Member Engagement and the EU AI Act: Which Risk Category Does Your Organisation Fall Into?

Author

EU AI Act risk categories for membership organisations using AI to analyse member engagement.

Membership organisations are increasingly using technology to understand engagement.

Event attendance, email interactions, website activity, community participation, learning, volunteering and other signals can all help build a clearer picture of how members are interacting with their organisation. Increasingly, AI can also be used to analyse those signals, identify patterns or recommend what happens next.

The EU AI Act doesn’t make this kind of engagement analysis inherently problematic. Instead, it takes a risk-based approach. What matters is how AI is being used, what information it is analysing and what happens as a result.

For membership organisations, most relevant uses are likely to sit at the lower end of that spectrum. But some applications can move into much more heavily regulated territory, and a small number are prohibited altogether.

So how do you know where your organisation sits?

First, does your engagement tracking actually use AI?

Before looking at risk categories, there’s an important distinction to make.

Not all engagement tracking is AI.

If your membership platform records that a member attended three events, opened an email and logged into their account twice, that’s data collection and analytics. A rules-based engagement score, like we use at VeryConnect, usually won’t meet the EU AI Act’s definition of an AI system.

The Act becomes relevant where an AI system is being used, for example, to infer something from member behaviour, predict an outcome, generate a recommendation or contribute to a decision.

So, it’s best to understand first and foremost if you’re simply recording and reporting member activity, or using AI to interpret it and generate predictions, recommendations or decisions.

If AI is involved, the next question is what kind of risk that particular use creates.

Category 1: Prohibited AI practices

At the highest end of the risk framework are uses of AI that the EU considers an unacceptable threat to people’s rights or safety.

These aren’t subject to additional compliance requirements. They are prohibited.

Most ordinary membership engagement tracking comes nowhere near this category, but there are some relevant boundaries organisations should understand.

Emotion recognition in workplaces and education

Imagine an organisation running an online professional development session.

Recording whether somebody attended is one thing. Using AI to analyse their face or voice through their webcam and infer whether they are interested, bored, frustrated or enthusiastic is something quite different.

The AI Act prohibits AI systems used to infer a person’s emotions in workplace and educational settings, except for limited medical or safety purposes.

This distinction is important for professional bodies and membership organisations delivering education or operating in employment-related environments. The type of organisation alone doesn’t determine the classification. The context in which the AI is being used does.

Certain biometric categorisation

The Act also prohibits AI systems that use biometric data to categorise people in order to deduce or infer certain sensitive characteristics, including race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.

Again, this is very different from analysing ordinary membership activity.

How do you know if this applies to you?

Ask: Are we using biometric information such as faces or voices to infer emotions or sensitive characteristics about individual members?

If the answer is no, these particular prohibitions are unlikely to be relevant to your engagement tracking.

If the answer is yes, the context and purpose need careful examination before that technology is used.

Category 2: High-risk AI

The next category is more nuanced.

High-risk AI isn’t prohibited. But the EU Act places much stronger requirements on certain systems because their decisions or outputs can materially affect people’s safety, rights or opportunities.

The Act identifies specific high-risk areas including employment, education, access to certain essential services, biometrics, critical infrastructure, law enforcement and migration.

This is where what you do with an engagement score becomes particularly important.

Imagine an AI system identifies a professional body member as having low engagement.

If that insight simply prompts the membership team to consider sending more relevant communications or checking whether the member needs support, that’s unlikely to make the system high risk on that basis alone.

But imagine engagement analysis is being used in an employment context to evaluate someone’s performance or inform a decision about promotion or termination.

Or an educational organisation uses AI analysis to determine someone’s access to education or their progression.

Those uses can fall into the Act’s high-risk categories.

The dividing line isn’t therefore, “Do we use an AI engagement score?” It’s much closer to “Is AI being used in one of the Act’s specified high-risk areas to materially influence an important decision about a person?”

The Act also contains important detail here. Some AI systems associated with Annex III use cases may not ultimately be treated as high risk where they perform narrow procedural or preparatory tasks and don’t materially influence decision-making. However, AI systems performing profiling of natural persons in those Annex III contexts are treated as high risk. This is one reason organisations should avoid trying to classify complex use cases from a simple checklist alone.

