← Back to Klariq Check my obligations →

EU AI Act risk categories and risk levels explained

Regulation (EU) 2024/1689 sorts every AI system into one of four risk categories. The category decides which obligations apply, what they cost to get wrong, and from which date they bite.

The EU AI Act does not regulate "AI" as a single thing. It sorts each AI system your company provides or uses into one of four risk levels, based on what the system is used for rather than on the technology behind it. Two companies running the same chatbot software can land in different risk classes depending on the purpose they put it to.

A note on wording, because it trips people up when they search: the Regulation itself never uses the word "tier". Risk tiers, risk levels, risk categories and risk classes are four names for the same four-way split. What the Regulation actually contains is a prohibition in Article 5, a high-risk regime in Chapter III, a set of transparency duties in Article 50, and silence about everything else. This page uses the terms interchangeably, because the search results, the trade press and the national authorities all do.

The four risk levels compared

Risk categoryLegal basisWho it bindsCore obligationApplies fromMaximum fine
Prohibited
(unacceptable risk)
Art. 5 Anyone placing on the market, putting into service or using the system Do not do it at all 2 Feb 2025
(NCII and CSAM generation bans: 2 Dec 2026)
EUR 35M or 7% of worldwide turnover, whichever is higher (SMEs incl. start-ups: whichever is lower, Art. 99(6))
High-risk Art. 6, Annex I and Annex III Providers heavily, deployers more lightly, plus importers and distributors Risk management, data governance, technical documentation, logging, human oversight, conformity assessment 2 Dec 2027 (Annex III)
2 Aug 2028 (Annex I)
EUR 15M or 3%, whichever is higher (SMEs incl. start-ups: whichever is lower, Art. 99(6))
Limited-risk
(transparency)
Art. 50 Providers for paras 1 and 2, deployers for paras 3 and 4 Tell people they are dealing with AI, and mark AI-generated content 2 Aug 2026
(marking of pre-existing systems: 2 Dec 2026)
EUR 15M or 3%, whichever is higher (SMEs incl. start-ups: whichever is lower, Art. 99(6))
Minimal-risk No specific provision No tier-specific duties; Art. 4 AI literacy still applies None beyond Art. 4 AI literacy Not applicable No category-specific fine

Two things in that table catch most SMEs by surprise. First, the risk level that applies to almost all of them is limited-risk, and it is the one whose deadline has already passed. Second, the fines are ceilings on what a national authority may impose, not tariffs, and for smaller companies the ceiling is calculated the other way round. Both points are worked through below.

Risk category 1: prohibited AI practices (Article 5)

Prohibited: Article 5

A closed list of AI practices banned outright, whatever safeguards you put around them. There is no conformity assessment that makes a prohibited practice lawful.

Article 5(1) bans, among others:

The Digital Omnibus (Regulation (EU) 2026/1744) inserted two further prohibitions as Article 5(1)(ba) and (bb): AI systems that generate or manipulate non-consensual intimate material depicting an identifiable person, and AI systems that generate or manipulate child sexual abuse material. New Article 5(1a) narrows those two for providers to systems whose intended purpose is that generation, or whose design makes it a reasonably foreseeable and reproducible outcome without adequate safeguards; for deployers it bites only when they actually use the system for that purpose. Those two bans apply from 2 December 2026, not from February 2025 like the rest of Article 5.

Worked example. A logistics company installs a webcam tool that scores warehouse staff for "engagement" and "frustration" from facial expression, and feeds the scores into shift allocation. That is emotion inference in the workplace under Article 5(1)(f), and it is not saved by consent, by anonymisation or by an internal policy. The correct action is to switch it off, not to document it.

Risk category 2: high-risk systems (Article 6, Annex I and Annex III)

High-risk: Article 6, Annex I and Annex III

Two separate routes into this risk class, with different deadlines and different conformity mechanics.

Route A: Annex III stand-alone use cases

Article 6(2) makes any system listed in Annex III high-risk. The eight Annex III areas are biometrics; critical infrastructure; education and vocational training; employment and workers' management; access to essential private and public services; law enforcement; migration, asylum and border control; and administration of justice and democratic processes. For a company outside the public sector, the entries that matter in practice are recruitment and candidate evaluation, decisions on promotion or termination and task allocation, creditworthiness evaluation and credit scoring, and risk assessment and pricing for life and health insurance.

