April 18, 2025

AI Regulation: system classification and compliance requirements

Practical guide to classify AI systems according to risk level and determine the transparency, documentation and governance requirements applicable to each category.

AI Regulation

The AI Act: regulatory framework for artificial intelligence

The EU Artificial Intelligence Regulation (AI Act) establishes the world’s first comprehensive legal framework for regulating AI systems. Its risk-based approach classifies systems into four categories, each with proportionate requirements.

Classification of AI systems by risk level

Unacceptable risk (prohibited)

  • Social scoring systems
  • Real-time remote biometric identification in public spaces (with exceptions)
  • Subliminal manipulation or exploitation of vulnerabilities
  • Emotion inference in workplaces and educational centers

High risk

  • Personnel selection and employee evaluation systems
  • Credit scoring and financial risk assessment
  • AI-assisted medical diagnosis
  • Critical infrastructure management systems
  • Autonomous vehicles and safety components

Limited risk

  • Chatbots and virtual assistants (transparency obligation)
  • Content generation systems (deepfakes)
  • Biometric categorization systems

Minimal risk

  • Spam filters
  • Video games with AI
  • Inventory systems

Requirements for high-risk systems

  1. Risk management system — Continuous assessment throughout the lifecycle
  2. Data governance — Quality, representativeness, and absence of biases in training data
  3. Technical documentation — Detailed description of the system, its purpose, and limitations
  4. Activity logging — Traceability of system operations
  5. Transparency — Clear instructions for operators
  6. Human oversight — Effective human intervention mechanisms
  7. Accuracy, robustness, and cybersecurity — Verifiable technical standards

Application timeline

DateMilestone
August 2024Entry into force
February 2025Prohibitions on unacceptable-risk AI
August 2025Requirements for general-purpose AI models
August 2026General application of remaining provisions (transparency, Article 50)
December 2026New prohibition on NCII/CSAM AI; watermarking deadline for pre-August 2026 systems
December 2027Requirements for high-risk systems (Annex III, standalone)
August 2028Requirements for high-risk systems (Annex I, regulated products)

How to prepare your company?

The first step is to correctly classify your AI systems. Not all require the same level of compliance. At A2 Estudio Legal we conduct classification assessments and design compliance roadmaps tailored to your product. Consult with our team.

Contact us