{"id":32303,"date":"2026-07-13T08:00:00","date_gmt":"2026-07-13T06:00:00","guid":{"rendered":"https:\/\/pegamento.nl\/niet-gecategoriseerd\/how-does-risk-classification-work-under-the-ai-act\/"},"modified":"2026-07-13T10:01:05","modified_gmt":"2026-07-13T08:01:05","slug":"how-does-risk-classification-work-under-the-ai-act","status":"publish","type":"post","link":"https:\/\/pegamento.nl\/en\/contact-center\/how-does-risk-classification-work-under-the-ai-act\/","title":{"rendered":"How does risk classification work under the AI Act?"},"content":{"rendered":"<p>The AI Act classifies AI systems into four risk categories: prohibited AI, high-risk AI, limited-risk AI, and minimal-risk AI. The greater the potential impact on fundamental rights, safety, or society, the more stringent the obligations. This classification directly determines which rules your organization must follow. In this article, we answer the most frequently asked questions about <a href=\"https:\/\/pegamento.nl\/en\/ai-powered-intelligence\/\">risk classification under the AI Act<\/a> and what that means for you in practice.   <\/p>\n<h2>What risk categories does the AI Act identify?<\/h2>\n<p>The AI Act distinguishes four risk categories: <strong>unacceptable risk<\/strong> (prohibited), <strong>high risk<\/strong> (heavily regulated), <strong>limited risk<\/strong> (transparency requirements), and <strong>minimal risk<\/strong> (virtually no requirements). This tiered approach ensures that the strictest rules apply to applications with the greatest potential for harm, while innovation in low-risk AI remains as unrestricted as possible. <\/p>\n<p>The classification is based on the principle that the intensity of regulation must be proportional to the risks posed by an AI system. A spam filter in your email program falls into a completely different category than an AI system that evaluates job applicants or makes medical diagnoses. The regulation considers not only the system itself, but also the context in which it is used and the people directly affected by it.  <\/p>\n<p>Important to know: the classification is not static. A system that poses minimal risk in one context may be high-risk in another. The intended use and the sector in which you operate therefore determine which category applies.  <\/p>\n<h2>Which AI applications are completely prohibited?<\/h2>\n<p>The AI Act prohibits AI applications that pose an unacceptable risk to fundamental rights and human dignity. This includes systems that manipulate people through subconscious techniques, exploit vulnerable groups, assign social scores by governments, and most forms of remote biometric identification in public spaces in real time. <\/p>\n<p>Specifically, Section 5 of the AI Act prohibits the following categories:<\/p>\n<ul>\n<li>AI systems that use subliminal techniques to influence behavior without a person&#8217;s awareness<\/li>\n<li>Systems that deliberately manipulate vulnerable groups, such as children or people with disabilities<\/li>\n<li>Social scoring systems operated by or on behalf of governments that evaluate citizens based on their behavior in daily life<\/li>\n<li>Real-time remote biometric identification in public spaces by law enforcement, with limited exceptions<\/li>\n<li>AI that recognizes emotions in the workplace or in educational institutions, except for medical or security purposes<\/li>\n<li>Systems that use biometric categorization to infer sensitive characteristics such as political views or sexual orientation<\/li>\n<\/ul>\n<p>These prohibitions were the first to take effect, specifically on <strong>February 2, 2025<\/strong>. Organizations that were already using such systems at that time were required to take immediate action. The fines for violations of these prohibitions are also the highest: up to 35 million euros or 7% of global annual revenue.  <\/p>\n<h2>How do you determine whether an AI system is high-risk?