The EU AI Act risk levels are four: unacceptable, high, transparency (often called limited), and minimal. Obligations attach to the job a system does rather than to the technology inside it, so the same language model can sit on three different rungs depending on where it is pointed. Prohibited practices under Article 5 have been enforceable since 2 February 2025 and the transparency duties in Article 50 since 2 August 2026, while the heavy high-risk chapter now applies from 2 December 2027 after Regulation (EU) 2026/1744 moved it. General-purpose AI models sit outside the ladder altogether, in a chapter of their own.
Most of the practical argument turns on the second rung, because it’s the only one that comes with a written escape route.
The four-level structure is the European Commission’s own framing rather than a commentator’s simplification, and the Commission is blunt about the distribution: the regulatory framework page puts the great majority of AI currently used in the Union in the minimal category, where no specific rules apply at all. And that distribution is worth holding onto. A classification exercise that ends with everything marked high risk has almost certainly gone wrong somewhere.
The four EU AI Act risk levels
The four EU AI Act risk levels run from unacceptable through high and transparency down to minimal, and each is defined by function rather than by architecture. Regulation (EU) 2024/1689 never asks how many parameters a model has. It asks what decision the system feeds.
Unacceptable risk means banned. Article 5 lists the prohibited practices from (a) to (h), and they have been enforceable since 2 February 2025. The list covers subliminal or purposefully manipulative techniques that materially distort behaviour, exploitation of vulnerabilities tied to age, disability or social and economic situation, and social scoring that produces detrimental treatment in unrelated contexts. It runs on through predictive policing based solely on profiling or personality traits, untargeted scraping of facial images from the internet or CCTV to build recognition databases, emotion inference in workplaces and educational institutions, biometric categorisation that infers sensitive attributes, and real-time remote biometric identification in public spaces for law enforcement. Two further prohibitions were inserted by the July 2026 omnibus, covering non-consensual intimate imagery and child sexual abuse material, and those take effect on 2 December 2026.
Note what the workplace prohibition does not cover. Emotion recognition is banned in employment and education specifically, not everywhere, and medical or safety uses are carved out.
High risk is the tier with the documentation load. It’s reached by two separate routes, which the next section takes apart, and it carries the full Chapter III obligation set: a risk management system running across the lifecycle, data governance for training and testing sets, technical documentation, automatic logging, human oversight built into the design, accuracy and cybersecurity thresholds, conformity assessment before market entry, registration in the EU database, and post-market monitoring afterwards.
For an Indian services firm the relevant entries in Annex III are usually the ordinary commercial ones rather than the dramatic ones. Recruitment and application filtering, promotion and termination decisions, task allocation and performance monitoring, admission to education and exam proctoring, creditworthiness scoring, and risk pricing for life and health insurance are all on the list. Law enforcement and border control make the headlines. But employment software is what most firms actually build.
Transparency risk, the tier also called limited risk, is where disclosure replaces documentation. Article 50 requires that people are told when they’re interacting with an AI system unless that’s obvious to a reasonably well-informed person, that synthetic audio, image, video and text is marked in a machine-readable format as artificially generated or manipulated, that deployers of emotion recognition or biometric categorisation inform the people exposed to it, and that deepfakes are disclosed as such. Notice the split: some of those duties fall on providers, others on deployers, and a firm can easily carry one without the other. Article 50 has applied since 2 August 2026, which makes it the only tier with substantive duties currently biting on most commercial AI.
Minimal risk carries no substantive obligations. Spam filters, recommendation engines, inventory forecasting, the AI in a video game: none of it triggers anything under the Act.
One duty sits outside the ladder entirely and catches everyone. Article 4 covers AI literacy among staff who deal with these systems, and it has been live since February 2025 regardless of which tier a firm’s systems land in.
So does touching one of the eight Annex III areas settle the classification? Not by itself, and that gap is where most of the useful work happens.
Classifying a system under the EU AI Act risk levels
Classifying a system under the EU AI Act risk levels is a two-question test set out in Article 6, and the second question is the one most explainers leave out.
The first route is product safety. Under Article 6(1), an AI system is high risk when it functions as a safety component of a product covered by the Union harmonisation legislation in Annex I, and that product must undergo third-party conformity assessment. The July 2026 omnibus narrowed the definition here in a way that matters commercially: features that merely assist the user, optimise performance, improve service efficiency, automate a step or add convenience are not safety components, unless their failure would endanger health or safety.
The second route is Article 6(2). A system listed in Annex III is high risk by default. Default, though, is not the same as automatic, and that distinction is the whole of Article 6(3).
Under Article 6(3), an Annex III system is not high risk where it poses no significant risk of harm to health, safety or fundamental rights and it meets any one of four conditions. Those conditions are a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns without being meant to replace or influence the human assessment already made absent proper human review, or performing a preparatory task to an assessment relevant to an Annex III use case. Any one of the four suffices. But there’s a carve-out that admits no derogation at all: a system that performs profiling of natural persons is always high risk, whatever else it does.
The derogation isn’t self-executing either. Article 6(4) requires the provider to document its assessment before the system goes on the market or into service, produce that documentation to authorities on request, and register the system under Article 49(2). The omnibus reinstated a simplified registration for exactly this case, which is a fair signal of how closely self-assessed exemptions are expected to be checked. The habit it asks for is the one Article 30 of the GDPR already builds: a record written when the decision is taken, not when an authority asks for it.
What that documented assessment looks like in practice is short and specific: This system converts uploaded CVs into structured fields covering name, qualification and years of experience. It does not score, rank, filter or compare candidates, and it performs no profiling of natural persons. A recruiter reads every parsed application before any shortlist is drawn. On that basis the system performs a narrow procedural task within the meaning of Article 6(3)(a) and poses no significant risk of harm to fundamental rights.
