Cookies
By clicking “Yes”, you agree to the storing of cookies on your device to enhance site navigation, and to improve our marketing. View our Privacy Policy for more information.

EU AI Act: How risk is classified

The EU AI Act classifies AI systems into four different risk levels: unacceptable, high, limited, and minimal risk. Each class has different regulation and requirements for organizations developing or using AI systems. This article explains how AI systems and GPAI models are classified and gives examples for high-risk cases.

Last updated:
July 30, 2026

We previously outlined the EU AI Act in a short article, where we already showed that the EU wants to take a risk-based approach in regulating AI systems. Different use cases entail different levels of risk, which the EU AI Act sets out in law. This article drills down on the risk classifications and the corresponding application areas to help you understand whether your AI use case classifies as high-risk.

If you want to understand the EU AI Act's rules behind GPAI models take a look at this article, and if you want to understand how modifications to existing AI systems or models may change your obligations take a look at this article we wrote in collaboration with the Future of Life Institute.

Wondering if you are affected by the AI Act and which risk level your AI application is classified as? Then take this free self-assessment to quickly get an answer.

Current Status

The EU AI Act entered into force on 1 August 2024 and applies in stages. The prohibitions on unacceptable AI practices and the AI literacy duty have applied since 2 February 2025, the rules for general-purpose AI models since 2 August 2025, and the regulation applies generally from 2 August 2026.

The Act was amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026. This postponed the high-risk requirements: Chapter III now applies from 2 December 2027 for systems classified as high-risk via Annex III, and from 2 August 2028 for systems classified via Annex I. Two new prohibitions were also added, applying from 2 December 2026.

Timeline of the EU AI Act enforcements after the release of the Digital Omnibus on AI.

Risk classifications according to the EU AI Act

The EU's Artificial Intelligence Act (AI Act) sets out four risk levels for AI systems: unacceptable, high, limited, and minimal (or no) risk. There are different regulations and requirements for each class.

Unacceptable risk is the highest level of risk. This tier can be divided into ten AI application types that are incompatible with EU values and fundamental rights. These are applications related to:

  1. Subliminal manipulation: changing a person's behavior without them being aware of it, which would harm a person in any way. An example could be a system that influences people to vote for a particular political party without their knowledge or consent.
  2. Exploitation of the vulnerabilities of persons resulting in harmful behavior: this includes social or economic situation, age and physical or mental ability. For instance, a toy with voice assistants that may animate children to do dangerous things.
  3. Biometric categorization of persons based on sensitive characteristics: this includes race, political opinions, trade union membership, religious or philosophical beliefs, sex life and sexual orientation. Labeling or filtering of lawfully acquired biometric datasets in the area of law enforcement is not covered.
  4. General purpose social scoring: using AI systems to rate individuals based on their personal characteristics, social behavior and activities, such as online purchases or social media interactions. The concern is that, for example, someone could be denied a job or a loan simply because of their social score that was derived from their shopping behavior or social media interactions, which might be unjustified or unrelated.
  5. Real-time remote biometric identification (in public spaces): this is prohibited, subject to narrow exceptions. Post-remote biometric identification is not prohibited – it is classified as high-risk and subject to additional safeguards under Article 26(10). Exceptions can be made for law enforcement with judicial approval and the Commission’s supervision. This is only possible for the pre-defined purposes of targeted search of crime victims, terrorism prevention and targeted search of serious criminals or suspects (e.g. trafficking, sexual exploitation, armed robbery, environmental crime).
  6. Assessing the emotional state of a person: this holds for AI systems at the workplace or in education. Emotion recognition may be allowed as high-risk application, if they have a safety purpose (e.g. detect if a driver falls asleep).
  7. Predictive policing: assessing the risk of persons for committing a future crime based on personal traits.
  8. Scraping facial images: creating or expanding databases with untargeted scraping of facial images available on the internet or from video surveillance footage.
  9. [New addition through Digital Omnibus] Non-consensual intimate imagery: AI systems that generate or manipulate realistic images, video, audio or similar material depicting an identifiable person's intimate parts, or that person engaged in sexually explicit activity, without their explicit consent.
  10. [New addition through Digital Omnibus] Child sexual abuse material: AI systems that generate or manipulate material within the meaning of Directive 2011/93/EU.

AI systems related to these areas are prohibited in the EU.

High-risk AI systems are the most regulated systems allowed in the EU market. In essence, this level includes components that perform a safety function in already regulated products and stand-alone AI systems in specific areas (see below), which could negatively affect the health and safety of people or their fundamental rights. These AI systems can potentially cause significant harm if they fail or are misused. We will detail what classifies as high-risk in the next section.

The third level of risk is limited risk, which includes AI systems with a risk of manipulation or deceit. AI systems falling under this category must be transparent, meaning humans must be informed about their interaction with the AI (unless this is obvious), and any deep fakes should be denoted as such. For example, chatbots classify as limited risk. This is especially relevant for generative AI systems and its content.

The lowest level of risk described by the EU AI Act is minimal risk. This level includes all other AI systems that do not fall under the above-mentioned categories, such as a spam filter. AI systems under minimal risk do not have any restrictions or mandatory obligations. However, it is suggested to follow general principles such as human oversight, non-discrimination, and fairness. Providers and deployers of AI systems should still take measures to support AI literacy among their staff (see Article 4 in the EU AI Act).

As the AI Act is quite complex to understand, we have built a free-to-use self-assessment tool to help you identify which risk level your AI use case is classified as and which obligations you are likely to face under the AI Act.

