The EU AI Act’s entire structure rests on one idea: EU AI Act risk categories. Every AI system is sorted into one of four tiers, and your obligations flow almost entirely from which tier applies. Get the classification right and the rest of compliance becomes a manageable roadmap; get it wrong and you either over-invest or expose yourself to serious fines.

Below we break down all four tiers, what each demands, and how to classify your own systems. For the wider context, start with our complete EU AI Act guide.
1. Unacceptable risk (prohibited)
A narrow set of AI uses is banned outright as a clear threat to safety and fundamental rights. These include social scoring by public authorities, manipulative or exploitative techniques that cause harm, untargeted scraping of facial images to build recognition databases, emotion recognition in workplaces and schools, and — with narrow law-enforcement exceptions — real-time remote biometric identification in public spaces. These prohibitions have applied since February 2025, so any such use must stop immediately.
2. High risk
This tier is the core of the Act. Systems are high-risk when used in sensitive domains — biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration, and the administration of justice — or when they act as a safety component of a regulated product. High-risk systems are permitted but must meet demanding obligations: a risk management system, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, a quality management system, conformity assessment, CE marking, and registration in the EU database.
3. Limited risk (transparency)
Some systems simply owe transparency. Chatbots must tell users they are talking to a machine; AI-generated or manipulated media (including deepfakes) must be labelled; and where emotion-recognition or biometric-categorization systems are permitted, people must be told they are exposed to them. The obligations are light but non-negotiable.
4. Minimal risk
The vast majority of AI — spam filters, recommendation engines, AI in video games — falls here with no new mandatory obligations, though voluntary codes of conduct are encouraged. Most organizations will find that only a small share of their systems rise above this tier.
How to classify your AI systems
Work top-down. First, rule out any prohibited uses. Next, check each system against the high-risk domains and the product-safety criteria — this is where careful assessment pays off, because misclassifying a high-risk system as limited-risk is the most expensive mistake you can make. Then apply transparency duties to any chatbots or generative features. Everything else is minimal risk. Document the reasoning for each decision; regulators will expect to see how you reached your classification.
Classify with confidence.
Our EU AI Act Toolkit includes a risk-classification questionnaire and register so you can sort every system into the right tier — and evidence the decision — in Word and Excel.
Frequently asked questions
How many risk categories does the EU AI Act have?
Four: unacceptable (prohibited), high, limited (transparency), and minimal. Obligations increase sharply from minimal to high, and unacceptable-risk uses are banned entirely.
What makes an AI system high-risk?
Use in a sensitive domain listed in the Act (such as employment, education, biometrics, or essential services), or acting as a safety component of a regulated product. High-risk systems face the Act’s full obligation set.
Which risk category do most AI tools fall into?
Most everyday AI is minimal risk with no new obligations. The compliance effort concentrates on the smaller number of high-risk systems and any transparency-tier features like chatbots.