Guide
The Four Risk Levels Under the EU AI Act
The EU AI Act uses a risk-based approach — obligations scale with the potential for harm. Here's what each level means for your AI system.
How risk classification works
The EU AI Act classifies AI systems into four risk tiers. The higher the risk, the stricter the obligations. This risk-based approach means not all AI is regulated equally — most AI systems (like spam filters or recommendation engines) fall into the minimal-risk category and face no specific obligations.
Classification is provider-driven: you determine the risk level of your own system based on its intended purpose and use cases. If your system falls under Annex III (high-risk categories) and meets certain conditions, you must comply with the full set of obligations including risk management, technical documentation, and human oversight.
Unacceptable risk — banned
Prohibited entirely
AI systems that pose a clear threat to safety, livelihoods, or fundamental rights are banned in the EU. This includes:
- Social scoring by governments — systems that rate citizens based on social behaviour or trustworthiness
- Real-time biometric surveillance in public spaces (with narrow exceptions for law enforcement)
- Manipulation of vulnerable groups through subliminal techniques
- Emotion recognition in workplaces and educational institutions
- Untargeted facial recognition scraping from the internet or CCTV footage
These prohibitions took effect in February 2025. If your system falls into this category, you cannot deploy it in the EU.
High risk — regulated
Full compliance obligations apply
This is where most of the compliance burden lives. High-risk AI systems include those used in:
- Critical infrastructure — energy, transport, water management
- Education — student scoring, admissions decisions
- Employment — CV screening, worker management, hiring decisions
- Law enforcement — risk assessment, polygraphs, evidence evaluation
- Migration — visa processing, asylum decisions
- Access to services — credit scoring, insurance pricing, emergency services dispatch
- Justice — interpreting facts, applying law to concrete facts
Providers of high-risk AI must implement: risk management (Art 9), technical documentation (Art 11), transparency (Art 13), human oversight (Art 14), accuracy and cybersecurity (Art 15), and quality management (Art 17). The compliance deadline for Annex III systems is December 2, 2027.
Limited risk — transparency obligations
Disclosure requirements only
Systems with specific transparency risks must inform users they're interacting with AI. This includes:
- Chatbots — must disclose the AI nature of the interaction
- Deepfake generators — content must be labelled as AI-generated
- Emotion recognition systems — users must be informed
- Biometric categorisation — users must be informed
The obligation is straightforward: tell people they're interacting with AI. These rules apply from August 2026.
Minimal risk — unregulated
No specific obligations
Most AI systems fall into this category and face no specific obligations under the Act. Examples include:
- Spam filters
- Recommendation engines
- AI-enabled video games
- Inventory management systems
However, providers can still voluntarily adopt codes of conduct to demonstrate responsible AI practices, which can build trust with customers and regulators.
Not sure which category your system falls into?
Use our free risk checker to classify your AI system in 30 seconds.