The classic trap
Recital 26 sets the reading grid of the AI Act: a risk-based approach with four tiers (unacceptable, high-risk, limited risk, minimal risk). The practical trap is misclassifying your own AI systems. Many organisations believe they operate 'limited risk' tools when in fact they run a high-risk system within the meaning of Annex III (HR, credit scoring, education, access to essential services). The EU AI Office and the future Luxembourg market surveillance authority will challenge your classification first, and 80% of your compliance burden depends on that qualification.
The defensible classification method
For each AI system deployed or developed, you must document a structured classification analysis:
- Identify the real purpose of the system, not its marketing name (an 'HR assistant' may be a CV-screening system = high-risk Annex III point 4).
- Check whether the purpose falls within a prohibited practice under Article 5 (social scoring, subliminal manipulation, emotion recognition at work, sensitive biometric categorisation).
- Cross-reference with Annex III for the eight high-risk domains.
- Verify Article 50 transparency obligations (chatbots, deepfakes, generated content).
- Document the decision with its justifications, dated and signed, so it can be defended during an inspection.
- Reassess the classification at every change of purpose or material functionality.
Without this formalised analysis, you are by default in a weak position: the regulator will presume the most demanding classification.
How Luxgap automates this risk
Our Luxgap AI Risk Classifier removes classification uncertainty by doing the work for you: a specialised LLM agent reads the technical documentation of each of your AI systems (model cards, functional specs, vendor contracts, system prompts) and produces a defensible AI Act qualification in under 10 minutes per system. The tool connects directly to your Confluence, SharePoint M365, Azure ML, AWS SageMaker, Vertex AI and GitHub to automatically inventory AI systems in production and development, without relying on a form filled in by business teams.
- Automatically detects deployed AI systems by cross-referencing Azure OpenAI logs, active SageMaker endpoints, API calls to OpenAI/Anthropic/Mistral and imported Hugging Face models.
- Classifies each system across the four AI Act tiers using Annex III, Article 5 and Article 50 criteria, with a confidence score and the textual evidence supporting the decision.
- Alerts in real time on Teams or Slack as soon as a new AI system appears in the IT environment and requires qualification.
- Generates classification records ready for the Article 49 register (high-risk) or internal Article 26 accountability documentation.
- Automatically reassesses the classification when the system prompt, underlying model or documented purpose changes.
- Produces a cryptographically sealed time-stamped PDF report, defensible before the EU AI Office and the Luxembourg market surveillance authority during an inspection.
Available as part of a Luxgap DPO or CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real AI systems, with a free 48-hour blank audit to map your AI Act exposure before any engagement.