Even without a legal framework like the EU AI Act, businesses can benefit from classifying risks:

  • High Risk: Impacts jobs, health, safety, rights, or legal outcomes

  • Medium Risk: Influences customer decisions or uses sensitive data

  • Low Risk: Internal productivity tools or non-decision-making systems

💡 Rule of thumb: If people are impacted directly — it’s high risk.