Classification of AI risks
Classification of AI risks refers to the process of identifying and grouping the types of harms, vulnerabilities, or failures that artificial intelligence systems can create.
This classification helps organizations, regulators, and developers understand the nature of potential risks, assess their severity, and apply appropriate safeguards based on context and impact.
This matters because without clear risk categories, it becomes difficult to apply controls, report issues, or comply with governance frameworks like the EU AI Act or NIST AI Risk Management Framework.
For compliance and risk teams, having a structured view of AI risks makes it easier to prioritize mitigation efforts and communicate clearly with stakeholders.
"71% of executives say they are concerned about AI risks, but only 24% say their organization has a formal classification system in place."
2023 Deloitte Global AI Report
Key dimensions of AI risk classification
AI risks can be grouped in multiple ways, but most frameworks break them down across four main dimensions:
-
Technical risks: Model performance issues like hallucination, overfitting, drift, or lack of robustness
-
Ethical risks: Harmful outputs such as bias, discrimination, or privacy violations
-
Operational risks: Integration problems, failures in AI deployment pipelines, or lack of explainability
-
Legal and compliance risks: Violations of regulations or standards, lack of documentation, or inadequate data controls
This type of classification helps align AI risk management with traditional enterprise risk models while introducing AI-specific nuances.
Risk tiers under the EU AI Act
The EU AI Act is in force and sorts AI systems into four tiers. The tier is set by what the system is used for, not by how advanced the model is, so a simple model in a hiring decision carries more obligation than a sophisticated one in a spam filter.
Unacceptable risk (prohibited)
Banned outright under Article 5, and these prohibitions have applied since 2 February 2025. They cover social scoring by public authorities, manipulative or exploitative techniques that target vulnerable groups, untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and schools, and most real-time remote biometric identification in public spaces for law enforcement. The Digital Omnibus agreement of May 2026 added non-consensual intimate imagery and child sexual abuse material, including nudification tools, to this list. If a system lands here, there is no compliance path. It cannot be placed on the EU market.
High risk
The tier that carries the real compliance weight: risk management, data governance, technical documentation, logging, human oversight, accuracy and security requirements, plus conformity assessment before going to market. Two routes lead into it. Annex III lists standalone use cases including biometrics, critical infrastructure, education, employment and worker management, essential public and private services such as credit scoring and insurance pricing, law enforcement, migration and border control, and administration of justice. Annex I covers AI embedded as a safety component in products already regulated under EU product law, such as medical devices, machinery and vehicles.
Under the Digital Omnibus, Annex III obligations apply from 2 December 2027 and Annex I from 2 August 2028. Note that self-assessing out of high risk is no longer a private decision: an Annex III provider that concludes its system is not high risk still has to register that determination in the EU database under Article 6(3).
Limited risk (transparency obligations)
No conformity assessment, but disclosure duties under Article 50. People must be told when they are interacting with an AI system, when content is AI-generated, and when emotion recognition or biometric categorisation is being applied. Synthetic content needs machine-readable marking. These watermarking and disclosure obligations apply from 2 December 2026, which makes them the nearest live deadline for most organisations shipping generative features.
Minimal risk
Everything else, and in practice the large majority of AI in use: spam filters, recommendation engines, inventory forecasting, productivity tooling. No obligations under the Act beyond general law. Voluntary codes of conduct are encouraged, and many organisations apply their internal standards here anyway for quality and reputational reasons.
Where GPAI fits
General-purpose AI models sit on a separate track rather than in these four tiers. They carry their own transparency and documentation duties, with additional obligations for models judged to pose systemic risk. A general-purpose model can still end up inside a high-risk system once someone deploys it for an Annex III purpose, and the obligations then follow that use.
One system can touch more than one tier. A recruitment platform doing CV ranking is high risk under Annex III, while its candidate-facing chatbot carries Article 50 transparency duties. Classify by use case, not by product.
Examples of risk classification in practice
A financial institution developing an AI-powered credit scoring system classifies it as high-risk under the EU AI Act due to its impact on access to essential services. This triggers requirements for risk documentation, human oversight, and post-deployment monitoring.
Meanwhile, a media platform experimenting with content recommendation AI classifies its system as limited risk. They apply transparency measures like user notifications but are not subject to strict conformity assessments.
In both cases, having a predefined risk classification helps streamline decisions and regulatory alignment.
Best practices for classifying AI risks
An effective classification process should be embedded early in the development lifecycle.
Start with a context analysis. Understand how the AI system will be used, who it impacts, and what the potential consequences of failure are. Use structured frameworks such as the ISO/IEC 23894 AI risk management guideline or NIST AI RMF to identify relevant risk categories.
Use cross-functional teams. Involve legal, technical, product, and ethics experts to make sure risks are considered from multiple perspectives. Classify risks based on likelihood and impact, then map them to mitigation responsibilities.
Review the classification regularly. AI systems evolve, and so should the understanding of their risk profiles.
Expanding the taxonomy – new areas of focus
As AI technologies grow more complex, risk classification frameworks are expanding. Emerging areas include:
-
Environmental risk: Energy consumption and carbon footprint of large-scale models
-
Supply chain risk: Dependence on third-party models or data providers
-
Misinformation and manipulation: Risks from generative AI, including deepfakes and synthetic content
-
Human autonomy: Systems that may influence decisions or behavior without awareness or consent
Recognizing these categories helps institutions keep pace with evolving threats and expectations.
FAQ
What is the purpose of AI risk classification?
It helps organizations understand, prioritize, and manage different types of risks AI systems can introduce, especially in high-impact use cases.
Who defines the risk categories?
Categories are often defined by regulations (e.g. EU AI Act), standards bodies (e.g. ISO), or internal risk teams using established frameworks.
Can a system fall into more than one risk category?
Yes. A system may have low technical risk but high ethical risk depending on how and where it's used. Classification should consider the full context.
Is classification required by law?
In some jurisdictions, yes. The EU AI Act, for example, requires developers to classify their AI systems and follow corresponding obligations.
What risk classification frameworks are commonly used?
The EU AI Act defines four risk categories: unacceptable, high, limited, and minimal risk. NIST AI RMF provides flexible risk characterization. Many organizations create internal taxonomies combining regulatory requirements with business-specific risks. Choose frameworks that align with your regulatory environment and risk management practices.
How do you classify AI systems when they have multiple uses?
Classify based on the highest-risk intended use. Consider both designed uses and reasonably foreseeable misuse. A system may require different governance in different deployment contexts. Document classification rationale and review when uses change. The EU AI Act's classification is use-case based, not technology-based.
Should risk classification be static or dynamic?
Risk classification should be reviewed periodically and when significant changes occur. Initial classification may need updating as understanding improves or regulations change. New use cases may change risk levels. Establish triggers for classification review. Document classification history and decision rationale.
Summary
Classifying AI risks is a foundational step toward building responsible, compliant, and resilient AI systems. It enables organizations to apply the right level of scrutiny, design appropriate controls, and communicate effectively with regulators and users.
As AI governance becomes a global priority, structured risk classification is one of the clearest ways to bring clarity to complexity
In practice
Most organizations adopt a tiered risk classification (e.g., unacceptable, high, limited, minimal) aligned with the EU AI Act or their own risk appetite. The classification then determines what governance controls apply: high-risk systems require conformity assessments, while minimal-risk systems may only need documentation.