Skip to main content
Risk Tiers Won't Save Your High-Risk AI SystemEU AI Act & GPAI
4 min readFor Model Risk & Assurance Teams

Risk Tiers Won't Save Your High-Risk AI System

Many believe that reclassifying an AI system into a lower risk category solves compliance issues. Model risk teams often debate whether their system truly meets the "high-risk" threshold under Annex III. Legal teams draft arguments to claim their recruitment tool only "performs a preparatory task" or their credit model merely "improves the result of a previously completed human activity." The goal: avoid the full weight of Articles 8-17.

It's understandable. High-risk obligations are substantial. You're looking at a risk management system, data governance protocols, technical documentation under Annex IV, automatic event logging, human oversight design, accuracy and robustness requirements, and a quality management system. That's a significant compliance lift.

But here's the problem: gaming the risk tier doesn't eliminate your actual model risk.

Why Classification Arguments Miss the Point

The AI Act's risk tiers address regulatory compliance, not operational model risk. If your system makes consequential decisions about employment, creditworthiness, or access to services, it carries inherent risks regardless of how you classify it under Article 6.

Consider what happens when you successfully argue your recruitment AI "only performs a preparatory task." You've avoided the Article 9 data governance requirements. You don't need to document your training dataset's representativeness or demonstrate you've addressed errors and gaps. You've sidestepped the Article 13 transparency obligations around record-keeping.

Then your model systematically screens out qualified candidates from protected groups because your training data reflected historical hiring biases. You have no documentation of your data quality checks. No logged decisions for audit review. No systematic human oversight design.

You've reduced your regulatory burden. You haven't reduced your liability exposure, reputational risk, or the actual harm your system might cause.

Evidence From Adjacent Frameworks

Look at how SR 11-7 approaches model risk in financial services. The framework doesn't offer risk tier exemptions. A model used for "preparatory" credit analysis still requires validation if it influences lending decisions. The principle: if a model affects business outcomes or carries potential for adverse impacts, it warrants controls proportional to those impacts.

ISO/IEC 23894 reinforces this through contextual risk factor analysis. The standard asks you to evaluate AI system risks based on actual deployment context, not regulatory classification. A "minimal risk" chatbot becomes high-stakes when deployed in mental health support. A "limited risk" emotion recognition system carries different implications in employee monitoring versus video game interfaces.

The General-Purpose AI Code of Practice takes a similar stance. Even open-source models with lighter obligations under Article 53 must address copyright compliance and publish training data summaries. The regulatory tier doesn't eliminate baseline responsibilities.

What to Do Instead

Stop optimizing for classification and start building proportional controls based on actual risk.

Map your real exposure. What decisions does your AI system influence? Who's affected? What's the magnitude of potential harm? Your recruitment tool might not meet the Article 6 high-risk criteria, but if it filters 10,000 applications monthly, you're making consequential decisions at scale. Design your controls for that reality.

Implement core practices regardless of tier. Data governance, documentation, and human oversight aren't just regulatory checkboxes. They're how you build reliable systems. If you can't explain what data trained your model, you can't assess its limitations. If you don't log decisions, you can't investigate failures. These practices protect you whether the AI Act categorizes your system as high-risk or not.

Document your classification reasoning. Article 6 requires providers who believe their Annex III system isn't high-risk to document that assessment before market placement. Don't treat this as a formality. Use it to articulate your actual risk position. If you're arguing your system only performs preparatory tasks, specify exactly what human review follows and how it addresses the system's limitations.

Build for the next regulatory cycle. The AI Act includes provisions for Annex III amendments. Use cases can be added through delegated acts. If your system sits in a gray area now, assume regulators will clarify it later. Controls you implement today become your baseline, not technical debt you'll need to retrofit.

Align with your existing model risk framework. If you're in financial services, your SR 11-7 program already requires validation, ongoing monitoring, and governance for models that influence business decisions. Don't create a separate, weaker process for "non-high-risk" AI systems. Integrate AI Act considerations into your existing tiering and validation approach.

When Classification Arguments Are Valid

Not every system needs the full Article 8-17 treatment. The Act's tiering structure serves a purpose.

If you're building AI-enabled spam filters or video game NPCs, minimal-risk classification is appropriate. These systems don't make consequential decisions about individuals. The potential for harm is genuinely low. Spending resources on elaborate governance would be disproportionate.

Similarly, if your system truly performs a narrow procedural task with no influence on substantive outcomes, the Article 6 carve-outs apply legitimately. A tool that formats data for human review, with no filtering or prioritization, sits outside high-risk obligations for good reason.

The distinction: these are systems with minimal actual risk, not high-stakes systems you've reclassified through creative interpretation.

Your classification argument is valid when it reflects reality, not when it's a compliance strategy. If you're spending more time on the argument than on building appropriate controls, you've already answered the question about where your system belongs.

The AI Act's risk tiers are regulatory scaffolding. Your model risk is structural. Build for the structure, not the scaffolding.

You Might Also Like