Regulation & governance9 min read
EU AI Act Risk Categories Explained With Examples
The four EU AI Act risk categories explained with business examples: prohibited, high-risk, transparency and minimal risk, plus GPAI rules and borderline cases.
Published
The EU AI Act sorts AI uses into four risk categories. Unacceptable risk: a short list of practices that are prohibited outright, such as social scoring or emotion recognition at the workplace. High risk: uses in sensitive areas like recruitment, credit scoring or critical infrastructure, which are allowed but subject to strict requirements. Limited risk: situations with transparency duties, such as chatbots and deepfakes, where people must be told they are dealing with AI. Minimal risk: everything else, such as spam filters or drafting assistants, with no specific obligations under the Act. Separately, providers of general-purpose AI models have their own rules. The category depends on what the AI is used for, not on the technology behind it.
This article explains each category with business examples. It is general information, not legal advice. The Regulation (EU) 2024/1689 contains detailed definitions and exceptions, and guidance continues to develop. Verify specifics against the official text and with qualified counsel.
The core principle: purpose decides
The AI Act regulates uses, not algorithms. The same language model can be:
- minimal risk when it drafts marketing copy,
- limited risk when it talks to customers as a chatbot,
- high-risk when it ranks job applicants,
- part of a prohibited practice if used to infer employees' emotions at work.
That is why classification must be done per use case. The free EU AI Act risk checker walks through the questions for one use case at a time.
Category 1: Unacceptable risk (prohibited)
Article 5 bans certain practices. These prohibitions have applied since 2 February 2025.
| Prohibited practice | Business-relevant example of what is not allowed |
|---|---|
| Manipulative or deceptive techniques causing significant harm | Interfaces designed to subliminally push people into harmful financial decisions |
| Exploiting vulnerabilities (age, disability, social or economic situation) | Targeting financially distressed people with manipulative AI-driven offers that cause significant harm |
| Social scoring leading to unjustified detrimental treatment | Scoring customers on unrelated social behaviour to deny them services |
| Predicting crime risk based solely on profiling or personality traits | Assessing whether a person is likely to commit an offence from personality profiles alone |
| Untargeted scraping of facial images for recognition databases | Building a face database from images collected across the internet |
| Emotion recognition at the workplace or in education | Analysing employees' facial expressions in video calls to assess engagement (exceptions exist for medical or safety reasons) |
| Biometric categorisation inferring sensitive traits | Using face images to infer political views, religion or sexual orientation |
| Real-time remote biometric identification in public spaces for law enforcement | Restricted to narrow exceptions for authorities |
For most businesses, the practical takeaway concerns HR and marketing. Emotion recognition of staff and manipulative targeting are where ordinary companies could stray into prohibited territory.
Category 2: High risk
High-risk AI is allowed but tightly regulated. There are two routes into this category.
Route A: AI in regulated products
AI systems that are a safety component of a product, or are themselves a product, covered by EU product safety legislation listed in Annex I and requiring third-party conformity assessment. Examples include AI in medical devices, machinery, toys, lifts and vehicles. These rules were scheduled to apply from 2 August 2027.
Route B: Use cases listed in Annex III
| Area | Examples |
|---|---|
| Biometrics | Remote biometric identification, biometric categorisation, emotion recognition (where not prohibited) |
| Critical infrastructure | AI as a safety component in managing road traffic or the supply of water, gas, heating or electricity, or digital infrastructure |
| Education and vocational training | Deciding admission, evaluating learning outcomes, steering learning, monitoring exams |
| Employment and workers management | CV screening, ranking candidates, targeted job ads, decisions on promotion or termination, task allocation based on behaviour or traits, performance monitoring |
| Access to essential services | Eligibility for public benefits, creditworthiness and credit scores (not fraud detection), risk assessment and pricing in life and health insurance, emergency call triage |
| Law enforcement | Various uses by or for police authorities |
| Migration, asylum and border control | Risk assessments, application examinations |
| Justice and democratic processes | Assisting judicial decisions, influencing elections or voting behaviour |
These obligations were scheduled to apply from 2 August 2026, though the EU has proposed changes to the timing of some high-risk rules. Check the current official timeline.
The Article 6(3) exception
An Annex III system is not considered high-risk if it does not pose a significant risk of harm, for example because it only:
- performs a narrow procedural task,
- improves the result of a previously completed human activity,
- detects decision-making patterns or deviations without replacing or influencing human assessment without proper review, or
- performs a preparatory task for an assessment.
However, a system that performs profiling of natural persons is always high-risk. A provider relying on the exception must document its assessment, and registration duties may still apply.
Examples of borderline cases
| Use | Likely classification | Why |
|---|---|---|
| AI ranks job applicants by fit | High-risk | Employment, influences selection |
| AI fixes spelling in job ads | Likely not high-risk | Narrow task, no influence on decisions about people |
| AI drafts interview questions from the job description | Likely not high-risk | Preparatory, no assessment of individuals |
| AI scores customers' creditworthiness | High-risk | Essential services, credit scoring |
| AI flags possibly fraudulent payments | Excluded from the credit-scoring category | Fraud detection is explicitly excluded there |
| AI sets individual life insurance premiums | High-risk | Insurance risk assessment and pricing |
| AI summarises an employee's own submitted report | Likely not high-risk | No evaluation of the person |
These are simplified illustrations to show the reasoning, not legal determinations.
