EU AI Act Risk Assessment for WordPress Sites: A Practical Guide
The EU AI Act does not treat all AI systems equally. It uses a tiered risk framework — from outright bans to minimal oversight — that determines what obligations apply to you. If you run a WordPress site that uses any AI-powered feature, understanding your risk tier is the essential first step toward compliance.
The four risk tiers
The EU AI Act organises AI systems into four categories, each with different requirements:
Tier 1: Unacceptable risk — Prohibited AI
These AI systems are banned outright across the EU. No organisation — large or small — may deploy them. Examples include AI systems that use subliminal manipulation techniques to distort human behaviour, social scoring systems operated by public authorities, and real-time biometric identification in publicly accessible spaces (with narrow law-enforcement exceptions).
Unless you are running a very unusual operation, your WordPress site will not come close to this category.
Tier 2: High risk — Strict requirements
High-risk AI systems are permitted but must meet a demanding set of obligations: conformity assessments, technical documentation, human oversight measures, transparency obligations, and registration in the EU database. High-risk AI is defined in Annex III of the Act and covers specific domains including biometrics, critical infrastructure, education, employment, essential services, law enforcement, and justice.
Tier 3: Limited risk — Transparency obligations
This is the tier where most WordPress sites sit. Limited-risk AI systems must comply with targeted transparency requirements under Article 50 — primarily: disclosing when users interact with AI chatbots, and labelling AI-generated content. These obligations are relatively lightweight but mandatory from August 2, 2026.
Tier 4: Minimal risk — No mandatory obligations
AI systems that do not fall into the categories above are considered minimal risk. The Act encourages voluntary codes of conduct for these systems but imposes no binding requirements. Examples include AI-powered spam filters, simple recommendation engines for playlists, and most AI-assisted grammar checkers.
Where most WordPress sites land: the Limited risk tier
The vast majority of WordPress sites that use AI fall into the Limited risk tier. Article 50 of the EU AI Act establishes the key obligations for this category:
- Article 50(1): Inform users when they are interacting with an AI chatbot, before or at the start of the interaction
- Article 50(4): For text published on matters of public interest (elections, public health policy), disclose when AI generated or substantially modified it — commercial text is not in scope
These are the obligations you most likely need to address. They apply regardless of whether the AI model is built by you or by a third party (Intercom, Tidio, ChatGPT API, etc.) — what matters is that you deploy the system on your site.
What makes a WordPress site HIGH risk?
Most WordPress sites will never enter the high-risk tier, but you should be aware of the features and plugins that could change that assessment. High-risk designation under Annex III applies when AI is used for:
Recruitment and HR
Plugins or integrations that use AI to screen job applicants, rank CVs, or make HR decisions. If your WordPress site includes an AI-powered recruitment module that helps filter candidates, that feature is likely high-risk under the Act.
Credit and financial scoring
Any WooCommerce integration that applies AI-based creditworthiness assessment or lending decisions. This includes certain Buy-Now-Pay-Later integrations that use AI under the hood to determine customer eligibility.
Biometric identification
Facial recognition tools or biometric authentication plugins used to identify visitors or grant access based on physical characteristics.
Education and student assessment
AI systems that evaluate student performance, generate grades, or make decisions about educational outcomes. If you run an e-learning platform with AI-graded assignments, this is a potential high-risk area.
Safety-critical systems
AI that controls or manages safety-critical infrastructure — for example, a WordPress-managed IoT dashboard that uses AI to make operational decisions for physical systems.
If any of these apply to your site, you need to conduct a formal conformity assessment and engage with a legal expert specialising in the AI Act. The obligations are significantly more demanding than for limited-risk systems.
The self-assessment process: what to document
Even for limited-risk sites, conducting a basic self-assessment is good practice — and provides evidence of due diligence if a supervisory authority ever asks. Here is what to capture:
- Inventory of AI systems: List every AI-powered feature on your site. Include third-party plugins, embedded widgets, and integrated APIs.
- Purpose classification: For each AI system, describe what it does and whether it involves interaction with users or generation of content visible to users.
- Risk tier determination: Based on the system's purpose and the Annex III categories, assign a risk tier. Most will land in Limited or Minimal risk.
- Obligations assessment: For each Limited-risk system, document which Article 50 obligations apply and how they are met (or will be met).
- Date of assessment and review schedule: Record when the assessment was conducted and set a review date (annually, or whenever you add new AI features).
Practical self-assessment checklist for WordPress sites
Use this checklist to get started today:
- Do I have a chatbot or AI chat widget on my site? If yes — is it disclosing its AI nature before users type their first message?
- Does my site publish AI-generated text (blog posts, product descriptions, FAQs)? If yes — is there a visible label near that content?
- Does my site use AI-generated images, audio, or video? If yes — are those assets individually labelled?
- Do I use any AI for recruitment, credit scoring, biometrics, student assessment, or safety-critical functions? If yes — consult a specialist immediately.
- Have I created a written record of the AI systems I use and the compliance measures in place?
Start with a site scan
Not sure which AI systems are active on your site? The Legibright scans your site in seconds and identifies AI-powered features that may trigger EU AI Act obligations. It is the fastest way to understand your starting point before beginning a formal self-assessment.
This article is for general information only and does not constitute legal advice. For your specific situation, consult a qualified legal professional with expertise in EU AI Act compliance.