VeritomeHelp Centre
/
Browse documentation
Using Veritome

Classify a system: the guided flow, screen by screen

Classification decides your risk tier and role, which decide what you must do. Eight screens and a review — role, Art. 25, GPAI, Art. 5, Annex III, Art. 6(3), Art. 50 and the five GDPR questions.

Updated Veritome documentation

Classification is the hinge of the whole EU AI Act. It decides your risk tier and your role, which together decide how much you have to do. Registration and classification are one guided flow — eight screens, then a review — and nothing is created until you confirm on the last screen. Aria can draft the reasoning at the end; the answers, and the classification, are yours, and the human decision is what your audit trail records.

Veritome never hard-codes obligation lists. Every duty is derived by the obligation engine from the system's role, risk tier, Annex III area, its behavioural flags and its GDPR answers. Change any of them by re-classifying and the obligations follow.

The four risk tiers

TierWhat it meansRoughly what is required
ProhibitedBanned under Art. 5 (social scoring, manipulative techniques, untargeted facial-image scraping, emotion recognition in the workplace or education, and the rest of the list).It cannot be placed on the market or used.
High-riskA safety component of an Annex I product (Art. 6(1)) or a use listed in Annex III (Art. 6(2)).The full set — risk management, data governance, documentation, human oversight, conformity assessment, registration.
Limited (transparency)Interacts with people, generates content, or recognises emotions.Art. 50 transparency: tell people they are dealing with AI; label synthetic content.
MinimalEverything else.No mandatory obligations beyond Art. 4 literacy; voluntary codes encouraged.

Screen 1 — System

Name the system and say what it does in a sentence or two. This is the text the engine and Aria read back on the review screen, so make it descriptive. Register a system even if you are not sure it is in scope: running it through classification is the cleanest way to find out.

Screen 2 — Role

Pick your position in the value chain: Provider (you build it, or put your name on it), Deployer (you use a system someone else built), Importer (you bring a non-EU system into the EU market) or Distributor (you make a system available in the chain). Each role has its own obligation set.

Screen 3 — Duties

Two things can change which duty set applies to you:

  1. Art. 27 — is your organisation a public body, or a private entity providing a public service (utilities, healthcare, education, transport, social housing)? This decides whether a fundamental-rights impact assessment applies to a high-risk system you deploy.
  2. Art. 25(1) — three questions: (a) do you put the system on the market or into service under your own name or trademark; (b) have you made a substantial modification not foreseen in the provider's conformity assessment (retraining or fine-tuning, for example); (c) have you changed its intended purpose so that it now falls under Annex III? A yes to any of them resolves your role to provider for the rest of the flow — you inherit the provider obligation set.

Screen 4 — Model

Separate from the risk tier: do you place a general-purpose AI model on the market? Three answers — you use a third-party GPAI model (no Chapter V duty; that belongs to the model provider), you develop or release a GPAI model (you take on Art. 53, and Art. 55 if it carries systemic risk — trained with more than 10²⁵ FLOP, or designated), or not applicable. The same screen asks whether the system is a safety component of a product covered by Annex I harmonisation law (medical devices, machinery, vehicles, toys), which is the Art. 6(1) route to high-risk.

Screen 5 — Prohibited

The Art. 5 prohibited-practices checklist, sourced from the in-app regulatory registry. It includes the two practices added by Regulation (EU) 2026/1744, which apply from 2 December 2026. A match makes the system Prohibited: the flow will not register it for use, and reclassifying an existing system into this tier marks it decommissioned. The screening answer is written onto the Art. 5 obligation so the dossier shows it was asked.

Screen 6 — Risk

Pick the single Annex III area the system falls in, or none (biometrics; critical infrastructure; education; employment; access to essential services including creditworthiness; law enforcement; migration; justice and democratic processes). Choosing employment also sets the workplace AI flag, which adds the deployer's Art. 26(7) worker-information duty. If you named an area, the screen asks the Art. 6(3) question — does the system only perform a narrow procedural or preparatory task (or one of the other listed cases)? A yes takes the system out of the high-risk tier — unless it performs profiling of natural persons, which the final subparagraph of Art. 6(3) says is always high-risk. The flow applies that override for you.

Screen 7 — Transparency

Three Art. 50 triggers, independent of tier: the system interacts directly with people (Art. 50(1)), generates or manipulates synthetic content (Art. 50(2) and (4)), or recognises emotions or categorises people biometrically (Art. 50(3)). Tick what applies; each adds its own disclosure duty, and on their own they make an otherwise-minimal system Limited.

Screen 8 — GDPR

Five questions decide the GDPR rows the engine adds: does personal data flow through the running system; are you controller or processor for it; does it touch special categories (GDPR Art. 9); does it make solely automated decisions with legal or similarly significant effects (GDPR Art. 22); and is any of it transferred outside the EU/EEA (GDPR Art. 44–49). The GDPR obligations are generated per system, next to the EU AI Act ones — see GDPR for AI systems.

Review

The last screen shows the engine's reading — role (and whether Art. 25 upgraded it), tier, area, the Art. 6(3) claim if made, the transparency and GDPR flags — with the obligations it will generate. Aria can draft a paragraph of reasoning here; you can edit or discard it. Tick the declaration (the classification is produced by a deterministic rules engine from your answers, is not legal advice, and you will re-classify on material change) and press Create. The system lands on the register, its obligations are generated, its classification dossier opens with a sealed first entry, and a classification evidence record is minted.

The formal Art. 6(3) self-assessment

The Art. 6(3) answer on screen 6 is what the engine reads. The documented assessment that Art. 6(4) expects — the criteria, the reasoning, who assessed it — is produced by the dedicated wizard at the system's Art. 6 obligation (open it from the Obligations tab; the drawer links to the wizard). It is listed on Assessments as the Art. 6(3) self-assessment. See The Article 6(3) exception for the test itself.

Reclassification

Press Re-classify in the system header. The same eight screens open with the current answers; on confirmation the engine replaces the obligation set, the dossier records the change (for example Reclassified High-risk → Limited-risk), and the classification evidence record is refreshed. A reclassification needs a justification note, and the permission to do it is separate from the permission to edit a system.