EuroComply
Free assessment

EU AI Act

The 4 EU AI Act risk levels, explained with examples

Every AI system placed on the EU market falls into one of four tiers. The tier decides everything: whether you need a lawyer, a compliance file, a disclosure banner, or nothing at all.

Prohibited

Article 5

Banned outright. No conformity path, no documentation makes it legal.

Real examples

  • Government social scoring systems that rank citizens by behaviour
  • Real-time remote biometric identification in public spaces for law enforcement (narrow judicial exceptions apply)
  • Systems that exploit vulnerabilities of children, elderly people, or people with disabilities to distort behaviour
  • Subliminal techniques designed to materially distort a person's behaviour and cause harm

What this means for you

Do not deploy in the EU. There is no compliance path, only removal or redesign of the use case.

High risk

Article 6, Annex III

Legal, but only with a full compliance package before going to market.

Real examples

  • CV screening or candidate ranking tools used in hiring
  • Credit scoring or insurance pricing models that affect access to services
  • AI used in medical diagnosis or triage
  • Proctoring or grading systems used in education
  • Biometric categorisation and emotion recognition in the workplace

What this means for you

Conformity assessment, technical documentation, risk management system, human oversight, and EU database registration before 2 August 2026.

Limited risk

Article 50

Legal with disclosure. The obligation is transparency, not certification.

Real examples

  • Customer-facing chatbots and virtual assistants
  • Product recommendation engines on ecommerce sites
  • Tools that generate marketing copy, images, or video
  • Deepfake or synthetic media generators

What this means for you

Tell users clearly they are interacting with AI, and label AI-generated content where technically feasible.

Minimal risk

Article 95 (voluntary)

No mandatory obligations today. Most AI systems sit here.

Real examples

  • Spam filters and inbox categorisation
  • AI opponents or non-player characters in games
  • Internal analytics and forecasting tools
  • Search ranking and internal recommendation systems with no consumer-facing decision impact

What this means for you

None today. Voluntary codes of conduct are encouraged, and a change of use case can move you into a higher tier.

Which tier applies to your system?

Answer 7 questions and get your classification in about 3 minutes.

Start the assessment

Related

Main Guide

EU AI Act compliance guide for tech companies

Timeline, obligations, and fines in full

Limited Risk Deep Dive

AI Act rules for chatbots and recommenders

What Article 50 disclosure actually requires