Article 6(3) contains a filter that is routinely missed. A system in an Annex III area is not high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and it meets one of four conditions: it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations without replacing or influencing the earlier human assessment, or performs a preparatory task. The escape hatch closes the moment the system performs profiling of natural persons: such a system is always high-risk. A provider relying on Article 6(3) must document the assessment before placing the system on the market and register it under Article 49(2).

Route B: Annex I safety components

Article 6(1) covers AI used as a safety component of a product, or as a product, that is covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment: machinery, medical devices, vehicles, toys, lifts, radio equipment and similar. The Digital Omnibus added Article 6(1a) to (1c), which clarify that AI used solely for non-safety aspects such as user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not qualify as a safety component, while AI whose failure would endanger health and safety does.

What the high-risk category actually requires

RoleObligationsWhere
ProviderRisk management system, data governance, technical documentation, automatic logging, transparency and instructions for use, human oversight design, accuracy, robustness and cybersecurity, quality management system, conformity assessment, EU declaration of conformity, CE marking, registration, corrective actionArt. 16 to 21, 43, 47 to 49
DeployerUse in line with the instructions for use, assign human oversight to competent and trained people with authority and support, ensure relevant and representative input data where they control it, monitor operation and suspend and report where a risk appears, keep logs for at least six months, inform workers' representatives and affected workers before workplace useArt. 26
Importer, distributorVerify conformity assessment, documentation and marking before placing on the market or making availableArt. 23, 24

Worked example. A 40-person recruitment agency buys an applicant-ranking tool and uses it to shortlist candidates. The agency is a deployer, not a provider, so its duties are the Article 26 list: follow the instructions for use, put a named, trained person in charge of oversight with real authority to overrule the ranking, keep the logs, and tell affected workers. The vendor carries the Article 16 provider load. Because the tool sits in Annex III area 4, the obligations apply from 2 December 2027, so the agency's realistic 2026 task is contractual: get the vendor to commit in writing to being conformity-assessed in time.

Risk category 3: limited-risk and the Article 50 transparency duties

Limited-risk: Article 50 (transparency)

The risk level that catches almost every SME using generative AI or a chatbot. No conformity assessment, no CE marking, no notified body. Four concrete disclosure duties instead.

DutyWho owes itWhat it means
Art. 50(1)ProviderSystems intended to interact directly with people must be designed so that people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person. What a chatbot disclosure meeting Article 50(1) looks like.
Art. 50(2)ProviderSystems generating synthetic audio, image, video or text must mark the output in a machine-readable format, detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. Does not apply where the system performs an assistive function for standard editing or does not substantially alter the input or its semantics. How watermarking maps onto this duty.
Art. 50(3)DeployerPeople exposed to an emotion recognition or biometric categorisation system must be informed of its operation, and the personal data handled under the GDPR.
Art. 50(4)DeployerDeep fakes must be disclosed as artificially generated or manipulated. For evidently artistic, creative, satirical or fictional work the duty is limited to disclosing the existence of such content in a way that does not hamper enjoyment of the work. Text published to inform the public on matters of public interest must also be disclosed, unless it went through human review with a named person holding editorial responsibility.

Article 50(5) sets the timing and form: the information must reach the person concerned in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and must meet applicable accessibility requirements. A disclosure buried in a terms-of-service page does not satisfy that.

Worked example. A Czech e-shop runs a support chatbot on its product pages and publishes AI-drafted blog posts that a human editor reviews and signs off. The chatbot needs a first-contact disclosure under Article 50(1), which in practice is one line in the opening message. The blog posts fall outside the Article 50(4) text-disclosure duty because a named person holds editorial responsibility after human review. The AI writing tool's own provider, not the e-shop, carries the Article 50(2) machine-readable marking duty. All of that is live now: the deadline was 2 August 2026.

Risk category 4: minimal risk

Minimal-risk

Everything the other three risk classes do not catch: spam filters, AI-enabled video games, inventory forecasting, most internal productivity tools. No AI Act specific obligations.

Minimal risk is the residual category. The AI Act imposes no tier-specific duties on these systems, but the GDPR, employment law, consumer law and sector rules keep applying exactly as before, and Article 4 AI literacy still binds the people operating them.