What high-risk means in practice
Providers must implement risk management, data governance, technical documentation, logging, transparency to deployers, human oversight design, accuracy and robustness measures, a quality management system, conformity assessment and registration. Deployers must use the system as instructed, assign competent human oversight, monitor it, keep logs, inform workers and affected people, and in some cases carry out a fundamental rights impact assessment. Our article on EU AI Act obligations for deployers covers the deployer side in detail.
Category 3: Limited risk (transparency obligations)
Article 50 sets transparency duties for certain AI systems, regardless of whether they are high-risk:
| Situation | Obligation (simplified) | Who |
|---|---|---|
| AI interacts directly with people | Inform people they are interacting with AI, unless obvious | Provider (design) |
| AI generates synthetic audio, image, video or text | Mark output in a machine-readable way as artificially generated | Provider |
| Deepfakes | Disclose that content is artificially generated or manipulated | Deployer |
| AI-generated text on matters of public interest | Disclose, unless under human editorial review and responsibility | Deployer |
| Emotion recognition or biometric categorisation | Inform the people exposed | Deployer |
Typical business examples: a website chatbot, an AI voice assistant on a hotline, AI-generated product images featuring realistic people, or synthetic video of a spokesperson. These obligations were scheduled to apply from 2 August 2026.
Category 4: Minimal risk
Most AI uses in business fall here: drafting emails, summarising documents, translation, spam filtering, product recommendations, internal analytics, coding assistance, inventory forecasting. The AI Act sets no specific obligations for these systems, though voluntary codes of conduct are encouraged.
Two things still apply:
- AI literacy (Article 4) applies to all providers and deployers regardless of risk. See AI literacy under the EU AI Act.
- Other laws continue to apply, such as data protection, consumer protection, copyright, anti-discrimination and product liability.
General-purpose AI models: a separate track
Large models that can perform a wide range of tasks, the kind behind popular AI assistants, are regulated at the model level. Providers of general-purpose AI models must, among other things, maintain technical documentation, provide information to downstream providers, have a copyright policy and publish a summary of training content. Models with systemic risk face additional duties such as evaluations and incident reporting. These rules have applied since 2 August 2025.
If you only use such a model through an app or API, these model obligations are on the model provider. Your obligations depend on your own use case, as described in the categories above.
How to classify your own use cases
- List each use case, not each tool.
- Check prohibited practices first. If any applies, stop.
- Check Annex I and Annex III. If the use is listed, consider whether the Article 6(3) exception could apply and whether profiling is involved.
- Check transparency situations. These can apply on top of any category.
- Record your reasoning with date and author.
- Get advice for anything high-risk or unclear.
- Reassess when the use changes. Extending a tool to a new purpose can change its category.
Embed this in your internal rules; our guide to an AI acceptable use policy shows how to define uses that require approval.
Common misconceptions
- "We only use a standard tool, so the AI Act doesn't affect us." Deployers have obligations, and a standard tool used for a high-risk purpose is a high-risk use.
- "Generative AI is automatically high-risk." No. Classification depends on purpose.
- "Minimal risk means no rules at all." AI literacy and other laws still apply.
- "The exception covers any human-in-the-loop setup." The Article 6(3) exception is narrow and does not apply to profiling.
- "The dates are fixed." Some have been subject to proposed changes. Check the current text.
Summary
Prohibited practices are banned, high-risk uses are allowed with strict controls, transparency situations require disclosure, and everything else is minimal risk with no specific AI Act obligations beyond AI literacy. Classify by use case, document your reasoning and get advice where the stakes are high. Start with the EU AI Act risk checker for a first orientation on each use case.
FAQ
What are the risk categories of the EU AI Act?
Unacceptable risk (prohibited practices), high risk (allowed with strict requirements), limited risk (transparency obligations) and minimal risk (no specific obligations). General-purpose AI models are regulated separately.
Is a chatbot high-risk under the EU AI Act?
Usually not. A customer service chatbot typically has transparency obligations: people must be informed that they are interacting with AI. It becomes high-risk only if used for a high-risk purpose, such as deciding on access to essential services.
Who decides which risk category applies?
The provider and deployer must assess it based on the system's intended purpose and use. Authorities supervise compliance. When in doubt, seek legal advice and document your reasoning.
Can one AI system fall into several categories?
Yes. A high-risk system can also be subject to transparency duties, and the same underlying model can be minimal risk in one use and high-risk in another. Classification depends on the use case.
Related articles
Regulation & governance9 min read
EU AI Act for Deployers: What Businesses Must Do
EU AI Act obligations for deployers: AI literacy, transparency duties, high-risk use rules, when a user becomes a provider, and a practical checklist.
Regulation & governance7 min read
AI Literacy Under the EU AI Act: What Article 4 Means
What the AI literacy requirement in Article 4 of the EU AI Act means for companies, who it covers, what good training includes and how to document it.
Regulation & governance8 min read
How to Write an AI Acceptable Use Policy for Your Team
How to write an AI acceptable use policy: the sections to include, a copyable outline, a traffic-light data rule, rollout steps and mistakes to avoid.