The four AI Act risk levels, explained
The principle: risk comes from use
Regulation (EU) 2024/1689 does not regulate technologies: it regulates uses. The same large language model can be minimal risk when it rewrites an email, limited risk when it powers a public chatbot, and high risk when it pre-screens job applications. No product sheet will give you the answer: it depends on what you do with it.
The text organises systems into four layers, from the most constrained to the freest. Each layer has a proportionate set of obligations and its own date of application.
| Level | Legal basis | Regime | Applicable since / on |
|---|---|---|---|
| Unacceptable | Article 5 | Prohibition | 2 February 2025 |
| High risk | Article 6, Annexes I and III | Heavy obligations (provider) + Article 26 (deployer) | 2 August 2026 (Annex III) · 2 August 2027 (Annex I) |
| Limited risk | Article 50 | Transparency | 2 August 2026 |
| Minimal risk | — | No specific obligation | — |
Unacceptable risk — prohibited practices
Article 5 outright prohibits eight families of practices, applicable since 2 February 2025. The main ones:
- Subliminal manipulation or purposefully deceptive techniques materially distorting a person's behaviour and causing significant harm.
- Exploitation of vulnerabilities due to age, disability or a specific social or economic situation.
- Social scoring: evaluating or classifying people based on social behaviour, leading to detrimental treatment in unrelated contexts.
- Predicting the risk of committing a criminal offence based solely on profiling or personality traits.
- Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases.
- Emotion recognition in the workplace and in education institutions, save for medical or safety reasons.
- Biometric categorisation inferring race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation.
- Real-time remote biometric identification in publicly accessible spaces for law enforcement, outside strictly framed exceptions.
The sixth deserves particular attention: it directly targets products marketed as “engagement measurement” tools for meetings or training. Their use in a company is prohibited, and the penalty cap is the highest in the Regulation — €35M or 7% of worldwide annual turnover.
This is not a theoretical category. An interview-analysis tool scoring a candidate's “enthusiasm level”; an e-learning platform measuring pupils' attention through a webcam: these uses fall under Article 5. An up-to-date register is the only way to spot them before an authority does.
High risk — Annexes I and III
Article 6 defines two doors into the high-risk regime.
Door 1 — Annex I. The AI system is a safety component of a product already covered by Union harmonisation legislation (machinery, medical devices, toys, lifts, radio equipment, vehicles…), or is itself such a product, and is subject to third-party conformity assessment. These systems become fully subject to the Regulation on 2 August 2027.
Door 2 — Annex III. The system falls within one of eight listed areas, applicable on 2 August 2026:
- Biometrics: remote identification, biometric categorisation, emotion recognition (outside prohibited cases).
- Critical infrastructure: management and operation of road traffic, water, gas, heating, electricity.
- Education and vocational training: admission, assessment of learning outcomes, guidance, monitoring prohibited behaviour during exams.
- Employment and worker management: recruitment, targeted job ads, application filtering, evaluation, promotion, termination, task allocation, performance monitoring.
- Access to essential services: eligibility for public benefits, creditworthiness assessment, risk pricing in life and health insurance, emergency call triage.
- Law enforcement.
- Migration, asylum and border control.
- Administration of justice and democratic processes.
Point 4 is the one that catches the most private companies: a CV screening tool, a performance score, a promotion recommendation system are high-risk AI systems. It does not matter that they are “just decision support”: Annex III explicitly covers systems “intended to be used to make decisions or to materially influence decisions”.
Article 6(3) provides a derogation: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights — for instance if it performs a narrow procedural task, improves the result of a previously completed human activity, or performs a preparatory task. The derogation never applies where the system performs profiling of natural persons. And crucially: the provider invoking it must document its assessment before placing the system on the market. A deployer relying on it without documentation is relying on nothing.
Obligations attached to high risk
On the provider side (Chapter III, Section 2): risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11), record-keeping (Art. 12), transparency and instructions (Art. 13), human oversight (Art. 14), accuracy, robustness and cybersecurity (Art. 15), quality management system (Art. 17), conformity assessment and CE marking.
On the deployer side (Art. 26): use in line with the instructions, competent human oversight, control of input data, monitoring, logs kept at least six months, informing workers, informing persons subject to a decision. Details in our guide to deployer obligations.
Limited risk — transparency
“Limited risk” is not a category named by the text: it is the common name of the Article 50 regime. It covers systems that do not directly threaten fundamental rights but create a risk of illusion.
- Systems interacting with people (chatbots, voice assistants): disclose that this is an AI.
- Systems generating synthetic content: machine-readable marking of outputs.
- Lawful emotion recognition and biometric categorisation: inform the exposed persons.
- Deepfakes and certain texts of public interest: disclose the artificial nature of the content.
This regime applies on 2 August 2026. A provisional agreement from May 2026, the “AI Omnibus”, foresees a delay until 2 December 2026 for the machine-readable marking of generative systems already on the market. Until that text is published in the Official Journal, the enforceable date remains 2 August 2026. See the Article 50 guide.
Minimal risk
Everything that falls into none of the three previous categories. Spam filters, internal content recommendation engines, video-game AI, logistics optimisation, spell-checking. The Regulation imposes no specific obligation beyond Article 4 (AI literacy), which applies to everyone.
The vast majority of systems used in companies belong here. That does not excuse leaving them out of the register: it is precisely the entry that documents the “minimal” conclusion, and that allows it to be revisited if the use changes.
The special case of general-purpose AI models
Chapter V creates a distinct regime for general-purpose AI models (GPAI), applicable since 2 August 2025. It is not a fifth risk level: it is a layer of obligations borne by model providers — technical documentation, information to downstream providers, copyright policy, summary of training data. Models with systemic risk (Art. 51) carry reinforced duties: adversarial evaluations, mitigation of systemic risks, serious incident reporting, cybersecurity.
For a deployer the practical consequence is simple: check that the model provider publishes the required information, and record it in the register. The GPAI regime and the high-risk regime stack: a general-purpose model embedded in a CV screening system triggers both.
A five-step classification method
- Describe the real use in one sentence. “Tool X is used for Y, on data Z, affecting W.” If the sentence cannot be written, the register row is wrong.
- Test Article 5. Is the use among the prohibited practices? If so, stopping it is the only possible compliance.
- Test Annexes I and III. Is the system a safety component of a regulated product, or does its use fall within one of the eight areas? If so: high risk, unless a documented Article 6(3) derogation applies.
- Test Article 50. Does the system interact with people, generate synthetic content, analyse emotions, produce deepfakes? If so: transparency obligations.
- Otherwise: minimal. Record the conclusion, justify it in one sentence, set a review date.
A system can trigger several regimes at once. A candidate-screening chatbot is both high risk (Annex III, point 4) and subject to Article 50(1). The register must reflect that overlap rather than pick one.
Automating steps 1 to 4. AI Act Register Pilot recognises, locally, the AI tools your teams use, proposes a risk level and a role for each, warns about uses likely to fall under Annex III or Article 5, and generates the transparency notices. You decide, the tool documents.
Get the register template
AI system register template (XLSX + CSV)
With a “risk level” column and a “justification” column.
Keep reading
This content is provided for information only. It reflects Regulation (EU) 2024/1689 as at the update date and does not constitute legal advice.