AI Act classification wizard
The AI Act classification wizard at /assessment/ai-act sorts your AI use into one of five tiers, seeds the matching EU AI Act Essentials obligations, and hard-stops on prohibited practices. This page covers the questions, the tiers, what gets seeded, re-running, and the prohibited hard-stop.
The EU AI Act sorts AI uses into tiers, each with different obligations. ObligoBoard's AI Act classification wizard at /assessment/ai-act walks you through a short set of questions, assigns you a tier, and seeds the matching obligations from the EU AI Act Essentials framework. This page covers the questions, the five tiers, what gets seeded, the prohibited hard-stop, and re-running the wizard.

Who should run it
Run the wizard if your organisation deploys, provides, distributes, imports, or builds general-purpose AI. The first question is your role, and your role together with your use case decides which obligations apply. The roles are:
- Deployer — you use an AI system (Art. 26 deployer duties)
- Provider — you place an AI system on the market (Art. 9/10/15/17)
- Distributor — you make an AI system available (Art. 24)
- Importer — you place a non-EU provider's system on the EU market (Art. 23)
- GPAI provider — you build a general-purpose AI model (Art. 53/55)
- None — your use is out of scope
The questions
The wizard asks up to seven questions. Two are conditional and are skipped when they don't apply, so you see five or seven depending on your path.
- Role — deployer, provider, distributor, importer, GPAI provider, or none
- Use case — any of chatbot, generative content, emotion recognition, biometric categorisation, deepfake, or none (choose all that apply)
- Annex III category — the eight high-risk categories, or none (this replaces the old yes/no high-risk question)
- Public body — shown only if you are a deployer with an Annex III category; drives EU database registration
- GPAI — whether your use involves general-purpose AI
- Systemic risk — shown only for GPAI providers or if you answered GPAI; drives the Article 55 cluster
- Prohibited practices — any of social scoring, real-time biometric identification, emotion recognition in the workplace, or untargeted scraping of facial images (choose all that apply)
Answer honestly — your tier and your obligations follow from your answers.
The five tiers
The classifier assigns one of five tiers:
- Prohibited — a practice banned under Article 5. The wizard hard-stops (see below); no obligations are seeded.
- High-risk (Annex III) — a deployer or provider of an Annex III system. The full high-risk regime applies.
- Limited-risk — Article 50 transparency obligations (disclosure and marking) matched to your use case.
- Minimal-risk — no specific AI Act obligations apply.
- GPAI — general-purpose AI. Article 53 baseline obligations, plus the Article 55 systemic-risk cluster if applicable.
The classifier uses a precedence: prohibited takes priority over everything; GPAI and high-risk are distinct tracks; limited-risk applies where transparency duties bite; otherwise the use is minimal-risk.
What gets seeded
On a non-prohibited classification, the wizard seeds the EU AI Act Essentials framework with the obligations matched to your tier and role. Seeding is additive and idempotent — it adds any newly-matched obligations and skips ones you already have. The set depends on your tier and role; your Obligations page shows the authoritative live set. The matched obligations include, by track:
- High-risk deployer — instructions-for-use compliance (Art. 26), human oversight (Art. 14), log retention (Art. 26(6)), post-market monitoring and incident reporting (Art. 72), AI literacy and staff training (Art. 4), and bias monitoring (Art. 26(5)). Public-body deployers also get EU database registration (Art. 71).
- High-risk provider — AI risk management (Art. 9), data governance and quality (Art. 10), accuracy, robustness and cybersecurity (Art. 15), quality management (Art. 17), and EU database registration (Art. 71).
- Limited-risk — the Article 50 transparency sub-clauses matched to your use case: chatbot disclosure (Art. 50(1)), synthetic content marking (Art. 50(2)), emotion-recognition and biometric-categorisation disclosure (Art. 50(3)), and deepfake and manipulated-content labelling (Art. 50(4)).
- Minimal-risk — nothing. Minimal-risk uses have no specific AI Act obligations.
- GPAI — the Article 53 baseline (technical documentation, downstream-provider information, copyright policy, training-content summary), plus the Article 55 cluster (model evaluation and adversarial testing, systemic-risk assessment, serious-incident reporting to the AI Office, cybersecurity, energy reporting) if you indicated systemic risk.
- Importer — the Article 23 obligations (verification of CE marking and declaration of conformity, conformity assessment, Annex IV technical documentation, and identification and contact details).
- Distributor — the Article 24 obligations (verification of CE marking and declaration of conformity, instructions for use, storage and transport conditions, and cooperation with competent authorities).
Your Obligations page shows the exact set the wizard seeded for you. The list above is the current shape of the EU AI Act Essentials framework; the wizard seeds the subset that matches your tier and role.
The prohibited hard-stop
If your answers indicate a prohibited practice under Article 5, the wizard does not seed obligations. It shows a hard-stop instead: This use cannot be supported. Your answers match practices the AI Act prohibits under Article 5 (in force since 2 February 2025) — ObligoBoard cannot support this use, no obligations are created, and onboarding is blocked.
This is intentional, not an error. The assessment is still recorded for auditability, but ObligoBoard will not build a compliance plan for a practice the AI Act prohibits. Consult qualified counsel on what to do next.
The prohibited outcome is a hard-stop, not a bug. Do not expect obligations to appear, and do not re-run the wizard hoping for a different result — if your answers match a prohibited practice, consult qualified counsel about the correct next step for your organisation.
Re-running the wizard
You can re-run the wizard at any time. Each run is recorded, and the latest classification is the active one shown on your obligations page and dashboard.
Seeding is additive: re-running with a different tier adds any newly-matched obligations, but it does not remove obligations seeded by a previous classification. If your situation changed and you need the old set removed, contact support — the wizard will not delete them for you.