Work note 02 / Classification analysis
Where a classification analysis stops, and counsel begins.
Subject: AI ACT Buddy self-check tool, assessment contract and parser · published 2026-08-23 · method demonstration on our own system
01 / The line
We do not issue the classification. We establish what it depends on.
When a law firm asks whether a client's system is high risk, the answer is a legal determination and it belongs to the firm. What the firm frequently does not have is a defensible technical account of what the system actually does: what it infers, on what inputs, with what degree of autonomy, and whether the thing described in the contract matches the thing running in production.
That account is the work. We write it, we show how each fact was established, and we hand it over. We do not give legal advice, and we do not issue the classification, and both of those sentences appear in our terms as well as here because the reader is usually a lawyer.
02 / The facts established
Six questions of fact, each tied to the provision that makes it matter.
Every row is phrased as a question about the system, not about the law. That is the discipline: the moment a row reads as a conclusion, the analysis has crossed into counsel's territory.
| Question of fact | Anchor | What the answer settles |
|---|---|---|
| Does it infer? | Art. 3(1) | Whether the thing is an AI system at all, or deterministic software that has been described as one in a pitch deck. |
| Whose system is it? | Art. 25 | Whether fine-tuning, rebranding or substantial modification has moved the operator from deployer to provider, and on what date that happened. |
| Which heading does it touch? | Annex III | The area of use, described against the listed headings rather than in the vendor's own vocabulary. |
| Is it a safety component? | Art. 6(1) | Whether the system is a safety component of a product already covered by Union harmonisation legislation. |
| Does the derogation bite? | Art. 6(3) | Whether the system performs a narrow procedural task, or in fact profiles natural persons, which forecloses the derogation. |
| Is it a general-purpose model? | Chapter V | GPAI status, and the distance between the model's training compute and the systemic-risk threshold. |
Provisions are cited to the Official Journal text of Regulation (EU) 2024/1689[04], and re-read on each engagement rather than carried forward from a previous one. The register on this site exists because that field keeps moving.
03 / The worked example
A self-check tool that is allowed to say it does not know.
The subject is AI ACT Buddy, a free self-check tool we publish. It takes a description of a system and returns a provisional characterisation. Running our own classification discipline over it produces the following.
It infers, so Article 3(1) is engaged. The tool does not apply a decision table. It passes a natural-language description to a model and parses a structured judgement back. That is inference from input to output, which puts it inside the definition rather than outside it, and it is the answer we would give whether or not it suited us.
It reports a role as well as a tier. The output carries a role field taking one of provider, deployer, importer, distributor or unknown. Most tools in this category return a risk tier alone, which is close to useless: the same system produces entirely different obligations depending on which end of Article 25 the operator sits at, and the tier without the role cannot tell you what to do next.
It can refuse. The tier enumeration includes not_ai and needs_clarification alongside the four substantive tiers. A tool that must always return an answer will always return one, and a confident wrong tier is worse than an admission that the description was too thin. The same principle governs our own reports: an unestablished fact is written down as unestablished.
It fails loud rather than quiet. If the model's response does not parse, or does not match the expected shape, the tool raises and shows nothing. The error text is explicit that the assessment has not been shown, and the tests pin a no-silent-defaulting guarantee: no missing field is quietly filled with a plausible value. This is the same fail-closed posture we look for on engagements, and it is rarer than it should be.
It carries its assumptions. The output includes an assumptions field and a confidence level. An analysis that does not state what it assumed cannot be re-performed, and re-performance is the safeguard that lets classification work sit on the audit side of our independence wall at all.
04 / Where it stops
Four things this analysis does not tell you.
It does not tell you the system is high risk. It tells you the system performs CV screening for recruitment, which is a fact, and that recruitment appears in Annex III, which is also a fact. Whether the two meet in this instance is the determination, and it is counsel's.
It does not resolve the Article 6(3) derogation. We can establish that a system performs a narrow procedural task and that it does or does not profile natural persons. Whether the derogation is available on those facts is a legal reading, and it is the reading most likely to be contested.
It is not an audit. A classification analysis establishes what a system is. An audit tests whether stated controls operate. Under ISAE 3000 these are different engagements with different assurance levels[03], and describing one as the other is the single most common misrepresentation in this market.
AI ACT Buddy is not an audit either, and it says so. It sits on the other side of our independence wall: a free tool, not a service line, not evidence, and not something we would ever cite in an opinion.
One further limit worth stating: this note characterises a system we built, which is exactly the position we would disclose and re-perform around if the same system ever came to us for audit. Prior classification work does not bar a later audit, but it is disclosed before the engagement is accepted, and the audit team re-performs the analysis rather than relying on it. The self-interest threat here is named in the IESBA framework[05], and naming it is how it gets managed.
05 / The frame
Context, data and input, model, task and output.
The four dimensions we characterise a system against are the OECD's[02], adopted into the NIST AI Risk Management Framework[01]. We use them because they are public, primary and widely adopted, which means a determination built on them can be defended in front of someone who did not commission it. We do not build our published method on any competitor's framework, with or without attribution.
Acting for a client who needs this established?
Tell us the determination you need to reach and what you have been given so far. We will tell you which facts are establishable, which are not, and what the analysis would cost to run.