The duty that ignores the risk classes entirely

Article 4 (AI literacy) has applied since 2 February 2025 and sits outside the four-category structure: it binds every provider and deployer of any AI system, at any risk level, including minimal-risk ones. As replaced by the Digital Omnibus, it requires providers and deployers to take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training, the context of use, and the people the systems are used on. The same paragraph states that the obligation does not require guaranteeing any specific level of AI literacy of any individual.

Which risk category is my system? Worked examples

What you doRisk categoryWhy
Support chatbot on your websiteLimited-riskInteracts directly with people, so Art. 50(1) applies. No Annex III purpose.
Generative AI drafting marketing copy, human-edited before publicationLimited-riskArt. 50(2) marking sits with the tool's provider. Art. 50(4) text disclosure is displaced by editorial responsibility.
CV screening or candidate rankingHigh-riskAnnex III area 4(a). Art. 6(3) rarely rescues it, and never where the system profiles candidates.
Credit scoring for consumer lendingHigh-riskAnnex III area 5(b). Fraud detection is expressly carved out of that entry.
Spell-checking or reformatting an existing documentMinimal-riskAssistive function for standard editing, expressly outside Art. 50(2).
Emotion analysis of employees or studentsProhibitedArt. 5(1)(f), outside medical or safety purposes.
Deepfake video of a real person in an adLimited-risk, disclosure requiredArt. 50(4) deep fake labelling. It becomes prohibited if the material is intimate and non-consensual, from 2 Dec 2026.

Penalties per risk category, and the Article 99(6) SME cap

Article 99 sets three ceilings, and they follow the risk categories:

BreachGeneral ceilingBasis
Prohibited practices (Art. 5)Up to EUR 35,000,000 or, if the offender is an undertaking, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher; for SMEs including start-ups, whichever is lower (Art. 99(6))Art. 99(3)
Art. 50 transparency, provider duties (Art. 16), deployer duties (Art. 26), importer, distributor, authorised representative and notified body dutiesUp to EUR 15,000,000 or 3% of total worldwide annual turnover, whichever is higher; for SMEs and SMCs, whichever is lower (Art. 99(6), (6a))Art. 99(4)
Supplying incorrect, incomplete or misleading information to notified bodies or national competent authoritiesUp to EUR 7,500,000 or 1% of total worldwide annual turnover, whichever is higher; for SMEs and SMCs, whichever is lower (Art. 99(6), (6a))Art. 99(5)

Article 99(6): for SMEs the rule is inverted

For a smaller company this provision changes the practical exposure more than any other sentence in Article 99. Article 99(6) provides that in the case of SMEs, including start-ups, each fine referred to in Article 99 shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower. The general rule takes the higher of the fixed sum and the percentage; for an SME the ceiling is the lower of the two.

SME here means a micro, small or medium-sized enterprise as defined in Recommendation 2003/361/EC, which the Digital Omnibus wrote into the AI Act as Article 3(14a): broadly, fewer than 250 staff and either annual turnover of EUR 50 million or less or a balance sheet total of EUR 43 million or less.

Worked example. A Polish SME with EUR 4 million of annual turnover ships a chatbot with no AI disclosure and is found in breach of Article 50. Under the general Article 99(4) rule the ceiling would be the higher of EUR 15 million and 3% of turnover (EUR 120,000), so EUR 15 million. Under Article 99(6) the ceiling is the lower of the two, so EUR 120,000. Take the same company breaching the Article 5 prohibition: the general ceiling would be EUR 35 million, the SME ceiling is 7% of EUR 4 million, so EUR 280,000.

These are maximums, not expected fines. Article 99(7) requires the authority to weigh gravity, duration, cooperation, whether the operator self-reported, and any mitigating factor, and Article 99(1) as amended requires Member States to take into account the interests of SMEs, including start-ups, and small mid-cap enterprises, and their economic viability when imposing penalties.

One boundary worth knowing: the Digital Omnibus inserted Article 99(6a), which gives small mid-cap enterprises the same lower-of treatment, but only for paragraphs 4 and 5. The prohibited-practices ceiling in paragraph 3 keeps its higher-of calculation for small mid-caps. The full SME carve-out in paragraph 6 remains the wider one.