Change one word in that description, let the tool rank candidates by fit, and the derogation collapses, because ranking people against each other is the profiling the carve-out is aimed at. The discipline here is the same one behind a privacy impact assessment: the assessment is only worth anything if it describes the system that was actually shipped.
General-purpose AI models sit alongside this ladder rather than on it. Chapter V regulates them at the model level, and those obligations have applied since 2 August 2025. Article 53 sets the baseline for every provider: technical documentation, documentation for downstream providers building on the model, a copyright policy, and a public summary of training data.
Above that, Article 51 presumes systemic risk once training compute crosses 10^25 floating point operations, a presumption that can be rebutted and that the Commission can also apply below the threshold on capability grounds. Crossing it triggers notification to the AI Office within two weeks and the Article 55 additions: model evaluation including adversarial testing, systemic-risk mitigation, serious-incident reporting and cybersecurity measures. A firm that fine-tunes someone else’s model and deploys it in recruitment is dealing with the system ladder and the model chapter at the same time, on different clocks.
The mistake we see most often is a team reading Chapter III, pricing out a conformity assessment, and never checking Article 50. That’s backwards on both counts. Article 50 is in force now and Chapter III isn’t. And the documentation that keeps a system out of Chapter III is a page of reasoning, not an audit.
Deadlines and penalties by risk level
Deadlines now vary by risk level more widely than they did when the Act was passed, because Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and pushed the high-risk chapter back. Any explainer still quoting 2 August 2026 as the high-risk date was written before that and hasn’t been touched since.
| Date | What applies |
|---|---|
| 2 February 2025 | Article 5 prohibitions, Article 4 AI literacy |
| 2 August 2025 | General-purpose AI model obligations, Chapter V |
| 2 August 2026 | Article 50 transparency duties |
| 2 December 2026 | Machine-readable marking for systems already on the market; the two new Article 5 prohibitions |
| 2 December 2027 | Stand-alone high-risk systems under Annex III |
| 2 August 2028 | High-risk systems embedded in regulated products under Annex I |
But a deferral isn’t a repeal, and it reached only the high-risk chapter. Everything above 2 December 2027 in that table is either already enforceable or lands within the next fifteen months.
The omnibus also settled what happens to systems already running. A system lawfully placed on the market before its applicable date can keep being supplied at type and model level without picking up the new obligations, provided the design isn’t materially changed. But material change after the date pulls the system into full compliance, which makes the definition of a substantial modification a live commercial question rather than a drafting detail.
Penalties don’t scale evenly across the tiers. Article 99 sets administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover for breaching the Article 5 prohibitions, up to EUR 15 million or 3% for most other obligations including Article 50, and up to EUR 7.5 million or 1% for supplying incorrect, incomplete or misleading information to authorities. Turnover, not profit, and worldwide, not European. And the detail that gets reported wrong almost every time sits in Article 99(6): for small and medium enterprises, including start-ups, each fine is capped at whichever of the amount or the percentage is lower, not higher.
One obligation moved in the other direction. The omnibus softened Article 4, shifting AI literacy from a duty on organisations to ensure staff competence towards a duty on the Commission and Member States to support and facilitate it. The evidentiary burden on an individual firm drops. The commercial case doesn’t, because European clients run vendor questionnaires whether or not a regulator demands the training record, and a credential such as CIPP/E still answers that question faster than a policy document.
For a firm outside the Union the sequencing is fairly mechanical. Establish first whether the Act reaches the business at all, which turns on Article 2 and is worked through in detail in does the EU AI Act apply to Indian companies. Next, sort each AI-touching workstream against Article 50 before opening Chapter III, since Article 50 is the tier already in force. After that, for anything sitting in an Annex III area, write the Article 6(3) assessment or accept the high-risk load.
That written assessment is the single cheapest artefact in the whole exercise, and it’s the one that decides which of two very different compliance programmes a firm ends up running. India has no umbrella AI statute to fall back on, so this work gets built rather than inherited from whatever the business already runs under the DPDP Act.
Frequently asked questions
Can an AI system’s risk level change after it is deployed?
Yes, and it happens without any deliberate decision. Article 25(1) turns a deployer into a provider on three triggers: putting its own name on a high-risk system, making a substantial modification, or changing the intended purpose so a system becomes high risk.
Who decides which EU AI Act risk level applies to a system?
The provider does, through self-assessment. No pre-approval body issues a classification and no regulator signs off before market entry. National authorities check afterwards, which is why Article 6(4) wants the not-high-risk assessment documented before the system ships.
Is a customer service chatbot high risk under the EU AI Act?
Usually not. A general support chatbot sits in the transparency tier and owes disclosure under Article 50(1), so users are told they are dealing with AI unless that is obvious. It turns high risk only if it performs an Annex III function, such as screening job applicants.
Do the risk levels apply to AI a company uses only internally?
Yes. Putting a system into service for a company’s own use is covered, and deployer duties attach to use rather than to sale. An internal recruitment screening tool built in-house sits in Annex III area 4 exactly as a bought one would, on identical terms.
References
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 4, 5, 6, 25, 49, 50, 51, 53, 55 and 99, and Annex III. https://artificialintelligenceact.eu/
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 2026/1744, 24 July 2026, in force 27 July 2026. https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- European Commission, Regulatory framework for AI, Shaping Europe’s digital future. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission, General-purpose AI obligations under the AI Act. https://digital-strategy.ec.europa.eu/en/factpages/general-purpose-ai-obligations-under-ai-act
This article is general information about a regulation and how it classifies AI systems, current as of 2 September 2026. It is not legal advice on any specific system, product or contract. Which risk level applies to a particular AI system depends on facts this article cannot see, and the classification carries consequences that a qualified professional should review before anything is placed on the market.


Allow notifications