EU AI Act risk categories: the four tiers explained
The EU AI Act regulates AI by risk, not by technology — so the whole framework hangs on which of four tiers your system falls into. This guide explains each category with examples and the obligations that come with it. Part of our guide to the EU AI Act.
AramGRC Team·AI Compliance & Assurance·September 11, 2026·8 min read
The risk-based approach
Rather than regulate all AI the same way, the EU AI Act sorts systems into four tiers by the risk they pose to health, safety and fundamental rights. The higher the tier, the stricter the obligations — so classifying each system correctly is the first and most important compliance step.
1. Unacceptable risk (prohibited)
Some uses are banned outright because the risk is deemed unacceptable — for example, social scoring by public authorities, manipulative or exploitative techniques that cause harm, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, and certain biometric categorisation. Real-time remote biometric identification in public spaces is prohibited with narrow law-enforcement exceptions. These prohibitions have applied since February 2025.
2. High risk
High-risk systems carry the full obligations. They fall into two groups:
Annex III (standalone) systems — AI used in employment and worker management, creditworthiness and credit scoring, education, access to essential public and private services, biometric identification, law enforcement, migration, and critical infrastructure.
Annex I systems — AI used as a safety component of regulated products such as medical devices, machinery and vehicles.
After the 2026 Digital Omnibus, high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. See EU AI Act requirements for high-risk AI.
3. Limited risk (transparency)
Systems like chatbots, generative AI and deepfakes fall into the limited-risk tier: they must meet transparency duties under Article 50 — telling people they're interacting with AI, marking AI-generated content in machine-readable form, and labelling deepfakes. These transparency rules apply from August 2026.
4. Minimal risk
Everything else — spam filters, recommendation engines, AI in video games — is minimal risk, with no specific obligations under the Act, though voluntary codes of conduct are encouraged.
How to classify your AI system
Work top-down: is the use prohibited? If not, is it a high-risk use under Annex III or a safety component under Annex I? If not, does it interact with people or generate content (limited-risk transparency)? If none apply, it's minimal risk. Document the decision — the classification and its rationale are part of your compliance evidence. The full sequence is in EU AI Act compliance.
Why classification is the first compliance step
Every obligation flows from the tier. Misclassify a high-risk system as limited-risk and you'll miss the requirements that carry the largest penalties. This is why a documented, defensible classification of every AI system is where EU AI Act compliance begins.
How AramGRC helps
AramGRC classifies your AI systems against the Act's tiers and Annexes, and builds the compliance roadmap that follows from each classification.
Frequently asked questions
What are the EU AI Act risk categories?+
Four: unacceptable risk (prohibited), high risk (full obligations), limited risk (transparency duties), and minimal risk (no specific obligations).
What is a high-risk AI system under the EU AI Act?+
AI used in areas like employment, credit scoring, education, essential services, biometrics, law enforcement and critical infrastructure (Annex III), or as a safety component of regulated products like medical devices and vehicles (Annex I).
What AI is prohibited under the EU AI Act?+
Practices deemed unacceptable — social scoring by authorities, manipulative techniques, untargeted facial-image scraping, workplace and school emotion recognition, and certain biometric categorisation — banned since February 2025.
What is limited-risk AI?+
Systems like chatbots, generative AI and deepfakes, which must meet transparency obligations — disclosing AI interaction and marking AI-generated content — from August 2026.