Running Your First Risk Assessment
Classify your first AI system in about 10 minutes.
Risk classification is the foundation of EU AI Act compliance — every other obligation depends on which risk level your system falls into.
Steps
- Sign in and open Dashboard → Risk Classification.
- Describe the AI system: what it does, who uses it, and in which sector.
- Answer the questionnaire. Questions cover the system's purpose, whether it affects people's access to services, employment, education, credit, or legal outcomes, and how it's deployed.
- Review your result: a risk level with the reasoning behind it, mapped to the Act's articles and Annex III categories.
Tips for accurate results
- Answer for the system as actually deployed, not as designed on paper.
- If you're unsure about an answer, choose the more conservative option — under-classifying risk is the expensive mistake.
- Classify each AI system separately. A company rarely has one risk level; it has one per system.
After classification
- High-risk → generate Annex IV documentation and a FRIA if you're a public-facing deployer.
- Limited risk → add transparency notices (Art. 50).
- Minimal risk → document the classification and move on.
Not sure what to classify first? Run the Shadow AI scanner to inventory what's actually in your codebase.