AI Act

The AI Act risk pyramid

The AI Act regulates uses, not technologies. The same model can be unregulated in one deployment and high-risk in another, because the classification follows what the system is used for and who it affects. Getting the level right is the first compliance decision you make — every obligation downstream depends on it.

The pyramid in 60 seconds

Four levels
Prohibited, high-risk, transparency risk and minimal risk — with a separate track for general-purpose AI models.
Where the weight sits
Nearly all the documentation and process obligations attach to high-risk systems. Everything else is either banned or comparatively light.
Two routes into high-risk
Annex I — AI as a safety component in regulated products. Annex III — a listed use case, from biometrics and HR to credit scoring and law enforcement.
Classification is a duty
The provider classifies the system and must be able to justify the reasoning to a market surveillance authority.

The four levels

Classification determines the obligations. General-purpose AI models are handled on a separate track.
LevelWhat it coversExamples
ProhibitedPractices considered incompatible with EU fundamental rights. Banned outright — no compliance route exists.Social scoring by public authorities; untargeted scraping of facial images to build recognition databases.
High riskPermitted, but only with the full set of provider requirements and deployer duties before and after going to market.CV screening in recruitment, credit scoring, AI as a safety component in a regulated machine.
Transparency riskPermitted with disclosure duties, so people know when they are dealing with, or looking at, AI output.Customer-service chatbots, AI-generated images and video presented as real.
Minimal riskNo new obligations under the AI Act; voluntary codes of conduct are encouraged.Spam filters, recommendation engines, most internal productivity tooling.

Prohibited practices

The risk-based approach starts at the top of the pyramid. These have applied since 2 February 2025 and carry the heaviest fines. The prohibited practices include:

  • social scoring by public authorities;
  • manipulative or exploitative techniques — including those that exploit vulnerabilities such as age or disability — that materially distort behaviour;
  • emotion recognition in workplaces and educational institutions;
  • untargeted scraping of facial images from the internet or CCTV to build or expand facial recognition databases;
  • most real-time remote biometric identification in publicly accessible spaces by law enforcement.

There is no documentation package that rescues a prohibited use. If a system is in this band, the only compliant answer is to stop it.

High risk: two routes in

A system becomes a high-risk AI system through one of two doors. Most companies only look at the second one and miss the first. Either route leads to the same conformity assessment before the system reaches the market.

RouteHow it worksWhat it typically catches
Annex IThe AI is a safety component of a product, or is a product, covered by existing EU product legislation subject to third-party conformity assessment.Machinery, medical devices, lifts, vehicles and other regulated products with an AI-driven safety function.
Annex IIIThe system is used for one of the listed use cases, regardless of the sector the company sits in.Biometrics; critical infrastructure; education and vocational training; employment and HR; access to essential services, including credit scoring and insurance pricing; law enforcement; migration and border control; justice and democratic processes.

The Annex III list is where ordinary companies land: a recruitment tool that ranks applicants, a model that prices insurance, or a system that decides who gets credit is high-risk even though the business has nothing to do with machinery or medical devices.

Transparency-risk duties

  • Chatbots must disclose that they are AI. People interacting with an AI system must be informed of that fact, unless it is obvious from the circumstances.
  • Deepfakes and AI-generated content must be labelled. Synthetic image, audio, video and text content presented as real must be marked as artificially generated or manipulated.

These transparency obligations are cheap to satisfy and easy for a regulator, a journalist or a competitor to observe from the outside — which is exactly why they tend to be the first thing anyone checks.

Minimal risk

Everything not caught above sits here with no new obligations: spam filters, recommendation engines, most internal tooling. Voluntary codes of conduct are encouraged, and a regulatory sandbox is available for testing before a system moves up a level. Many organisations adopt one so that the same governance applies to systems that might be reclassified as their use expands. Minimal risk is a status, not a permanent property — repurposing a tool for an Annex III use moves it up the pyramid.

Frequently asked questions

Related reading

AI Act document packages are available now

The AI system inventory, risk classification workbook and documentation templates, in three tiers from 99 EUR. Pay once, download immediately.

See the packages