Skip to content

Example output · AI Compliance Officer AI

What the AI System Risk Classification (EU AI Act) actually produces

Takes a description of an AI system (what it does, who deploys it, where it operates) and produces a directional read on likely EU AI Act risk tiers, plus GPAI and US state overlay flags, with a rationale and a list of open questions to route to legal counsel and any notified body.

Real output from this tool's promptEmployment-use AI hiring tool risk screenGenerated 2026-08-29
The input
System Description:
AI-based resume screening and candidate ranking tool using an LLM (Claude Sonnet 5) to score applicants against job descriptions and generate shortlists for recruiters.
Intended Purpose:
Automate initial screening of job applications to reduce recruiter workload and surface top candidates for open corporate roles.
Deployment Jurisdictions:
European Union (Germany, France), United Kingdom, and United States (California, Illinois, Colorado)
Provider Vs Deployer Role:
Our company is the deployer; the underlying model and screening platform are licensed from a third-party HR-tech vendor (provider)
System Context:
Integrated into existing ATS (applicant tracking system); recruiters review AI-generated shortlist before making outreach decisions; no fully automated rejection without human review.
Likely Risk Tiers & Categories

PRE-LEGAL DIRECTIONAL SCREEN — NOT A DETERMINATION. Likely tier: HIGH-RISK via Annex III(4) Employment (recruitment/selection screening tool). Not prohibited (Article 5) — no evidence of manipulation, biometric categorization for prohibited purposes, or social scoring. Article 6(1) safety-component/Annex I product route: does not appear applicable (no evidence this is a safety component of a regulated product like a medical device or machinery) — flag as unlikely but confirm with counsel. Article 6(3) exemption from high-risk status: POSSIBLY applicable if the tool performs only a narrow procedural task or human-improvement function without replacing human judgment — requires documentation, not assumed. GPAI obligations: Article 51-55 STACK on top of high-risk classification (not instead of) because the system embeds an LLM (Claude Sonnet 5) — provider-side GPAI obligations rest with the vendor, not your company as deployer. US overlays: Colorado AI Act (consequential decision — employment) likely implicated; Illinois has AI-in-hiring notice requirements [CITATION NOT VERIFIED - confirm in current regulation]; NYC Local Law 144 AEDT may apply if any covered role/candidate is NYC-based [CITATION NOT VERIFIED - confirm in current regulation]; California CPRA automated decision-making provisions may apply; EEOC AI guidance on adverse impact/disparate treatment in hiring is relevant regardless of state. This is a DIRECTIONAL SCREEN ONLY — all tier and category flags below require legal counsel and (where applicable) a notified body to confirm.

Rationale Behind Each Flag

ANNEX III(4) EMPLOYMENT — flagged because the system description states the tool 'scores applicants against job descriptions and generates shortlists for recruiters' for 'initial screening of job applications,' which is a recruitment/selection use squarely within Annex III(4)'s employment category (Article 6 + Annex III). This requires legal counsel and (where applicable) a notified body to confirm. ARTICLE 6(3) EXEMPTION — the description notes 'recruiters review AI-generated shortlist before making outreach decisions; no fully automated rejection without human review,' which may support an argument that the system performs a preparatory/decision-support task rather than replacing human assessment. However, ranking and shortlisting candidates plausibly still 'significantly influences' the outcome of the employment decision, so the exemption is not self-evident from the facts given. This requires legal counsel and (where applicable) a notified body to confirm. ARTICLE 6(1)/ANNEX I SAFETY-COMPONENT ROUTE — no facts indicate this system is a safety component of a product under Annex I harmonisation legislation (e.g., medical device, machinery). Flagged as an open question only because this route is commonly overlooked, not because current facts support it. This requires legal counsel to confirm. PROHIBITED (ARTICLE 5) — no facts describe subliminal manipulation, exploitation of vulnerabilities, social scoring, or real-time biometric identification in public spaces for law enforcement; no basis to flag this tier. PROVIDER/DEPLOYER SPLIT — your company is DEPLOYER; the HR-tech vendor is PROVIDER of the underlying model/platform. If Annex III(4) high-risk status is confirmed: PROVIDER (vendor) obligations include Article 9 (risk management system), Article 10 (data governance), Article 11 (technical documentation), Article 12 (record-keeping/logging capability), Article 13 (transparency/instructions for use), Article 14 (human oversight design), Article 15 (accuracy/robustness/cybersecurity), Article 16 (umbrella — CE marking, conformity assessment, declaration of conformity, quality management system per Article 17). DEPLOYER (your company) obligations include Article 26 — use per provider instructions, assign human oversight to competent trained persons, ensure input data (job descriptions, applicant data) is relevant/representative, monitor operation, retain automatically generated logs for at least 6 months, inform workers before deployment in the workplace, and report identified risks/serious incidents to the provider and relevant authorities. ARTICLE 27 FRIA — does NOT automatically apply to your company; it binds public-law bodies, private entities providing public services, and specified high-risk deployer categories. A private corporate employer using this tool for internal hiring is unlikely to fall within Article 27's scope absent additional facts, but this must be confirmed with counsel, not assumed. GPAI STACKING — because the platform uses an LLM (Claude Sonnet 5), Article 53 baseline GPAI provider obligations (technical documentation, downstream information, copyright policy, training summary) attach to whichever entity qualifies as the GPAI model provider — likely Anthropic or the HR-tech vendor depending on contractual structure, not your company as deployer. Article 55 (systemic-risk GPAI obligations) only applies if that model is designated as GPAI-with-systemic-risk under Article 51 — no facts here indicate that designation. These GPAI obligations STACK WITH, not replace, the Annex III(4) high-risk analysis above. This requires legal counsel to confirm which entity holds GPAI provider status. APPLICABILITY DATE — if confirmed high-risk under Annex III(4) employment, the applicable date is 2 August 2028 (employment/education/essential-services category under existing Union harmonisation legislation), not the general 2 December 2027 date — confirm with counsel which date governs this specific deployment.

