AI Act Risk Categories Explained

Understanding the four-tier risk classification framework

How the Risk-Based Framework Works

The EU AI Act classifies all AI systems into four risk categories based on their potential impact on health, safety, and fundamental rights. The higher the risk, the stricter the compliance requirements. This tiered approach ensures proportionate regulation — minimal-risk systems face no additional burden, while high-risk systems must meet comprehensive obligations.

1. Unacceptable Risk (Prohibited)

These AI practices are banned outright under Article 5 of the AI Act:

  • Social scoring by public authorities
  • Subliminal or manipulative techniques that exploit vulnerabilities
  • Real-time remote biometric identification in public spaces (with limited law enforcement exceptions)
  • Emotion recognition in workplaces and educational institutions
  • Untargeted scraping of facial images for facial recognition databases

Full guide to prohibited practices →

2. High Risk

AI systems listed in Annex III or embedded in regulated products under Annex I must comply with extensive requirements under Articles 9-15:

  • Biometric identification and categorisation
  • Critical infrastructure management (water, gas, electricity, transport)
  • Education and vocational training access and assessment
  • Employment, recruitment, and worker management
  • Access to essential services (credit scoring, insurance)
  • Law enforcement, migration, and border control
  • Administration of justice and democratic processes

Full guide to high-risk AI requirements →

3. Limited Risk (Transparency Obligations)

AI systems with transparency obligations under Article 50 include: chatbots and virtual assistants (users must know they are interacting with AI), deepfake and AI-generated content (must be labeled), emotion recognition systems (subjects must be informed), and biometric categorisation systems.

4. Minimal Risk

The majority of AI systems fall into this category — spam filters, AI-enhanced video games, inventory management systems, and similar tools. No specific AI Act obligations apply, though providers are encouraged to follow voluntary codes of conduct.

How to Determine Your Classification

Use our free risk assessment tool to determine your AI system's risk category, or consult with a verified AI Act compliance expert from our directory for a detailed classification analysis.