Interpreting Your Results
What each risk level requires you to do next.
Your classification result maps directly to a to-do list. Here's how to read it.
Prohibited
Stop deploying the practice in the EU — this has been enforceable since February 2025. There is no compliance path for prohibited practices; the remediation module suggests redesigns that step out of Art. 5 territory.
High-risk
Your obligations, roughly in build order:
- Risk management + data governance — documented processes (Art. 9–10).
- Annex IV technical documentation — the core evidence file. Start with the generator.
- FRIA — if you're a public body or provide essential services, a fundamental-rights impact assessment (Art. 27).
- Human oversight — a named mechanism, not a vague intention (Art. 14).
- Conformity assessment + Declaration of Conformity + CE marking (Art. 43/47/48).
- EU database registration before putting the system into service (Art. 49).
- Post-market monitoring plan and incident reporting (Art. 72–73).
Limited risk
Implement Art. 50 transparency: tell users they're interacting with AI, label AI-generated content, disclose emotion recognition or biometric categorisation where lawful. The transparency generator produces these notices.
Minimal risk
Keep the classification record. That's your evidence the assessment happened — surprisingly valuable in due diligence and audits.