Concentric bands showing the EU AI Act risk classes: minimal risk in the outermost band, then limited risk, then high risk, with prohibited practices at the centre — the permitted space narrows as risk rises. A separate element shows general-purpose AI models, classified by capability into GPAI models and GPAI models with systemic risk. The Article 4 AI literacy duty and the Article 50 transparency duties apply across all bands.
The four risk classes of the EU AI Act and the GPAI model categories.

What counts as high-risk in the EU AI Act?

The high-risk classification of AI systems defined by the EU AI Act was one of the most controversial and discussed area, as it imposes a significant burden on organizations. As previously mentioned, this includes all AI applications that could negatively affect the health and safety of people, or their fundamental rights. To be put on the market and operated in the EU, AI systems in this risk class must meet certain requirements.

One part that falls under this classification is AI systems related to the safety components of regulated products (see Annex I of the EU AI Act), i.e., products already subject to third-party assessments. These are, for example, AI applications integrated into medical devices, lifts, vehicles, or machinery.

Since July 2026, through the Digital Omnibus, Article 6(1a) adds a further carve-out: AI systems that are solely used for non-safety-related aspects of user assistance, performance optimization, service efficiency, automation or convenience or quality control shall not qualify as safety components.

Annex III of the AI Act identifies additional areas that would classify new stand-alone AI systems as high-risk.

Falling into an Annex III area does not automatically make a system high-risk. Under Article 6(3), a system listed in Annex III is not high-risk where it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing or influencing human assessment, or performs a preparatory task – provided it does not profile natural persons.

These Annex III applications include:

(a) biometric and biometrics-based systems (such as remote biometric identification, categorization of persons and emotion recognition systems),

(b) management and operation of critical infrastructure (such as road traffic, energy supply or digital infrastructure),

(c) education and vocational training (such as assessment of students in educational institutions),

(d) employment and workers management (such as recruitment, performance evaluation, or task-allocation),

(e) access to essential private and public services and benefits (such as credit-scoring, risk assessments in health insurance and dispatching emergency services),

(f) law enforcement (such as evaluating the reliability of evidence or crime analytics),

(g) migration, asylum and border control management (such as assessing the security risk of a person or the examination of applications for asylum, visa, or residence permits),

(h) administration of justice and democratic processes (such as assisting in interpreting & researching facts, law, and the application of the law or for influencing elections).

High-risk AI systems in the EU AIA can be categorized into eight areas. This includes AI systems in safety components or regulated systems.
EU AI Act high-risk areas

Consult this article to learn how to meet the regulatory requirements if you develop or deploy a high-risk AI system. Law enforcement authorities may in exceptional cases of public security employ high-risk systems before completing the conformity assessment procedure.

The EU also maintains a publicly accessible database listing high-risk AI systems registered by their providers and deployers (Article 71 of the EU AIA). Only law-enforcement, migration, asylum and border-control systems are registered in a non-public section, accessible to the Commission and to national authorities. Providers of GPAI models are not listed here – systemic-risk models appear on a separate public list maintained by the Commission.

GPAI

While the original proposal of the EU AI Act certainly didn't mention General Purpose AI (GPAI) models, such as those from OpenAI or Anthropic, the EU updated its proposal also in this regard during the negotiations of the EU AI Act. Above, we've seen that the risk classification depends on the use case of the AI system, which is difficult to limit with a GPAI model. The EU AI Act differentiates between two risk classes: non-systemic and systemic risk, based on whether the model has high impact capabilities – presumed where the cumulative amount of computation used for training exceeds 10^25 floating point operations. While all foundational models will need to meet documentation and transparency requirements, those with a systemic risk have much stricter obligations. GPAI model creators must provide relevant information to downstream providers who use these models in a high-risk application.

Publicly available open-source models can avoid stricter requirements if their license allows for access, usage, modification and distribution of the model and its parameters. This holds true as long as there is no relation to high-risk or prohibited applications or no risk of manipulation. Learn more about how the AI Act treats GPAI and GenAI systems in this article.

Conclusion

The EU AI Act takes a risk-based approach to regulating AI systems, with four levels of risk: unacceptable, high, limited, and minimal (or no) risk. Each level is subject to different degrees of regulations and requirements. Additionally, the AI Act differentiates between non-systemic and systemic risk when it comes to GPAI.

Unacceptable risk is the highest level of risk and covers ten main types of AI applications incompatible with EU values and fundamental rights. These applications are prohibited in the EU.

High-risk AI systems are the most regulated systems allowed in the EU market and include safety components of already regulated products and stand-alone AI systems in specific areas. This level imposes significant burdens on organizations and requires AI systems to meet certain requirements before they can be put on the market and operated in the EU.

Limited risk includes AI systems with a risk of manipulation or deceit. These AI systems must be transparent, and humans must be informed about their interaction with the AI or AI-generated content.

Minimal risk includes all other AI systems not falling under the above categories. AI systems under minimal risk do not have any specific restrictions or mandatory obligations, but it is suggested to follow general principles such as human oversight, non-discrimination, and fairness. There may be organizational requirements though.

GPAI model providers are subject to documentation and transparency obligations, which become stricter when a systemic risk exists, i.e. if the model is powerful.

If your AI use case classifies as high-risk, you should start preparing for the regulation with its extensive documentation already today to make sure you stay competitive.

We have built a free-to-use EU AI Act compliance checker to help you identify the risk class of your AI system and the obligations you are likely to face under the AI Act.

At trail, we help you fully understand your AI governance requirements and to automate tedious compliance tasks such that you can scale AI responsibly. Learn more about trail here and get started today or learn here how we can help you cope with the EU AI Act.