Skip to main content

Boardroom Answers · Strategic Command · Risk Management & Governance

EU AI Act Risk Classification: Where a Platform Sits

The question a Board Member / Non-Executive Director (NED) asks: The EU AI Act is now enforcing. Where does your platform sit under it — and is any of it high-risk?

The short answer

One open item, stated up front: whether our workforce modules hit Annex III high-risk awaits counsel sign-off — and we run them at the high-risk control bar meanwhile. The rest of the platform is human-in-loop decision support whose architecture reads like the Act’s own checklist: logging, oversight, traceability, robustness.

The full executive answer

Here is our classification analysis, including the one open item — and I will give you the open item first because you would find it anyway. The Act’s Annex III lists high-risk uses, and one of them is AI used in employment and workforce decisions — promotion, task allocation, performance evaluation. A subset of our 68 modules touches workforce and organisational diagnostics, and whether our specific implementations fall inside Annex III is a legal judgment we have deliberately not self-certified: it is awaiting qualified counsel sign-off, and until that opinion lands we treat those modules to high-risk-grade controls as a matter of engineering conservatism. I would rather tell a board "counsel review pending, controls built to the higher bar" than hand you a self-serving classification.

For the platform generally: most modules are decision-support for strategy, risk and governance analysis with a human decision-maker in the loop — a posture the Act treats far more favourably than autonomous decision systems, and the Act’s high-risk obligations read like our architecture document: risk-management system, logging and traceability, human oversight, accuracy and robustness measures. Concretely we ship: append-only hash-chained logging of every generation; mandatory human approval gates; documented model governance across two providers with adjudication; provenance validation on quantitative output; and prompt-injection and personal-data protections on everything entering a model. Alignment with ISO/IEC 42001 — the AI-management-system standard that is emerging as the practical route to demonstrating Act compliance — is the architectural spine, with certification itself on the roadmap after SOC 2.

Also relevant to a director: the Act primarily binds providers and deployers of AI systems — your organisation, as deployer, carries its own obligations when using any AI, including human-oversight and usage-transparency duties. A governed platform materially eases your deployer obligations compared with the ungoverned chatbot use almost certainly already occurring in your organisation — that comparison, not perfection, is the honest baseline for this conversation.

Grounded in: EU AI Act (Annex III; deployer obligations) · ISO/IEC 42001

Want this answered live, on your data?