<\/h2>\n<p>An AI system is considered high-risk if it falls within the sectors or applications listed in Annex III of the AI Act, or if it is a safety component of a product already covered by existing EU legislation (Annex I). The key question is always: Could the system have significant negative consequences for people\u2019s health, safety, or fundamental rights? <\/p>\n<p>Appendix III contains a specific list of high-risk application areas:<\/p>\n<ul>\n<li>Biometric Identification and Categorization of Individuals<\/li>\n<li>Management of critical infrastructure, such as energy, water, and transportation<\/li>\n<li>Education and vocational training, including student admission and evaluation<\/li>\n<li>Employment, Human Resources Management, and Access to Self-Employment<\/li>\n<li>Access to and use of essential private and public services, such as credit scoring<\/li>\n<li>Law enforcement, including risk assessment of individuals<\/li>\n<li>Migration, Asylum, and Border Control<\/li>\n<li>The Administration of Justice and Democratic Processes<\/li>\n<\/ul>\n<p>There is one important exception: if a system appears at first glance to fall under Annex III but in reality has no significant impact on decision-making regarding people, the provider can argue that it is not high-risk after all. However, this requires a documented assessment and is not something you can simply assume. <\/p>\n<h2>What are the requirements for high-risk AI systems?<\/h2>\n<p>Providers of high-risk AI systems must meet a comprehensive set of requirements before bringing their systems to market. The core obligations include a robust risk management system, technical documentation, data governance, transparency toward users, human oversight, and registration in an EU database. <\/p>\n<p>Specifically, these obligations are as follows:<\/p>\n<ul>\n<li><strong>Risk management system:<\/strong> an ongoing process that identifies, evaluates, and mitigates risks throughout the system&#8217;s entire lifecycle<\/li>\n<li><strong>Technical documentation:<\/strong> a detailed description of the system, its operation, the test results, and the conformity assessment procedure<\/li>\n<li><strong>Data quality:<\/strong> training, validation, and test data must be relevant, sufficiently representative, and as free of errors as possible<\/li>\n<li><strong>Transparency and user information:<\/strong> Users must understand what the system does, what its limitations are, and how they can use it safely<\/li>\n<li><strong>Human oversight:<\/strong> The system must be designed so that people can understand, monitor, interrupt, or correct it<\/li>\n<li><strong>Accuracy, robustness, and cybersecurity:<\/strong> demonstrably consistent performance, even in the face of unexpected input or attacks<\/li>\n<li><strong>Conformity assessment and CE marking:<\/strong> depending on the type of system, either through self-assessment or through a notified body<\/li>\n<li><strong>Registration:<\/strong> Registration in the EU database for high-risk AI prior to market introduction<\/li>\n<\/ul>\n<p>Deployers\u2014that is, organizations that use high-risk AI developed by others\u2014also have obligations. They must ensure human oversight, use the system in accordance with the provider\u2019s instructions, and report incidents. Responsibility is therefore shared between the party that builds the system and the party that deploys it.  <\/p>\n<h2>What is the difference between limited risk and minimal risk?<\/h2>\n<p>Low-risk AI is subject to specific transparency requirements: users must be aware that they are interacting with an AI system. Minimal-risk AI is subject to virtually no obligations under the AI Act. The distinction lies in the extent to which the system interacts with people and can thereby influence their perceptions or decisions.  <\/p>\n<p>The low-risk category includes, among other things, chatbots, deepfakes, and AI-generated content. If your organization uses a chatbot for customer service, the user must always be aware that they are not speaking with a human. The same applies to synthetically generated audio, video, or text intended to mimic real people or events.  <\/p>\n<p>Low-risk AI accounts for the lion&#8217;s share of all AI applications in use today: spam filters, AI in video games, content recommendation systems, and simple automation tools. There is no legal obligation for this category, although the AI Act encourages providers to voluntarily follow codes of conduct. <\/p>\n<p>So the practical difference for your organization is significant. Do you only use low-risk AI? Then the compliance requirements are minimal. Are you using a chatbot that could pass itself off as a human? Then a transparency requirement applies. And as soon as you use AI for employee evaluations or credit decisions, you quickly fall into the high-risk category.     <\/p>\n<h2>When does the risk classification under the AI Act take effect?<\/h2>\n<p>The risk classification will take effect in phases. The prohibitions on unacceptable risks (Article 5) will apply as of February 2, 2025. The requirements for high-risk systems listed in Annex III will take effect on August 2, 2026. Systems used as safety components in regulated products (Annex I) will not be subject to these requirements until August 2, 2027.   <\/p>\n<p>The full implementation will proceed as follows:<\/p>\n<ul>\n<li><strong>February 2, 2025:<\/strong> Prohibitions under Article 5 and the requirement for AI literacy (Article 4)<\/li>\n<li><strong>August 2, 2025:<\/strong> Requirements for GPAI models, governance structure, and penalty provisions<\/li>\n<li><strong>August 2, 2026:<\/strong> Most requirements for high-risk Annex III systems<\/li>\n<li><strong>August 2, 2027:<\/strong> Requirements for high-risk AI as a safety component (Annex I) and compliance deadline for GPAI models that were already on the market before August 2025<\/li>\n<\/ul>\n<p>In practical terms, this means that by 2026, organizations that offer or use high-risk Annex III systems must already be working on their compliance preparations. The deadline is fast approaching, and setting up a risk management system, preparing technical documentation, and establishing human oversight takes time. <\/p>\n<p>Reviews of the regulation are scheduled for 2028 and 2029, with a final report on enforcement in 2031. The AI Act is therefore not a static document, but a living framework that evolves alongside technological developments. <\/p>\n<h2>How Pegamento Helps You with AI Compliance and the Responsible Use of AI<\/h2>\n<p>The AI Act sets specific requirements for how you develop, deploy, and manage AI. This calls for a partner who is not only technically strong but also understands what responsible AI means in practice. At Pegamento, we combine in-depth AI expertise with a clear focus on ethical, human-centered technology.  <\/p>\n<p>What we can do for you:<\/p>\n<ul>\n<li><strong>Mapping Risk Classification:<\/strong> We\u2019ll help you determine which category your AI applications fall into and what obligations arise from that<\/li>\n<li><strong>Responsible Implementation of Agentic AI:<\/strong> Our <a href=\"https:\/\/pegamento.nl\/en\/agentic-ai-for-customer-service\/\">Agentic AI solutions for customer service<\/a> are designed with human oversight as a core principle, ensuring that you comply with the transparency and oversight requirements of the AI Act<\/li>\n<li><strong>Everything under one roof:<\/strong> from consulting and development to implementation, management, and support\u2014without complex supplier structures<\/li>\n<li><strong>Customized solutions using standard building blocks:<\/strong> no costly custom work, but a smart combination of proven modules tailored to your situation and industry<\/li>\n<li><strong>Certified quality:<\/strong> Pegamento is ISO 27001 certified (information security), supplemented by ISO 9001 and ISO 26000, so you can be sure that information security and quality are systematically guaranteed<\/li>\n<\/ul>\n<p>Would you like to know where your organization currently stands in terms of AI compliance, or are you curious about how to use AI responsibly within the framework of the AI Act? <a href=\"https:\/\/pegamento.nl\/en\/contact-2\/\">Please contact us<\/a>, and we\u2019d be happy to help you figure it out.<\/p>\n<div class=\"wp-block-seoaic-faq-block\">\n    <h2 class=\"seoaic-faq-section-title\">Frequently Asked Questions<\/h2>\n            <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat moet ik doen als mijn AI-systeem op de grens ligt tussen twee risicocategorie\u00ebn?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Als het niet direct duidelijk is in welke categorie jouw systeem valt, is een gedocumenteerde risicobeoordeling de aangewezen route. Breng daarin de beoogde toepassing, de doelgroep, de sector en de potenti\u00eble impact op grondrechten in kaart. Bij twijfel is het verstandig om uit te gaan van de hogere risicocategorie en juridisch of technisch advies in te winnen, zodat je niet achteraf geconfronteerd wordt met non-compliance.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Geldt de AI Act ook voor AI-systemen die wij als organisatie inkopen bij een externe leverancier?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, ook als deployer \u2014 de partij die een AI-systeem van een andere aanbieder inzet \u2014 heb je verplichtingen onder de AI Act. Je bent verantwoordelijk voor menselijk toezicht, het gebruik conform de instructies van de aanbieder, en het melden van ernstige incidenten. Het is daarom essentieel om bij inkoop van AI-systemen contractueel vast te leggen welke partij welke verplichtingen draagt en welke documentatie de aanbieder moet aanleveren.