The EU AI Act’s four risk tiers, explained
In short
The EU AI Act does not regulate AI as a single category, it sorts every AI system into one of four risk tiers, and the tier determines everything else: which obligations apply, who carries them, and what a non-compliant deployment costs you. Understanding which tier a system falls into is the first and most consequential step in any compliance assessment.
Unacceptable risk, prohibited outright
Eight specific practices, listed in Article 5, are banned regardless of safeguards: manipulative or exploitative techniques, social scoring, several biometric and emotion-recognition uses, and certain predictive-policing profiling. There is no compliance pathway for a system in this tier, it must not be placed on the market or put into service in the EU. These prohibitions applied from 2 February 2025.
High risk, the Act's heaviest obligation set
A system is high-risk if it falls into one of the eight categories in Annex III (biometric identification and categorisation, critical infrastructure, education, employment, essential services, law enforcement, migration/asylum/border control, or administration of justice and democratic processes) or is a safety component of a product already regulated under EU product-safety law listed in Annex I (such as medical devices or machinery) where that product requires third-party conformity assessment. High-risk systems carry the full Articles 9-15 obligation set for providers, plus a distinct Article 26 obligation set for deployers.
Limited risk, transparency obligations only
Systems that interact directly with people, generate synthetic content, or perform emotion recognition/biometric categorisation face a narrower, disclosure-focused duty under Article 50: telling people they are talking to an AI, labelling AI-generated content, or informing people that emotion recognition is in use. None of the Articles 9-15 high-risk requirements apply unless the same system independently qualifies as high-risk on other grounds.
Minimal risk, no mandatory obligations, but not exempt from everything
The large majority of AI systems (internal analytics tools, spam filters, most recommendation engines) fall outside the prohibited, high-risk, and transparency categories entirely. The Act does not impose mandatory technical obligations on them beyond two duties that apply regardless of risk tier: AI literacy for staff (Article 4) and, for general-purpose AI models specifically, the separate Chapter V obligations covering model documentation and, for the most capable models, systemic-risk assessment.
One system can sit in more than one tier at once
Risk classification is not always a single label. A recruitment chatbot, for example, can simultaneously be high-risk under Annex III §4 (employment) and subject to the Article 50 transparency duty because it interacts directly with candidates. When a system triggers multiple provisions, every applicable obligation stacks, the highest tier does not absorb or replace the others.
Because Annex III categories and the Annex I/Article 6(1) product-safety route both involve fact-specific line-drawing (what counts as a “safety component,” whether third-party conformity assessment is actually required) a confident self-classification still benefits from a systematic, rule-based assessment rather than a read-through of the Annex headings alone.
Frequently asked questions
- What are the four risk tiers of the EU AI Act?
- Unacceptable risk (practices prohibited outright under Article 5), high risk (Annex III categories or Annex I safety components, carrying the full Articles 9–15 provider obligations and the Article 26 deployer obligations), limited risk (transparency-only duties under Article 50), and minimal risk (no mandatory technical obligations beyond AI literacy under Article 4).
- What makes an AI system high-risk under the EU AI Act?
- A system is high-risk if it falls into one of the eight Annex III categories (such as employment, essential services, or biometric identification) or is a safety component of a product regulated under EU product-safety law listed in Annex I where that product requires third-party conformity assessment.
- Can one AI system fall into more than one risk tier?
- Yes. A recruitment chatbot can be high-risk under Annex III (employment) and, at the same time, subject to the Article 50 transparency duty because it interacts directly with people. When a system triggers multiple provisions, every applicable obligation stacks, the highest tier does not replace the others.
Related guides
Not sure where your company stands?
Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.
Start the free check