The EU AI Act regulates AI systems by risk tier — and the obligations differ dramatically between tiers. TruePrivacy classifies each system in your inventory through a guided questionnaire, then tracks the applicable obligations as compliance tasks.
EU AI Act risk tier classification with obligations per tier

The four risk tiers

TierExamplesObligations
ProhibitedSocial scoring, manipulative or exploitative systems, untargeted facial-image scrapingMust not be deployed. TruePrivacy flags these for immediate escalation.
High-riskEmployment and worker-management decisions, credit assessment, educational access, biometric identification, critical infrastructureConformity assessment, risk management system, data governance, human oversight, logging, transparency, registration
Limited riskChatbots, emotion recognition disclosure cases, AI-generated contentTransparency obligations — users must be told they are interacting with AI or viewing AI-generated content
Minimal riskSpam filters, recommendation tuning, inventory forecastingNo mandatory obligations; inventoried for completeness
High-risk classification hinges on the use case, not the technology. The same language model is minimal risk when summarizing internal notes and high-risk when screening job applicants. Classify each deployment, not each model.

The classification questionnaire

1

Answer guided questions

The questionnaire walks through the deployment context: what the system decides, who is affected, whether it touches an Annex III high-risk category, and whether any prohibited practice applies. Answers are pre-filled from the inventory entry where possible.
2

Review the proposed tier

TruePrivacy proposes a risk tier with the rationale mapped to the specific criteria that triggered it. Legal reviewers can accept the tier or override it with a documented justification.
3

Obligations become tasks

The obligations for the assigned tier are created as tracked compliance tasks with owners and deadlines. High-risk systems also automatically trigger a DPIA workflow, pre-populated from the inventory entry.
4

Reclassify on change

When a system’s use case, data inputs, or affected population changes — or regulatory guidance is updated — the questionnaire is re-opened and the classification refreshed.

Obligations tracking for high-risk systems

For each high-risk system, TruePrivacy tracks the conformity obligations as a living checklist:
  • Risk management system — documented, iterative risk identification and mitigation across the lifecycle
  • Data governance — training, validation, and test data quality criteria, with provenance from the inventory
  • Technical documentation and record-keeping — maintained and exportable
  • Human oversight — documented measures allowing humans to understand, monitor, and override the system
  • Accuracy, robustness, and transparency — performance characteristics documented in the model card
Progress per system is visible on the governance dashboard, and overdue obligations escalate to the system’s business owner.

Conformity documentation

Generate a documentation package per system on demand:
  • The inventory record and model card
  • The classification questionnaire responses and tier rationale
  • Assessment results, including any linked DPIA
  • Obligation checklist status with evidence attachments
The package is formatted for EU AI Act conformity documentation and works equally as a response to DPA inquiries under GDPR.
Run classification before procurement or launch, not after. A prohibited or high-risk determination is far cheaper to handle at design time than after deployment.
GDPR obligations apply in parallel with the EU AI Act wherever personal data is processed — classification here does not replace your DPIA or RoPA duties.