What you must do, and by when

Already overdue

  • Since 2 Feb 2025: stop any Article 5 practice. Confirm in writing that no tool in use does workplace emotion inference, social scoring or untargeted face scraping.
  • Since 2 Feb 2025: have Article 4 AI-literacy measures in place, with a record that the training happened.
  • Since 2 Aug 2026: Article 50 disclosures live on every customer-facing AI interaction, at first contact.

Next deadlines

  • 2 Dec 2026: systems generating synthetic content that were on the market before 2 August 2026 must meet the Article 50(2) machine-readable marking duty (Art. 111(4)). The Article 5(1)(ba) and (bb) bans also start.
  • 2 Dec 2027: full high-risk regime for Annex III systems. If you deploy one, the contractual work with your vendor starts long before this date.
  • 2 Aug 2028: high-risk regime for Annex I embedded safety components.

How to classify your own system

  1. Fix the purpose, not the technology. Ask what decision the output feeds, about whom, and with what consequence. Model architecture is irrelevant to the risk category.
  2. Check Article 5 first. It is a short closed list and it overrides everything below it.
  3. Check Annex III against your actual use case, then test the Article 6(3) filter, and stop if the system profiles natural persons.
  4. Check Annex I if the AI sits inside a physical product that needs third-party conformity assessment.
  5. Check Article 50 regardless of the answers above: the transparency duties can stack on top of a high-risk classification.
  6. Record the reasoning. Article 6(4) requires a documented assessment where a provider concludes an Annex III system is not high-risk, and a documented classification is what you hand an authority or an enterprise customer that asks.

Most companies using AI turn out to be deployers of limited-risk or minimal-risk systems, not providers of high-risk ones. Klariq's free classifier asks a short set of questions about how you use AI and tells you which risk category and which obligations apply, with the correct post-omnibus dates.

Common questions

How many risk categories does the EU AI Act have?

Four: prohibited (Art. 5), high-risk (Art. 6 with Annex I and Annex III), limited-risk or transparency (Art. 50), and minimal-risk (no AI Act specific obligations). The Regulation itself never uses the word tier; risk tiers, risk levels, risk categories and risk classes all describe the same four-way split.

What is the difference between risk levels and risk categories in the EU AI Act?

There is no legal difference. Both are informal names for the same structure in Regulation (EU) 2024/1689: an unacceptable-risk ban in Article 5, a high-risk regime in Chapter III, transparency duties in Article 50, and everything else left unregulated by the AI Act.

Which risk category is a customer-facing chatbot?

Almost always limited-risk. It must meet the Article 50 transparency duties, in particular telling users they are interacting with an AI system, and not the heavier high-risk regime, unless the same system is also used for an Annex III purpose such as credit scoring, insurance pricing or recruitment, which pulls it into the high-risk category.

Are the high-risk obligations in force now?

No. The Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, amended Article 113 so that Chapter III Sections 1 to 3 apply from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I systems. Article 50 transparency was not deferred and applies from 2 August 2026.

What are the fines for each EU AI Act risk category?

Article 99(3) caps fines for prohibited practices at EUR 35 million or 7 percent of total worldwide annual turnover, whichever is higher. Article 99(4) caps fines for Article 50 transparency breaches and the high-risk operator duties at EUR 15 million or 3 percent, whichever is higher. Article 99(5) caps fines for supplying incorrect, incomplete or misleading information to authorities at EUR 7.5 million or 1 percent, whichever is higher. For SMEs including start-ups, Article 99(6) makes each cap the lower of the two figures instead.

Is there a smaller penalty cap for SMEs?

Yes. Article 99(6) reverses the rule for SMEs including start-ups: each fine referred to in Article 99 shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower. For a company below the fixed-amount threshold the percentage of turnover therefore becomes the ceiling. Article 99(6a), inserted by the Digital Omnibus, gives small mid-cap enterprises the same lower-of rule, but only for paragraphs 4 and 5.

Does the AI literacy duty depend on the risk category?

No. Article 4 sits outside the four risk classes and binds every provider and deployer of any AI system, including minimal-risk ones. It has applied since 2 February 2025.

This page is general information about Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, not legal advice, and does not replace a case-by-case legal assessment. Article text was checked against the consolidated Official Journal texts. Last verified: 27 August 2026.