Understanding these classifications is essential for organizations operating AI systems in the European market.
Certain AI practices are entirely banned within the EU due to unacceptable risks to fundamental rights and safety.
🚫 Prohibited practices include:
The prohibition applies both to the intended purpose and the actual effect of an AI system. An AI system producing manipulative or exploitative effects falls under the prohibition even where such outcomes were unintended.
Compliance consideration: Organizations must ensure prohibited AI systems are not placed on the market, put into service, or used within EU territory. The ban applies regardless of where the system was developed.
Example: A multinational corporation cannot deploy emotion recognition technology to assess employee engagement, motivation, or dissatisfaction in its EU offices, even if the same system operates legally in non-EU locations.
⚠️ High-risk AI systems face the most extensive regulatory requirements under the EU AI Act. Two pathways lead to high-risk classification.
First pathway: AI systems serving as safety components of products covered by EU harmonization legislation (such as medical devices, machinery, or aviation equipment), or products themselves subject to such legislation.
Second pathway: AI systems operating in specific application areas listed in Annex III:
De minimis exception: Annex III systems avoid high-risk classification when they perform narrow procedural tasks, improve human activity results, or detect decision-making patterns—provided they do not replace human assessment and do not materially influence outcomes.
Compliance obligations for high-risk systems include:
Obligations fall primarily on providers (those placing systems on the market or putting them into service). Deployers face specific requirements including human oversight implementation, input data monitoring, use according to instructions, and registration duties.
Examples:
Recruitment AI: An organization uses AI to screen CVs, rank candidates based on predicted performance, or recommend hiring decisions. This qualifies as high-risk employment AI requiring comprehensive documentation, risk management, and human oversight.
Medical device AI: A healthcare provider implements AI software analyzing real-time patient conversations to assess depression or anxiety severity. The system likely falls under both EU AI Act high-risk requirements (as safety component software) and Medical Device Regulation obligations, requiring dual compliance.
Compliance consideration: Organizations often benefit from structured legal support when implementing high-risk AI systems given the breadth of obligations and potential penalties for non-compliance (up to €35 million or 7% of global annual turnover).
🤖 Limited-risk AI systems trigger primarily transparency obligations under Chapter IV of the EU AI Act. While not explicitly defined as a risk category, these systems typically involve human interaction or synthetic content generation.
Transparency requirements apply when:
Provider obligations include:
Deployer obligations include:
Example: A government agency implements an AI chatbot on its public website to help citizens navigate services and locate information. The chatbot must clearly disclose to users that they are interacting with an AI system rather than a human agent.
Compliance consideration: Transparency obligations may also arise under other regulations, particularly GDPR Article 13-14 (information to data subjects) and Article 22 (automated decision-making). Organizations should ensure coordinated compliance across applicable frameworks.
🆗 Some AI applications fall into the minimal-risk category, facing no specific obligations under the EU AI Act. These systems pose no risk to safety, health, or fundamental rights.
The Act encourages but does not mandate voluntary codes of conduct for minimal-risk AI. Organizations may adopt such codes to demonstrate responsible AI practices and align with broader governance expectations.
Examples:
Spam filtering: Email systems using AI to detect and categorize spam messages
Video enhancement: Creative software applying AI for color correction, resolution enhancement, or editing assistance
Compliance consideration: While the EU AI Act imposes no specific requirements, minimal-risk AI remains subject to other applicable regulation. GDPR requirements apply where personal data processing occurs. Sector-specific rules may impose additional obligations depending on the application context.
Determining correct risk classification requires systematic analysis.
Compliance consideration: Classification is not always straightforward, particularly for general-purpose AI systems, AI components within larger products, or systems with multiple functions. Organizations facing classification uncertainty benefit from legal assessment early in development or deployment planning.
Organizations operating AI systems in the EU market should prioritize:
Organizations with high-risk AI systems face the most substantial compliance burden and should consider structured legal support to ensure comprehensive implementation of required controls.