EU AI Act Risk Tiers Explained: Prohibited, High-Risk, Transparency, Minimal
Nothing else about AI Act compliance makes sense until you know which of the four risk tiers an AI system falls into. This is the classification logic, explained without the legal drafting language.
- Four tiers: Prohibited, High-Risk, Transparency (Article 50), Minimal/no obligation.
- Classification is per AI system, not per company: one company can have systems in three different tiers at once.
- Prohibited practices (Article 5) are banned outright, not regulated, since 2 February 2025.
- High-risk (Annex I and Annex III) obligations were delayed by the 2026 Digital Omnibus to December 2027 / August 2028.
- Transparency-tier systems (chatbots, content generators, emotion/biometric recognition) are under Article 50, in force since 2 August 2026, unaffected by that delay.
- A system can be BOTH high-risk and subject to Article 50 transparency duties at the same time; the tiers aren’t mutually exclusive.
Why "risk tier" is a per-system question, not a per-company one
The single most common misunderstanding is treating AI Act risk as a property of the company ("are we a high-risk company?"). It isn’t. Regulation (EU) 2024/1689 classifies individual AI systems. A company can simultaneously run a minimal-risk internal analytics tool, a transparency-tier customer chatbot, and (rarer, but possible) a high-risk recruitment screening tool. Each one is assessed on its own, which is exactly why an asset inventory listing every system individually, not a single company-wide checkbox, is the starting point for any real compliance work.
Tier 1: Prohibited (Article 5)
A narrow list of AI practices are banned outright, not regulated with paperwork. These have applied since 2 February 2025. They include: social scoring by public authorities, certain forms of manipulative or deceptive AI that materially distorts behaviour causing harm, exploitation of vulnerabilities (age, disability, socioeconomic situation), most real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow, judicially authorised exceptions), biometric categorization inferring sensitive attributes like race or political opinion, untargeted scraping of facial images to build recognition databases, and emotion recognition in workplaces and educational institutions (with narrow medical/safety exceptions). The 2026 Digital Omnibus added AI-generated non-consensual intimate imagery and CSAM to this list.
If a system falls here, there is no compliance path: it can’t legally be deployed in the EU market in that form, full stop.
Tier 2: High-Risk (Annex I and Annex III)
High-risk systems aren’t banned, but carry the heaviest compliance burden: a risk management system, technical documentation, data governance requirements, human oversight design, accuracy/robustness/cybersecurity requirements, and conformity assessment before market placement. Two categories exist: Annex III lists specific standalone high-risk use cases directly (recruitment and worker management, credit scoring and insurance pricing, law enforcement risk assessment, migration/asylum management, biometric categorization, and several others). Annex I covers AI embedded as a safety component in products already regulated under EU harmonization law (medical devices, machinery, toys, and similar).
Following the 2026 Digital Omnibus, Annex III obligations now apply from 2 December 2027 and Annex I from 2 August 2028, both delayed from their original 2026/2027 dates. See the Digital Omnibus guide for the full detail on that change.
Tier 3: Transparency obligations (Article 50)
This tier covers systems that aren’t necessarily high-risk but interact with people or generate content in ways that need disclosure: chatbots and conversational AI, systems generating synthetic audio/image/video/text, deepfake generators, and emotion or biometric recognition systems (outside the prohibited or high-risk categories). These obligations took effect on 2 August 2026 and were not touched by the Digital Omnibus. This is the tier most SMEs using off-the-shelf generative AI tools actually fall into. See the Article 50 checklist guide for the specific sub-obligations.
Tier 4: Minimal or no obligation
Most everyday AI use, spam filters, internal recommendation engines, basic classifiers with no public-facing or biometric/emotion element, and no interaction with natural persons requiring disclosure, falls outside the first three tiers. These systems carry no AI Act-specific obligations beyond general good practice and voluntary codes of conduct the Act encourages. The catch: you can’t know a system belongs here without actually assessing it against the other three tiers first. "Probably fine" isn’t a classification, it’s a guess, and it’s the guess that tends to be wrong when a new feature quietly adds a chatbot or a public-facing generation step to a tool that used to be internal-only.
How to actually classify a system
A practical decision path, in order:
- Does it match a Prohibited practice under Article 5? If yes, stop, it cannot be deployed in this form.
- Does it match an Annex III use case, or is it embedded as a safety component in an Annex I product category? If yes, it’s high-risk (obligations due 2 December 2027 / 2 August 2028).
- Does it interact with people, generate synthetic content, or use emotion/biometric recognition? If yes, Article 50 transparency obligations apply now, in addition to any high-risk duties above.
- None of the above? Minimal/no specific obligation, but log it anyway and re-check when its use case changes.
Want this tracked automatically, not read about?
The EU AI Act Governance Cockpit is a Notion + n8n workspace that logs your AI systems, runs this exact risk classification, tracks the required actions, and keeps the evidence. One-time payment from €49.