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe vaak moet ik de risicocategorie van mijn AI-systeem opnieuw beoordelen?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De classificatie is geen eenmalige exercitie. Wanneer je het systeem significant aanpast, het in een nieuwe context inzet, of de doelgroep verandert, kan de risicocategorie wijzigen. Voor hoog-risico systemen schrijft de AI Act bovendien een doorlopend risicobeheersysteem voor, wat betekent dat monitoring en herbeoordeling structureel onderdeel moeten zijn van je AI-governance.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Wat zijn de meest gemaakte fouten bij het voorbereiden op AI Act-compliance?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Een veelgemaakte fout is dat organisaties te laat beginnen en de complexiteit van de vereiste documentatie en processen onderschatten \u2014 met name het opzetten van een risicobeheersysteem en het borgen van menselijk toezicht kost meer tijd dan verwacht. Daarnaast overschatten veel organisaties de reikwijdte van de uitzondering voor niet-significante impact: beargumenteren dat een Bijlage III-systeem toch niet hoog-risico is, vereist een gedegen en gedocumenteerde onderbouwing, geen aanname.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Moeten wij als kleine of middelgrote onderneming ook volledig voldoen aan de AI Act?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Ja, de AI Act maakt in principe geen onderscheid op basis van bedrijfsomvang als het gaat om de toepasselijkheid van de regels. Wel zijn er lichtere procedures beschikbaar voor kleine aanbieders bij de conformiteitsbeoordeling, en houden toezichthouders bij het opleggen van boetes rekening met de omvang van de organisatie. Toch is het voor mkb-organisaties verstandig om tijdig te beginnen, juist omdat de capaciteit om snel bij te sturen vaak beperkter is.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe verhoudt de AI Act zich tot de AVG als mijn AI-systeem persoonsgegevens verwerkt?            <\/h3>\n            <p class=\"seoaic-answer\">\n                De AI Act en de AVG vullen elkaar aan en zijn beide van toepassing als jouw AI-systeem persoonsgegevens verwerkt. Waar de AVG zich richt op de rechtmatigheid en bescherming van gegevensverwerking, stelt de AI Act eisen aan het systeem zelf \u2014 zoals gegevenskwaliteit, transparantie en menselijk toezicht. Praktisch betekent dit dat je voor hoog-risico AI-systemen zowel een gegevensbeschermingseffectbeoordeling (DPIA) onder de AVG als een conformiteitsbeoordeling onder de AI Act moet uitvoeren.            <\/p>\n        <\/div>\n                <div class=\"seoaic-faq-item\">\n            <h3 class=\"seoaic-question\">\n                Hoe begin ik concreet met het in kaart brengen van de AI-toepassingen binnen mijn organisatie?            <\/h3>\n            <p class=\"seoaic-answer\">\n                Een goede eerste stap is een AI-inventarisatie: breng alle systemen en tools in kaart die AI gebruiken of AI-componenten bevatten, inclusief ingekochte software en cloudoplossingen van derden. Beoordeel vervolgens per toepassing de beoogde functie, de sector, en de impact op mensen. Op basis daarvan kun je een voorlopige classificatie maken en bepalen welke systemen prioriteit verdienen voor verdere compliance-voorbereiding. Externe begeleiding bij deze stap helpt om blinde vlekken te voorkomen en de beoordeling juridisch solide te maken.            <\/p>\n        <\/div>\n        <\/div>\n","protected":false},"excerpt":{"rendered":"<p>The AI Act has four risk categories\u2014find out which obligations apply to your organization.<\/p>\n","protected":false},"author":2,"featured_media":32304,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[500],"tags":[],"class_list":["post-32303","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contact-center"],"_links":{"self":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/comments?post=32303"}],"version-history":[{"count":1,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32303\/revisions"}],"predecessor-version":[{"id":32305,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/posts\/32303\/revisions\/32305"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media\/32304"}],"wp:attachment":[{"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/media?parent=32303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/categories?post=32303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pegamento.nl\/en\/wp-json\/wp\/v2\/tags?post=32303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}