The EU AI Act classifies every in-scope AI system into one of four risk tiers: unacceptable, high, limited, or minimal. The higher the potential harm to rights and safety, the stricter the obligations.
This article covers all four EU AI Act risk categories: what puts a system in each tier, what compliance requires, and how to run the classification yourself.
What are the four EU AI Act risk categories?
Each tier carries different obligations. Getting the classification right is the foundation of your EU AI Act compliance work.
How the EU AI Act’s Risk-Based Approach Works
The regulation scales obligations to risk: the greater the potential harm to people’s rights or safety, the stricter the requirements. Some AI is banned outright. Some requires full conformity assessment. Some only needs a disclosure. Most faces nothing mandatory at all.
| Tier | Applies to | Classification trigger | Key articles | Fine exposure |
|---|---|---|---|---|
| Unacceptable | All EU providers and deployers | System performs any Article 5 prohibited practice | Art. 5 • Art. 99(3) | €35M or 7% |
| High Risk | Providers (conformity) & deployers (oversight) | Annex III use case or Annex I safety component | Arts. 9–17 • Art. 72 • Art. 99(4) | €15M or 3% |
| Limited Risk | Deployers of conversational or generative AI | Interacts conversationally or generates/alters content | Art. 50 • Art. 99(4) | €15M or 3% |
| Minimal Risk | All organisations | Below all Art. 5, Annex III, Annex I & Art. 50 thresholds | Art. 95 (voluntary) | None. Retain classification rationale |
This table shows who is responsible for compliance in each tier, what triggers that tier, which articles apply, and the fine exposure for non-compliance. Source: Regulation (EU) 2024/1689
JAGGAER
Manage supplier AI compliance evidence in one place
JAGGAER Supplier Intelligence supports supplier visibility, documentation management, and AI governance readiness.
Tier 1: Unacceptable Risk (Banned)
Article 5 doesn’t restrict these eight practices. It bans them. There’s no assessment you can pass, no technical documentation that legitimises them, no transitional grace period that applies. They came into force on 2 February 2025 and became enforceable six months later. The maximum fine is €35M or 7% of global annual turnover, whichever is the larger figure (Article 99(3)).
Subliminal manipulation causing harm
Exploiting vulnerabilities (age, disability, poverty)
Social scoring by public authorities
Criminal risk prediction from profiling
Untargeted facial image scraping
Emotion recognition in workplaces or education
Biometric categorisation of sensitive attributes
Real-time biometric ID in public spaces
For most enterprise teams, the three practices with the most immediate exposure are social scoring by public authorities (c), workplace emotion recognition (f), and untargeted facial image scraping (e). All were enforceable from 2 August 2025. To make that concrete: a local authority running an AI system that scores residents’ benefit eligibility is in scope under Article 5(1)(c). An employer using real-time emotion inference on video calls hits Article 5(1)(f). Both are prohibited regardless of intent.
Tier 2: High Risk. What the 2026 Deadline Changes
High-risk AI systems sit at the top of the operational tier, deployable but with the most demanding compliance requirements in the regulation. The Digital Omnibus provisional agreement (7 May 2026) pushed the Annex III deadline back to 2 December 2027 for stand-alone systems, and 2 August 2028 for Annex I embedded products. (European Commission, Digital Omnibus, 2026) That deferral is still provisional. Formal adoption has not yet occurred.
A system is high risk if it matches one of the eight Annex III use-case categories or functions as an Annex I safety component in a regulated product. Classification is based on what the system does, not how it’s marketed.
The eight Annex III categories
| # | Category | Scope |
|---|---|---|
| 1 | Biometrics | Identity verification, categorisation, emotion detection |
| 2 | Critical infrastructure | Water, energy, transport |
| 3 | Education & training | Admissions, grading, assessment |
| 4 | Employment | CV screening, ranking, evaluation |
| 5 | Essential services | Credit scoring, insurance, social benefits |
| 6 | Law enforcement | Risk assessment, crime prediction |
| 7 | Migration & border control | Visa, asylum, border control |
| 8 | Administration of justice | Courts; electoral campaign AI |
Six compliance obligations
| Provider & deployer requirements: Articles 8–17 & 72 |
|---|
| Conformity assessment & Annex IV documentation |
| Risk management: Article 9 |
| Data governance: Article 10 |
| Human oversight: Article 14 |
| Accuracy & robustness: Article 15 |
| Post-market monitoring: Article 72 (logs: 6 months min.) |
JAGGAER
JAI includes the logging, oversight controls, and documentation outputs that Tier 2 providers need.
JAI combines ISO 42001 governance, human oversight, and tenant-isolated data.