Where a system does qualify as high risk, the obligations are considerably greater, covering areas including risk management, data governance, documentation, logging, human oversight, accuracy and cybersecurity. Under the current timetable, requirements for the relevant Annex III high-risk systems are due to apply from December 2027.

Category 3: Minimal or no risk

This is likely to be the most relevant category for many membership organisations.

The European Commission says the vast majority of AI systems used in the EU fall into the minimal or no-risk category.

For membership management, that could include relatively routine uses of AI that help an organisation understand information or make its services more relevant without making consequential decisions about individuals.

For example, an organisation might use AI to:

  • identify patterns associated with declining participation;
  • suggest content or events based on previous interests;
  • help membership teams identify members who might benefit from additional communication;
  • analyse aggregate engagement trends across its membership;
  • support staff in understanding activity across different member touchpoints.

The important distinction is that the technology is supporting the organisation’s understanding or service delivery rather than autonomously making a high-stakes decision about someone’s employment, education, rights or access to an essential service.

For these minimal or no-risk AI systems, the AI Act does not impose the extensive compliance regime applied to high-risk systems.

That doesn’t mean there are no responsibilities at all.

GDPR and wider data protection requirements still apply where personal data is involved. Organisations should still understand what information they’re collecting, why they’re processing it, how transparent they are with members and whether their use is fair and proportionate.

What about the fourth EU AI Act category?

The European Commission actually describes four levels in its AI Act risk framework.

Alongside prohibited, high-risk and minimal/no-risk AI, is transparency risk.

This covers particular AI uses where people need to know that AI is involved. A familiar example is a chatbot, where somebody should understand that they’re interacting with a machine rather than a person.

There are also transparency requirements around areas including emotion recognition systems and certain AI-generated or manipulated content.

These requirements have applied since August 2026.

For engagement tracking, it can be more useful to think of transparency as an additional obligation that may apply to a particular AI use rather than another level on a simple scale from “safe” to “dangerous”.

An organisation could therefore use relatively low-risk AI while still needing to consider whether particular transparency requirements apply.

So which category does your membership organisation fall into?

The key point is that the organisation itself doesn’t fall into a risk category. The individual AI use case does.

A single membership organisation could have several AI applications with completely different classifications.

A useful starting point is to work through four questions:

  1. Are we using AI at all?
    Recording attendance or reporting email activity isn’t automatically an AI use case.
  2. What information is the AI analysing?
    Ordinary participation data is very different from biometric information or sensitive personal characteristics.
  3. What is the AI doing with that information?
    Is it identifying a pattern, making a recommendation, profiling an individual or making a decision?
  4. What happens because of its output?
    Suggesting an event is very different from influencing someone’s employment, educational opportunities or access to an essential service.

That final question is particularly important.

The same engagement information can create very different levels of risk depending on how it’s used.

Better engagement insight doesn't have to mean more intrusive tracking


There is a broader lesson here for membership organisations.

As AI becomes more sophisticated, better engagement insight doesn’t have to mean collecting increasingly intrusive information about members.

Membership organisations already generate valuable signals through the relationships they have with their communities: events, communications, volunteering, mentoring, learning, payments, community participation and other interactions.

When that information is fragmented across several disconnected systems, understanding engagement can be difficult. But the answer doesn’t necessarily have to be collecting more information.

It can be connecting the information you already legitimately hold.

A connected membership platform can bring those interactions together to create a clearer picture of the member relationship without resorting to unnecessarily invasive forms of monitoring.

That distinction is going to become increasingly important as both membership technology and AI develop.

The goal isn’t to know everything about a member.

It’s to understand enough about their relationship with the organisation to provide better experiences, recognise changing engagement and make better decisions.

And under the EU AI Act, understanding how you’re doing that is just as important as understanding what you’re measuring.

 


 

This article provides general information about the EU AI Act and its potential relevance to membership organisations. It does not constitute legal advice. The classification of an AI system depends on its particular purpose, context and use, and organisations should seek appropriate professional advice where necessary.

Build a clearer picture of member engagement

Understanding member engagement doesn’t have to mean collecting more data. Often, it starts with connecting the information your organisation already holds.

VeryConnect brings membership, events, communications, payments and engagement data together in one connected platform, helping membership teams build a clearer picture of the member relationship and turn that insight into action.

See how VeryConnect helps membership organisations understand member engagement →