AI risk assessment
Three different exercises go by this name and they are not substitutes for each other. Working out which one you are being asked for saves doing the wrong one thoroughly.
Classifying a system under the EU AI Act, assessing AI risk across your organisation, and running a data protection impact assessment are three separate exercises under three separate obligations. Most confusion about AI risk assessment is really confusion about which of them is meant.
Someone asks for an AI risk assessment and everyone nods, and then two people go away and do quite different pieces of work. It is worth being blunt about which one is wanted before anybody starts.
Which of the three do you need?
Classifying a system under the Act. This asks what a specific AI system does, who it affects and which duties therefore attach to it. It is a legal question with a legal answer, and it is per system rather than per organisation. If someone needs to know whether the Act applies to a tool you are about to buy, this is the exercise.
An organisational AI risk assessment. This is part of running a management system: what AI you use, what could go wrong across all of it, and what you are doing about that. ISO/IEC 42001 builds this into its planning requirements (ISO/IEC 42001:2023). It is the exercise a board or a customer usually means, and it is not something the Act asks for.
A data protection impact assessment. A separate obligation under data protection law, triggered by processing likely to result in a high risk to people rather than by anything in the AI Act. The ICO guidance on AI and data protection covers when one is required and what it has to contain. A system can be outside the AI Act entirely and still need one.
They overlap in evidence but not in purpose, so doing one does not discharge another. The rest of this page is about the first, because that is the one the Act actually governs.
How classification under the Act works
The Act does not hand you a single risk score. It does several distinct things, and a system can be caught by more than one of them at once.
A short list of practices is prohibited outright at Article 5, and those bans are already in force. Certain uses are treated as high-risk, either because they appear in the categories at Annex III or because the AI is a safety component of a product already regulated under EU harmonisation law at Annex I. Separately from all of that, transparency duties attach to AI interactions and AI-generated content at Article 50, whatever category the system sits in.
You will see this drawn as a neat four-level pyramid of unacceptable, high, limited and minimal risk. It is a useful teaching shorthand, and it is not the structure of the Regulation. If you are making a decision rather than explaining one, work from the actual provisions.
Prohibited practices and high-risk systems and Annex III work through those two categories properly.
Your role changes the answer
This is the step most classification work skips, and it is where the public compliance tools tend to leave people stranded. The Act attaches duties by role as well as by system. It separates providers from deployers, along with importers, distributors and product manufacturers, and one organisation can hold different roles for different systems (Articles 2 and 3).
A provider develops an AI system or puts it on the market under its own name. A deployer uses one under its own authority. Buy a tool and you are usually a deployer; modify it substantially or put your own name on it and you may have become a provider, with a much heavier obligation set attached. Answering "is this high-risk?" without first answering "what are we, here?" produces a confident answer to the wrong question.
When the duties actually bite
The categories apply now; a lot of the obligations do not yet. Under Regulation (EU) 2026/1744, the stand-alone high-risk obligations moved to 2 December 2027 and the product-embedded ones to 2 August 2028.
That deferral is not a reason to postpone the classification. Knowing which of your systems sit in those categories is what tells you how much work is coming and when, and the prohibitions and transparency duties were not deferred at all. The timeline after the omnibus sets out what moved and what did not.
Doing it without building a spreadsheet
For most organisations this is a short exercise repeated per system rather than a project. List the AI systems you actually run, including the ones that arrived inside software you already licensed. For each, settle your role, then work through the prohibitions, the high-risk categories and the transparency duties in that order. Write down the answer and the reason, because the reason is what you will need when someone asks in a year.
The EU AI Act check on this site runs that sequence for one system at a time and gives you the reasoning alongside the answer, which is the part worth keeping.