The AI Act's 4 risk tiers

TierWhat it meansConsequence
Unacceptable risk8 practices banned outright under Article 5.Cannot be placed on the market or used at all in the EU.
High-riskFalls into one of the 8 Annex III categories, or is a safety component covered by other EU product legislation.Full obligations: risk management, technical documentation, human oversight, conformity assessment, registration.
Limited riskSystems like chatbots, deepfakes, or emotion-recognition tools not covered above.Transparency obligations only — people must be told they're interacting with AI or AI-generated content.
Minimal riskEverything else — spam filters, inventory forecasting, most internal productivity tools.No specific AI Act obligations, though other laws (GDPR, sector rules) may still apply.

Is your system in the unacceptable-risk tier?

Check this first — if it applies, no amount of documentation makes the system legal. Article 5 bans 8 practices:

  1. Subliminal or purposefully manipulative techniques that materially distort behavior and cause harm.
  2. Exploiting the vulnerabilities of a specific group (age, disability, economic situation) to distort their behavior harmfully.
  3. Social scoring — evaluating people by behavior or inferred characteristics to their detriment in unrelated contexts.
  4. Predicting criminal risk based solely on profiling or personality traits, without objective, verifiable facts.
  5. Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases.
  6. Inferring emotions in the workplace or in education, except for medical or safety reasons.
  7. Biometric categorization to infer race, political opinion, union membership, religion, or sexual orientation.
  8. Real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions.

The 8 Annex III high-risk categories

If your system isn't banned, check whether it falls into one of these — this is where most classification questions actually land:

CategoryCovers
BiometricsRemote identification, sensitive-attribute categorization, emotion recognition.
Critical infrastructureManaging digital infrastructure, road traffic, water, gas, heating, electricity.
Education & vocational trainingAdmissions, evaluating learning outcomes, assessing appropriate education level, monitoring behavior during tests.
Employment & workers managementRecruitment, hiring decisions, task allocation, performance monitoring.
Essential services & benefitsEligibility for public assistance, healthcare, creditworthiness, insurance pricing, emergency dispatch.
Law enforcementVictim risk assessment, evidence evaluation, criminal profiling by or on behalf of authorities.
Migration, asylum & border controlSecurity and migration risk assessment, visa evaluation, identification at borders.
Justice & democratic processesAssisting judicial interpretation and application of law; influencing elections or referendums.

One important exception: Article 6(3) lets a system inside these categories avoid the high-risk label if it only performs a narrow procedural task, improves a completed human activity's output, detects patterns without replacing human judgment, or does purely preparatory work — but the provider has to document that exemption, not just assume it.

How to actually run this classification

  1. List every AI system in use, including ones bought from vendors or embedded in other software — you can't classify what you haven't inventoried.
  2. Screen against Article 5's 8 prohibited practices first. If any applies, stop the project.
  3. Check the 8 Annex III categories for each remaining system.
  4. If it lands in Annex III, check the Article 6(3) exemption — and document your reasoning either way, because "we assumed it was low-risk" is not a defense in an audit.
  5. Everything else gets checked against limited-risk transparency triggers (chatbots, deepfakes, AI-generated content) before defaulting to minimal risk.
AI Act Risk Classification Checklist A complete decision tree covering all 8 Annex III categories plus edge-case guidance for the Article 6(3) exemption. €19, VAT incl.
Buy →

Frequently asked questions

How do I know if my AI system is high-risk?

Check whether it falls into one of the 8 categories in Annex III of the AI Act — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration/border control, or justice and democratic processes. If it does, and it isn't a purely narrow, procedural task, it's high-risk under Article 6.

What AI systems are completely banned under the AI Act?

Article 5 prohibits 8 practices: subliminal or manipulative techniques causing harm, exploiting vulnerable groups, social scoring, predictive criminal profiling based solely on personality traits, untargeted scraping to build facial recognition databases, emotion inference at work or school, biometric categorization to infer protected characteristics, and most real-time remote biometric identification in public spaces for law enforcement.

Can a system in an Annex III category still be low-risk?

Yes, in narrow cases. Article 6(3) allows a system that falls in an Annex III category to be treated as not high-risk if it only performs a narrow procedural task, improves the result of a completed human activity, detects patterns without replacing human judgment, or does purely preparatory work — but the provider has to document and justify that exemption.

What happens if I classify my system wrong?

Misclassifying a high-risk system as lower-risk means skipping the technical documentation, conformity assessment, and oversight obligations Articles 11, 14 and 47 require — which falls under the mid-tier penalty in Article 99 (up to €15M or 3% of global turnover) for non-compliance with provider or deployer obligations.