Follow-Up Questions for Counsel & Notified Body

FOR INTERNAL LEGAL: (1) Does the vendor's shortlisting/scoring function constitute 'significantly influencing' the employment decision under Annex III(4), or can we document an Article 6(3) exemption (preparatory task / human-improvement / no intent to replace human assessment)? What documentation would substantiate this? (2) Confirm our role is solely deployer — does any customization, fine-tuning, or re-training of the vendor's model by us shift any provider obligations onto our company? (3) Is Article 27 FRIA triggered — are we a private entity providing a public service in this context, or does any Annex III high-risk deployer category apply to us specifically? (4) Which entity (Anthropic, the HR-tech vendor, or us) is the GPAI model provider under Article 53, and has that GPAI model been designated as carrying systemic risk under Article 51? (5) Confirm whether the Article 6(1)/Annex I safety-component route is genuinely inapplicable given no product-safety integration exists. (6) Which applicability date governs — 2 August 2028 (employment category) — and what is our compliance runway? FOR EXTERNAL ADVISORS: (7) Obtain the vendor's technical documentation, declaration of conformity (if issued), and CE marking status if Annex III(4) high-risk is confirmed. (8) Confirm Colorado AI Act consequential-decision obligations and timeline for employment-related AI systems. (9) Confirm current requirements under Illinois AI hiring-notice law and NYC Local Law 144 AEDT if any candidates/roles touch those jurisdictions [CITATION NOT VERIFIED - confirm in current regulation for both]. (10) Confirm California CPRA automated decision-making disclosure requirements applicable to this use case. (11) Assess EEOC adverse-impact/disparate-treatment exposure given AI-driven ranking across EU/UK/US candidate pools. FOR NOTIFIED BODY INTAKE (if provider conformity assessment is confirmed required): (12) Ask the vendor to confirm whether they have engaged, or intend to engage, a notified body for conformity assessment of the Annex III(4) system, and request the assessment scope/status. (13) Request the vendor's Article 12 logging architecture and Article 11 technical documentation to confirm our Article 26 log-retention (minimum 6 months) and monitoring obligations can be met on our end. All items above are preparatory only — final tier classification, exemption applicability, and conformity assessment scope must be confirmed by legal counsel and, where applicable, a notified body.

What to edit for your situation

Replace the system description, intended purpose, deployment jurisdictions, and provider/deployer role with the actual AI system under review, including as much detail as possible on human review steps and any product-safety integration, since the classification hinges on those specifics.

Human review: This is a pre-legal directional screen only, not a regulatory or legal determination, so every flagged tier, cited article, and jurisdictional overlay must be independently verified with qualified counsel and, where applicable, a notified body before any compliance decision is made.

Generate this for your own situation — free.

5 runs a day, no credit card.

Try the AI System Risk Classification (EU AI Act)

← Browse more example outputs