How the EU AI Act Classifies Risk
The EU AI Act (Regulation (EU) 2024/1689) establishes a risk-based approach to AI regulation. Every AI system used in the EU market falls into one of four risk categories, each with different compliance obligations:
- Unacceptable Risk (Banned): AI systems that pose a clear threat to safety, livelihoods, or fundamental rights. Includes social scoring, real-time biometric identification in public spaces (with limited exceptions), and manipulative AI techniques.
- High Risk: AI systems used in sensitive areas listed in Annex III — including employment, education, law enforcement, critical infrastructure, and migration. These require conformity assessment, risk management, documentation, human oversight, and ongoing monitoring.
- Limited Risk: AI systems with specific transparency obligations, such as chatbots, deepfake generators, and emotion recognition systems. Users must be informed they are interacting with AI.
- Minimal Risk: AI systems like spam filters, AI-enabled video games, and inventory management systems. No specific obligations under the AI Act, though voluntary codes of conduct are encouraged.
Why Risk Classification Matters
Getting your risk classification right is the first and most important step in AI Act compliance. Incorrectly classifying a high-risk system as minimal risk could result in fines up to €35 million or 7% of global turnover. Our free assessment tool walks you through the classification process based on the official Annex III categories and the Article 6 filter mechanism.
What the Assessment Covers
Our risk assessment tool asks you a series of questions about your AI system's purpose, deployment context, and affected individuals. Based on your answers, it determines the applicable risk category and provides tailored next steps for compliance. The assessment is free, requires no registration, and takes approximately 5 minutes to complete.