EU AI Act Risk Assessment for WordPress Sites: A Practical Guide

The EU AI Act does not treat all AI systems equally. It uses a tiered risk framework — from outright bans to minimal oversight — that determines what obligations apply to you. If you run a WordPress site that uses any AI-powered feature, understanding your risk tier is the essential first step toward compliance.

The four risk tiers

The EU AI Act organises AI systems into four categories, each with different requirements:

Tier 1: Unacceptable risk — Prohibited AI

These AI systems are banned outright across the EU. No organisation — large or small — may deploy them. Examples include AI systems that use subliminal manipulation techniques to distort human behaviour, social scoring systems operated by public authorities, and real-time biometric identification in publicly accessible spaces (with narrow law-enforcement exceptions).

Unless you are running a very unusual operation, your WordPress site will not come close to this category.

Tier 2: High risk — Strict requirements

High-risk AI systems are permitted but must meet a demanding set of obligations: conformity assessments, technical documentation, human oversight measures, transparency obligations, and registration in the EU database. High-risk AI is defined in Annex III of the Act and covers specific domains including biometrics, critical infrastructure, education, employment, essential services, law enforcement, and justice.

Tier 3: Limited risk — Transparency obligations

This is the tier where most WordPress sites sit. Limited-risk AI systems must comply with targeted transparency requirements under Article 50 — primarily: disclosing when users interact with AI chatbots, and labelling AI-generated content. These obligations are relatively lightweight but mandatory from August 2, 2026.

Tier 4: Minimal risk — No mandatory obligations

AI systems that do not fall into the categories above are considered minimal risk. The Act encourages voluntary codes of conduct for these systems but imposes no binding requirements. Examples include AI-powered spam filters, simple recommendation engines for playlists, and most AI-assisted grammar checkers.

Where most WordPress sites land: the Limited risk tier

The vast majority of WordPress sites that use AI fall into the Limited risk tier. Article 50 of the EU AI Act establishes the key obligations for this category:

These are the obligations you most likely need to address. They apply regardless of whether the AI model is built by you or by a third party (Intercom, Tidio, ChatGPT API, etc.) — what matters is that you deploy the system on your site.

What makes a WordPress site HIGH risk?

Most WordPress sites will never enter the high-risk tier, but you should be aware of the features and plugins that could change that assessment. High-risk designation under Annex III applies when AI is used for:

Recruitment and HR

Plugins or integrations that use AI to screen job applicants, rank CVs, or make HR decisions. If your WordPress site includes an AI-powered recruitment module that helps filter candidates, that feature is likely high-risk under the Act.

Credit and financial scoring

Any WooCommerce integration that applies AI-based creditworthiness assessment or lending decisions. This includes certain Buy-Now-Pay-Later integrations that use AI under the hood to determine customer eligibility.

Biometric identification

Facial recognition tools or biometric authentication plugins used to identify visitors or grant access based on physical characteristics.

Education and student assessment

AI systems that evaluate student performance, generate grades, or make decisions about educational outcomes. If you run an e-learning platform with AI-graded assignments, this is a potential high-risk area.

Safety-critical systems

AI that controls or manages safety-critical infrastructure — for example, a WordPress-managed IoT dashboard that uses AI to make operational decisions for physical systems.

If any of these apply to your site, you need to conduct a formal conformity assessment and engage with a legal expert specialising in the AI Act. The obligations are significantly more demanding than for limited-risk systems.

The self-assessment process: what to document

Even for limited-risk sites, conducting a basic self-assessment is good practice — and provides evidence of due diligence if a supervisory authority ever asks. Here is what to capture:

  1. Inventory of AI systems: List every AI-powered feature on your site. Include third-party plugins, embedded widgets, and integrated APIs.
  2. Purpose classification: For each AI system, describe what it does and whether it involves interaction with users or generation of content visible to users.
  3. Risk tier determination: Based on the system's purpose and the Annex III categories, assign a risk tier. Most will land in Limited or Minimal risk.
  4. Obligations assessment: For each Limited-risk system, document which Article 50 obligations apply and how they are met (or will be met).
  5. Date of assessment and review schedule: Record when the assessment was conducted and set a review date (annually, or whenever you add new AI features).

Practical self-assessment checklist for WordPress sites

Use this checklist to get started today:

Start with a site scan

Not sure which AI systems are active on your site? The Legibright scans your site in seconds and identifies AI-powered features that may trigger EU AI Act obligations. It is the fastest way to understand your starting point before beginning a formal self-assessment.

This article is for general information only and does not constitute legal advice. For your specific situation, consult a qualified legal professional with expertise in EU AI Act compliance.