VeritomeHelp Center
/

Classify a system: risk tier, role and the wizard steps

Classification decides your risk tier and role — which together decide how much you must do. Here are the five wizard steps and how the derogation works.

Updated 15.07.2026

Classification is the hinge of the whole Act. It decides your risk tier and your role, which together decide how much you have to do. The registration wizard walks you through it as five steps and, at the end, seals the decision into a tamper-evident dossier. Aria can propose answers, but a person always confirms — the human decision is the one recorded in your audit trail.

Veritome never hard-codes obligation lists. Every duty is derived by the obligation engine from your system's role, risk tier, Annex III area and behavioural flags (workplace use, chatbot, emotion recognition, content generation, own-name). Change any of these by re-classifying and the obligations update automatically.

The four risk tiers

TierWhat it meansRoughly what's required
ProhibitedBanned outright under Art. 5 (e.g. social scoring, manipulative techniques, untargeted face-scraping, most workplace/education emotion recognition).You cannot place it on the market or use it. Full stop.
High-riskA safety component of a regulated product (Art. 6(1) + Annex I) or listed in Annex III (Art. 6(2)).The full obligation set — risk management, data governance, documentation, human oversight, conformity assessment, registration.
Limited (transparency)Interacts with people, generates content, or recognises emotions.Art. 50 transparency: tell people they're dealing with AI / label synthetic content.
MinimalEverything else (spam filters, game AI, inventory forecasting).No mandatory obligations — voluntary codes encouraged.

Step 1 — Role (and the Art. 25 upgrade)

Pick your position in the value chain. This is role resolution — the engine tailors every obligation to it: Provider (Art. 3(3)), Deployer (Art. 3(4)), Importer (Art. 23), Distributor (Art. 24) or Authorised representative (Art. 22 / 54).

If you choose deployer, distributor or importer, the wizard asks the own-name / substantial-modification question. Answer yes and Art. 25(1) resolves your role to provider for the rest of the wizard — you inherit the provider obligation set. If your resolved role is provider, you're also asked whether your organisation is established outside the EU (Art. 22(1)/54(1) authorised-representative duty).

Step 2 — Model layer (GPAI)

Disambiguate the general-purpose AI question: you use a third-party GPAI model (no Chapter V duty — that's the model provider's); you develop / release a GPAI model (you take on Art. 53, and Art. 55 if it carries systemic risk); or not applicable (a narrow, single-purpose system).

Step 3 — Prohibited screening (Art. 5)

Work through the Art. 5 prohibited-practices checklist, sourced from the in-app regulatory registry. If any practice matches, the system is Prohibited — the wizard blocks registration for use, and reclassifying an existing system into this tier marks it decommissioned.

Step 4 — Risk (Annex I, Annex III area, Art. 6(3), Art. 50)

This step derives the tier:

  1. Annex I safety component (Art. 6(1)) — high-risk only when the system is a safety component of an Annex I product and that product needs third-party conformity assessment.
  2. Annex III area — pick the single high-risk domain, or None of the Annex III domains (biometrics; critical infrastructure; education; employment; essential services incl. creditworthiness; law enforcement; migration; justice & democracy).
  3. Art. 6(3) narrow-task derogation — if you selected an Annex III area, the wizard asks whether the system only performs a narrow procedural or preparatory task. A yes drops the tier to minimal for the wizard — but record the formal assessment (below).
  4. Art. 6(3) profiling guard — a system that performs profiling of natural persons is always high-risk, overriding any derogation claim.
  5. Art. 50 transparency capabilities — tick chatbot, synthetic-content generation and/or emotion recognition. On their own these make an otherwise-minimal system Limited.

Why the tiers can surprise you: the derogation makes an Annex III system minimal, not limited — but any Art. 50 capability flag still attaches its transparency duty independently of the tier.

Step 5 — Review, declaration, create

The wizard shows a live preview of the exact obligations the engine will generate for your (role, tier, area, flags) combination. For any non-minimal tier you tick the declaration: it states the classification is produced by a deterministic rules engine mapping your answers to Articles 5, 6 and Annex III, that it is not legal advice, that you'll re-classify on material change, and that you accept the Art. 99 penalty exposure. Press Create to write the classification and generate obligations.

The formal Art. 6(3) self-exclusion

The quick derogation toggle in Step 4 is a preview switch. The documented record that Art. 6(4) requires is produced by the dedicated Art. 6(3) wizard on the system. See The Article 6(3) exception for the disjunctive test and how to document it.

Reclassification

A system's classification is never frozen. When purpose, data or deployment context changes materially, open the system and choose Reclassify. On save, the engine replaces the obligation set to match the new answers, and the dossier records the change (e.g. Reclassified High-risk → Limited-risk).

Need to act on this?Open Veritome