Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

EU AI Act risk categories - unacceptable, high, limited and minimal risk tiers explained

EU AI Act Risk Categories: Prohibited, High-Risk & Limited

The EU AI Act’s entire structure rests on one idea: EU AI Act risk categories. Every AI system is sorted into one of four tiers, and your obligations flow almost entirely from which tier applies. Get the classification right and the rest of compliance becomes a manageable roadmap; get it wrong and you either over-invest or expose yourself to serious fines.

EU AI Act risk categories - unacceptable, high, limited and minimal risk tiers explained

Below we break down all four tiers, what each demands, and how to classify your own systems. For the wider context, start with our complete EU AI Act guide.

1. Unacceptable risk (prohibited)

A narrow set of AI uses is banned outright as a clear threat to safety and fundamental rights. These include social scoring by public authorities, manipulative or exploitative techniques that cause harm, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, and — with narrow law-enforcement exceptions — real-time remote biometric identification in public spaces. These prohibitions have applied since February 2025, so any such use must stop immediately.

2. High risk

This tier is the core of the Act. Systems are high-risk when used in sensitive domains — biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration, and the administration of justice — or when they act as a safety component of a regulated product. High-risk systems are permitted but must meet demanding obligations: a risk management system, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, a quality management system, conformity assessment, CE marking, and registration in the EU database.

3. Limited risk (transparency)

Some systems simply owe transparency. Chatbots must tell users they are talking to a machine; AI-generated or manipulated media (including deepfakes) must be labelled; and where emotion-recognition or biometric-categorization systems are permitted, people must be told they are exposed to them. The obligations are light but non-negotiable.

4. Minimal risk

The vast majority of AI — spam filters, recommendation engines, AI in video games — falls here with no new mandatory obligations, though voluntary codes of conduct are encouraged. Most organizations will find that only a small share of their systems rise above this tier.

How to classify your AI systems

Work top-down. First, rule out any prohibited uses. Next, check each system against the high-risk domains and the product-safety criteria — this is where careful assessment pays off, because misclassifying a high-risk system as limited-risk is the most expensive mistake you can make. Then apply transparency duties to any chatbots or generative features. Everything else is minimal risk. Document the reasoning for each decision; regulators will expect to see how you reached your classification.

Classify with confidence.

Our EU AI Act Toolkit includes a risk-classification questionnaire and register so you can sort every system into the right tier — and evidence the decision — in Word and Excel.

Explore the EU AI Act Toolkit →

Frequently asked questions

How many risk categories does the EU AI Act have?

Four: unacceptable (prohibited), high, limited (transparency), and minimal. Obligations increase sharply from minimal to high, and unacceptable-risk uses are banned entirely.

What makes an AI system high-risk?

Use in a sensitive domain listed in the Act (such as employment, education, biometrics, or essential services), or acting as a safety component of a regulated product. High-risk systems face the Act’s full obligation set.

Which risk category do most AI tools fall into?

Most everyday AI is minimal risk with no new obligations. The compliance effort concentrates on the smaller number of high-risk systems and any transparency-tier features like chatbots.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.