The EU AI Act: risk categories in plain terms
The four risk levels the AI Act uses, what falls into each, and how to classify your own uses without a legal degree.
The short answer
The AI Act is built around four levels of risk. Prohibited practices are banned outright: they include social scoring by public or private actors leading to unjustified detrimental treatment, certain manipulative or exploitative techniques that materially distort behaviour and cause harm, emotion recognition in the workplace and in education with narrow exceptions, untargeted scraping of facial images to build recognition databases, and specified biometric categorisation and real-time remote biometric identification practices. High-risk systems are permitted with substantial obligations, and they fall into two families: AI as a safety component of products already regulated under listed EU legislation, and systems used in the areas listed in the annex, which include biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services such as credit and insurance, law enforcement, migration, and the administration of justice. Limited-risk systems carry transparency duties, principally telling people they are interacting with AI and marking generated content. Everything else is minimal risk with no obligations under the Act. Classifying your own list honestly is the first governance task, and it usually shows that most uses are minimal.
The four levels
| Level | What it covers | Obligations |
|---|---|---|
| Prohibited | Social scoring; manipulative or exploitative techniques causing harm; emotion recognition at work and in education, with narrow exceptions; untargeted facial image scraping; certain biometric categorisation and identification practices | Do not use |
| High-risk | Safety components of regulated products; listed areas: biometrics, critical infrastructure, education, employment, essential services including credit and insurance, law enforcement, migration, justice | Risk management, data governance, documentation, logging, transparency, human oversight, accuracy and security for providers; instructions, oversight, monitoring, logs and worker information for deployers |
| Limited risk | Systems interacting with people; generating synthetic content; emotion recognition and biometric categorisation outside prohibited uses | Transparency: inform people; mark or disclose generated content |
| Minimal risk | Everything else: drafting, summarising, classification, extraction, scheduling, automation, recommendation for ordinary commerce | None under the Act; other law still applies |
Classifying your own uses
- List every AI use in the business, by purpose rather than by tool.
- Check each against the prohibited practices first; stop anything that matches.
- Check against the high-risk families: regulated product safety components, and the annex areas.
- For anything in an annex area, consider whether the narrow exception for uses not posing significant risk applies, and document the reasoning if you rely on it.
- Identify transparency triggers: interaction with people, generated content, emotion or biometric features.
- Mark the rest as minimal, with a note of why.
- Record the classification, the date and who decided, because that record is your evidence.
- Re-classify when a use changes purpose, which is when most reclassification is needed.
- Take advice on anything you place in or near the high-risk category.
What businesses find
A register of ten to twenty uses, of which almost all are minimal risk, two or three carry transparency duties because they talk to customers or generate content, and zero or one sits in a high-risk area, usually in recruitment. That is a manageable picture, and it converts the AI Act from an intimidating regulation into a short list of specific obligations. The value of the classification is knowing which uses deserve attention and budget, and being able to show the reasoning if anyone asks.
What this means for you
The AI Act sorts uses into prohibited, high-risk, limited-risk with transparency duties, and minimal risk. Classify your own uses by purpose, check the prohibited list first, then the high-risk families, then transparency triggers, and record the reasoning with dates. Expect most to be minimal, a few to need disclosure, and any employment or essential-services use to need proper treatment. This is general information rather than legal advice.
Frequently asked questions
How do we classify our own AI uses?
Work down the levels. Is the use among the prohibited practices? If not, does it fall within the high-risk annex, a safety component of a regulated product, or one of the listed areas such as employment or access to essential services? If not, does it interact with people or generate content, triggering transparency duties? If none of those, it is minimal risk and the Act adds nothing, though data protection still applies. Write the answer and the reasoning next to each use in your register.
What makes something high-risk?
Either it is a safety component of a product already regulated under listed EU legislation, or it falls within the areas listed in the annex: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services including credit and insurance, law enforcement, migration and border control, and administration of justice. There is a narrow exception where a system in a listed area does not pose a significant risk, which must be documented.
Where does a chatbot sit?
A customer service chatbot is normally minimal risk with a transparency duty: tell people they are interacting with AI. It becomes high-risk if it is used for something in the annex, for instance if it determines access to an essential service or screens candidates. The classification follows the purpose, not the technology, which is why the same tool can sit in two categories in two businesses.
Sources
- European Commission: AI Act (accessed 2026-09-12)
- EUR-Lex: Regulation (EU) 2024/1689 (Artificial Intelligence Act) (accessed 2026-09-12)