Skip to content
AI AI Act

EU AI Act Risk Categories

Katri Harjuveteläinen
Katri Harjuveteläinen
AI_and_human

REGULATION

EU AI Act

SUMMARY

The EU AI Act classifies AI systems into four risk categories, determining whether they may be used and which compliance measures apply. Misclassification can result in fines and costly delays.

NEXT STEPS

Organizations should begin by inventorying their AI systems, assessing each system’s risk level, and implementing proportionate compliance measures.

ENFORCEMENT

From 2 August 2026 by national authorities and EU AI Office

 
 

The European Union’s Artificial Intelligence Act (EU AI Act) establishes the first comprehensive legal framework for artificial intelligence. Its risk-based structure places AI systems into four broad categories, with regulatory obligations increasing in line with the potential harm a system may cause.

Organizations that develop, provide, deploy, import, or distribute AI systems in the European Union should assess their systems against this framework and implement the obligations that apply to their risk category.

Contents 

Prohibited AI Systems Pose Unacceptable Risks

High-Risk AI Systems Face Extensive Compliance Obligations

Limited-Risk AI Systems Require Transparency

Minimal Risk AI - No Additional Obligations

Practical Next Steps

Prohibited AI Systems Pose Unacceptable Risks

The EU AI Act prohibits the development, use and offering of any AI system that poses unacceptable risks to fundamental rights and safety. This category includes the following AI practices:
 
  • Subliminal manipulation techniques
  • Exploitation of vulnerabilities 
  • Social scoring
  • Real-time remote biometric identification*
  • Biometric categorization using sensitive attributes
  • Emotion recognition in workplace and educational settings*
  • Untargeted scraping of facial images from internet or CCTV
  • Specific use cases in law enforcement*
  • Nudifiers and generation of unconsentual sexual images.

This obligation means that organizations must ensure prohibited AI systems are not placed on the market, put into service, or used within EU territory. The ban applies regardless of where the system was developed.

Practical Example

A multinational corporation cannot deploy emotion recognition technology to assess employee engagement, motivation, or dissatisfaction in its EU offices, even if the same system operates legally in non-EU locations.

Violations of these obligations may result in significant financial penalties, including fines of up to €35 million. The severity of these sanctions highlights the importance of identifying prohibited AI practices before deployment and maintaining effective compliance controls throughout the system’s lifecycle.

High-Risk AI Systems Face Extensive Compliance Requirements

High-risk AI systems face the most extensive regulatory requirements under the EU AI Act. There are two pathways to classifying an AI system as high-risk. 

The first pathway includes products covered by harmonization regulation of the European Union, including medical devices, elevators and aviation equipments. The AI system could be a standalone system or a safety component of the product.

The second pathway includes AI systems for specific applications listed in Annex III. These use cases include:

  • Biometric identification and categorization
  • Management and operation of critical infrastructure
  • Education and vocational training (determining access, assessing learning outcomes)
  • Employment, worker management, and access to self-employment (recruitment, promotion, contract termination)
  • Access to essential private services and public assistance benefits
  • Law enforcement (risk assessments, evaluation of evidence reliability)
  • Migration, asylum, and border control management
  • Administration of justice and democratic processes

If the AI systems falls under the high-risk category, extensive obligations apply. The compliance obligations include requirements to implement risk management system, setting up data governance, drafting technical documentation and many more. (See full obligations)

Obligations fall primarily on providers, i.e. those placing systems on the market or putting them into service. Deployers face specific requirements including human oversight implementation, input data monitoring, use according to instructions, and registration duties.

Practical Examples

Recruitment AI: An organization uses AI to screen CVs and recommend hiring decisions. This qualifies as high-risk employment AI requiring comprehensive documentation, risk management, and human oversight.

Medical device AI: A healthcare provider implements AI software analyzing real-time patient conversations to assess depression or anxiety severity. The system likely falls under both EU AI Act high-risk requirements and Medical Device Regulation obligations, requiring dual compliance.

Violations of these obligations can result in significant financial penalties, including fines of up to 15 million € or 3 % of global annual turnover, whichever is higher. Non-compliance may also lead to regulatory scrutiny, operational disruption, and reputational damage. 

Limited-Risk AI Systems Require Transparency

Limited-risk AI systems trigger primarily transparency obligations. While not explicitly defined as a risk category, these systems typically involve human interaction or synthetic content generation.

Under Article 50, providers must inform people when they are interacting with an AI system, unless this is obvious from the context. Providers of generative AI must mark synthetic audio, images, video, and text in a machine-readable format where technically feasible.

Deployers must inform individuals when they use emotion-recognition or biometric-categorization systems. They must also clearly disclose AI-generated or manipulated deepfakes, including images, video, and audio, as well as public-interest text that has not undergone meaningful human review or editorial control.

 

Practical Example

AI Chatbot: government agency implements an AI chatbot on its public website to help citizens navigate services and locate information. The chatbot must clearly disclose to users that they are interacting with an AI system rather than a human agent.

Transparency obligations may also arise under other regulations, particularly GDPR Article 13-14 (information to data subjects) and Article 22 (automated decision-making). Organizations should ensure coordinated compliance across applicable frameworks.

Minimal-Risk AI - No Additional Obligations

Minimal-risk AI systems are not subject to specific obligations under the EU AI Act because they pose little or no risk to safety, health, or fundamental rights. The Act encourages organizations to adopt voluntary codes of conduct, which can demonstrate responsible AI practices and support broader governance goals.

Practical Examples

Spam filtering: Email systems using AI to detect and categorize spam messages

Video enhancement: Creative software applying AI for color correction, resolution enhancement, or editing assistance

While the EU AI Act imposes no specific requirements, minimal-risk AI remains subject to other applicable regulation. GDPR requirements apply where personal data processing occurs. Sector-specific rules may impose additional obligations depending on the application context.

Practical Next Steps

Organizations developing or deploying AI systems in the EU should prioritize three steps:

  1. System inventory: Document every AI system in use or development, including its purpose, data sources, and deployment context.

  2. Risk classification: Apply the EU AI Act’s risk-based framework to each system. 

  3. Implementation planning: Establish timelines and allocate the resources needed to achieve compliance.

    Classification is not always straightforward, particularly for general-purpose AI systems, AI components within larger products, or systems with multiple functions. Organizations facing classification uncertainty benefit from legal assessment early in development or deployment planning.


 

 



Share this post