer | Conflated | Not addressed | Settled before tiering |
| Recorded reasoning | None | None | Criteria and evidence per tier |
| Prohibited practices | Missed | Missed | Tested first, flagged plainly |
| Re-classification | Manual | Manual | Triggered by described change |
| Where findings live | Third-party model | Vendor cloud | Inside your estate |
| Audit artefact | None | None | Signed classification record |
Governance and controls
This agent is itself an AI system used in a compliance process, so it is built to the standard it applies: a stated basis for every finding, a named human owner, a pinned model, and a history that cannot be quietly rewritten.
Role-based access
Only compliance owners can sign a classification
Immutable audit log
Superseded classifications retained, not replaced
Mandatory sign-off
No tier stands without a named human owner
Stated basis
Every finding cites the criterion it applied
Contestability
Weak points surfaced rather than smoothed over
Model pinning
Version recorded against each classification
Evidence it leaves behind
What changes after rollout
Who runs the AI Risk Classification Agent
Chief compliance officer
Can answer the board question — how many high-risk AI systems do we operate, and on what basis — with a register whose every entry carries recorded reasoning rather than a colleague’s recollection.
Data protection officer
Gets classification aligned with existing GDPR work, because provider versus deployer status and affected-population analysis feed straight into impact assessments instead of being redone separately.
AI programme lead
Learns which proposed use cases fall into high risk before engineering starts, so obligations are designed in rather than discovered during a conformity assessment that was already scheduled.
Questions about the AI Risk Classification Agent
What is an AI risk classification agent?
It is an AI governance agent that classifies AI systems under the EU AI Act risk framework — unacceptable, high, limited, or minimal — maps high-risk systems to the relevant Annex III categories and Article 6 conditions, and produces a defensible rationale citing the regulation. VDF’s agent runs on your own infrastructure so system details stay private.
Why does risk classification matter so much?
Every other EU AI Act obligation depends on the tier. High-risk systems trigger the heavy duties — risk management, documentation, transparency, record-keeping. Getting the tier right is the foundation of the whole compliance program.
Does it replace legal review?
No — it accelerates it. The agent produces a consistent, citation-backed first-pass classification and rationale that your compliance and legal functions review and sign off, rather than re-reading Annex III from scratch each time.
How is the classification defensible?
Each output includes a rationale citing the relevant EU AI Act provisions and an Annex III mapping where applicable, giving you an auditable record to show a regulator instead of an undocumented judgment.
Is it part of a larger toolkit?
Yes. It’s one of VDF’s EU AI Act agents alongside governance policy, Annex IV documentation, transparency notices, record-keeping, training, and code scanning — see the AI Governance Agents hub.
Is this legal advice?
No, and it should not be presented as such. The agent applies the Act’s published criteria to the systems you describe and records the reasoning, which is what makes a classification reviewable by your own counsel or an external assessor. It is a way of doing the work consistently and defensibly, not a substitute for legal judgement.
What if we are a deployer rather than a provider?
That distinction is settled before tiering, because it changes almost everything downstream. Deployers carry obligations around human oversight, input data quality, monitoring and informing affected people; providers additionally carry conformity assessment, technical documentation and post-market monitoring. Badging someone else’s model as your own can make you a provider.
How does it handle a general-purpose model we fine-tuned?
Classification follows the use, not the base model. A fine-tuned general-purpose model deployed into a hiring, credit or safety process is assessed against Annex III on that use. Substantial modification can also move you from deployer to provider, so the agent tests that question explicitly and records the finding.
What triggers a re-classification?
A change in described use, in the data the system touches, in the population affected, or in how much human review sits between output and consequence. Those are the changes that move a tier. The previous classification is retained alongside the new one, so the register shows when the assessment changed and why.
Can it classify systems we bought rather than built?
Yes, and that is the common case. It works from how you use the system, drawing on vendor model cards and documentation where they exist and flagging where they are insufficient. A vendor claiming their product is minimal risk does not settle your position as a deployer, and the agent records that gap rather than accepting the claim.
Start your EU AI Act program with a defensible classification
See the AI Risk Classification Agent tier your systems with an Annex III mapping and cited rationale.