How to Classify Your AI Systems Under the EU AI Act Risk Framework
January 25, 2026 · 10 min read · By Jasone Rodriguez
The EU AI Act uses a risk-based approach to regulation. Not all AI systems are treated equally; your obligations depend entirely on the risk level of each system. Understanding this classification is the first step to compliance.
Tier 1: Prohibited AI Practices
Status: Banned since August 2, 2025
These AI practices are completely banned in the EU. If your organization uses any of these, you must discontinue immediately.
- Social scoring systems:AI that evaluates trustworthiness based on social behavior or personality characteristics, leading to detrimental treatment.
- Real-time remote biometric identification:Live facial recognition in public spaces by law enforcement (with narrow exceptions).
- Emotion recognition in workplace/education:AI that infers emotions of employees or students (with narrow exceptions for safety/medical).
- Cognitive behavioral manipulation:AI that manipulates people through subliminal techniques or exploits vulnerabilities (age, disability).
- Biometric categorization of sensitive attributes:AI that categorizes people by race, political opinion, sexual orientation, or religious beliefs from biometric data.
- Untargeted facial image scraping:Building facial recognition databases by scraping images from the internet or CCTV.
Penalty for violation: Up to EUR 35 million or 7% of global annual revenue.
Tier 2: High-Risk AI Systems
Enforcement: August 2, 2026
High-risk AI systems have the most comprehensive obligations. These are AI systems used in areas where errors or biases can significantly impact people's lives, rights, or safety.
Common High-Risk Use Cases (Annex III):
- Hiring and recruitment:Resume screening, interview assessment, candidate ranking (e.g., HireVue, Pymetrics, Eightfold).
- Credit scoring and financial decisions:AI that determines creditworthiness, insurance pricing, or loan approvals.
- Medical devices and diagnostics:AI used in clinical decision-making, medical imaging analysis, treatment recommendations.
- Critical infrastructure:AI managing electricity, water, gas, or transportation systems.
- Education assessment:AI that evaluates students, determines admissions, or affects educational opportunities.
- Law enforcement:Risk assessment, evidence analysis, crime prediction (with exceptions).
- Migration and border control:Visa processing, asylum applications, border surveillance.
Required for High-Risk Systems:
- Risk management system (ongoing, not one-time)
- Data governance and quality measures
- Technical documentation and model cards
- Record-keeping and audit logs
- Transparency and user information
- Human oversight capabilities
- Accuracy, robustness, and cybersecurity
- Registration in the EU AI database
Tier 3: Limited Risk AI Systems
Primary obligation: Transparency
Limited risk AI systems mainly need to be transparent about the fact that AI is being used. The regulatory burden is lighter, but transparency requirements are still legally binding.
- Chatbots and virtual assistants:Must disclose to users they are interacting with AI (e.g., customer service bots, Intercom, Drift).
- AI-generated content:Deepfakes and AI-generated text, images, audio, or video must be labeled as artificially generated.
- Emotion recognition systems:Must inform users that emotion detection is in use (when permitted).
- Biometric categorization:Must inform users that biometric categorization is occurring (when permitted).
Tier 4: Minimal Risk AI Systems
Obligations: Voluntary codes of conduct
The majority of AI systems fall into this category. There are no mandatory requirements, but the EU encourages voluntary adoption of codes of conduct.
- Spam filters:Email spam detection and filtering.
- Search and recommendation:Product recommendations, content curation (when not profiling individuals).
- Game AI:AI in video games and entertainment.
- Manufacturing optimization:Supply chain optimization, predictive maintenance (when no safety implications).
- Internal analytics:Business intelligence dashboards, sales forecasting (when not used for individual decisions).
Even minimal risk systems should follow good governance practices: documenting your AI use protects against future regulatory changes and builds customer trust.
How to Classify Your Own Systems
Classification depends on three main factors:
- 1. What decisions does the AI influence?:If the AI affects hiring, credit, medical, education, or law enforcement decisions, it's likely high-risk. The key question is whether the AI's output impacts an individual's rights, opportunities, or safety.
- 2. What data does it process?:Systems processing biometric data, health data, or data about protected characteristics face stricter classification. Processing sensitive data doesn't automatically make a system high-risk, but it increases the likelihood.
- 3. What is the deployment context?:The same AI technology can be different risk levels depending on how it's used. A recommendation engine for movies is minimal risk; the same technology recommending medical treatments is high-risk.
Classify Your AI Systems Automatically
Our assessment tool automatically classifies each of your AI systems under the EU AI Act risk framework based on your inputs. Get your risk levels in minutes, not weeks.
Take the Free Assessment