Tier 3: Limited Risk (Transparency Requirements)
Tier 3 systems have one requirement: be transparent about using AI. Article 50 is the relevant provision, covering chatbots, AI-generated content, emotion recognition, and biometric categorisation systems that aren’t already caught by Tier 1. No conformity assessment, no technical file, nothing like the Tier 2 burden. Just tell people. That obligation applies from 2 August 2026; systems already on the market when the rule kicks in have until 2 December 2026 to meet the watermarking requirements. (European Commission, AI Policy, 2026)
Getting this wrong is expensive. Failing to disclose can draw a fine of up to €15M or 3% of worldwide annual turnover under Article 99(4), a steep number for a labelling obligation. The regulation isn’t subtle on this point.
Tier 4: Minimal Risk (Largely Unregulated)
Most AI systems land here under the EU AI Act: spam filters, recommendation engines, logistics tools, internal workflow automation. The regulation places no mandatory obligations on them. There’s nothing you’re required to assess, file, or disclose. That said, if your system is ever queried by a regulator or an auditor, you’ll want to show you thought through the classification. Write down which articles and annexes you checked and why they didn’t apply. It doesn’t take long and it closes an otherwise open question.
An hour of documentation now. Potentially a lot less explaining later.
| Quick check: confirming minimal risk | Solution |
|---|---|
| Article 5 prohibited practice? | If yes → Tier 1 |
| Annex III use case or Annex I safety component? | If yes → Tier 2 |
| Article 50 transparency trigger? | If yes → Tier 3 |
| None of the above | Likely Tier 4 |
JAGGAER
Keep your EU AI Act classification rationale inside your supplier contracts
JAGGAER Contract Management helps teams organize contract documentation and maintain audit trails.
How to Classify Your AI System
Working through the EU AI Act risk classification takes four steps. Go in sequence and stop when you hit a yes. Classification turns on what the system actually does, not what it’s called, what the vendor says, or how it’s described internally. Function determines tier.
For systems spanning multiple Annex III categories or embedded in regulated products, take legal advice before finalising classification.
JAGGAER
JAGGAER connects contract, supplier, and spend data in one EU AI Act-ready platform
JAI supports responsible AI with ISO 42001 certification, human oversight, and tenant-isolated data.
Frequently Asked Questions
Four tiers, each with different consequences. Unacceptable risk (Article 5): banned outright, no compliance pathway. High risk (Annex III and Annex I): deployable, but only with full conformity assessment, oversight requirements, and ongoing monitoring obligations. Limited risk (Article 50): just a disclosure requirement: tell users they're interacting with AI. Minimal risk: most AI systems, no specific mandatory obligations under the regulation.
Article 5 lists eight prohibited categories. They've been in force since 2 February 2025: subliminal manipulation causing harm; exploiting vulnerabilities based on age, disability, or socioeconomic status; social scoring by public authorities; using profiling to predict criminal behaviour; scraping faces from CCTV or the internet to build recognition databases; assessing emotions in workplaces or schools; inferring sensitive characteristics from biometrics; and real-time remote biometric identification in public spaces for law enforcement, with narrow exceptions.
It falls within one of the eight Annex III use-case categories (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, administration of justice), or it is an Annex I safety component. The classification is based on what the system does, not what your vendor calls it.
Providers carry the heavier load: conformity assessment, Annex IV documentation, Article 9 risk management, Article 10 data governance, Article 14 human oversight, Article 15 robustness, and Article 72 post-market monitoring. Deployers have their own obligations too. They must use the system within its intended purpose, implement the oversight mechanisms the provider specifies, and keep logs for at least six months.
Limited risk means one obligation: tell people they are interacting with AI. Article 50 covers chatbots, AI-generated images, audio, video, and deepfakes. No conformity assessment. No technical documentation. Just the disclosure. Non-compliance can cost up to €15 million or 3% of global turnover under Article 99(4). Applies from 2 August 2026.
Minimal risk is the catch-all for AI that doesn't meet the threshold for any of the higher tiers. Spam filters, recommendation algorithms, workflow tools; they typically end up here. The regulation doesn't mandate anything for these systems. Article 95 encourages voluntary codes of conduct if you want to demonstrate good practice, but there's no legal requirement. Worth keeping a written record of how you reached that classification, though, it's the kind of thing an auditor would ask for.
Start at the top and work down. Does it do anything Article 5 prohibits? If yes, it cannot be deployed. Does it match an Annex III use case or an Annex I safety component? If yes, high-risk obligations apply. Does it trigger Article 50 disclosure? If yes, disclose. If none of those apply, you are probably looking at minimal risk. Document the reasoning at each step. That document is what a regulator would ask for.
Article 5 is the prohibition list. It defines what the EU considers unacceptable: AI practices that are banned regardless of safeguards, intent, or technical sophistication. These came into force 2 February 2025 and became enforceable from 2 August 2025. The Commission published interpretive guidance on 4 February 2025. Enforcement is handled by national market surveillance authorities in each member state, not by a central EU body.
Public-authority social scoring is banned. Article 5(1)(c) prohibits AI that classifies individuals based on social behaviour where this leads to disproportionate or detrimental treatment. Private-sector credit scoring is a separate matter. It is not banned, but it does sit in Annex III Category 5 as a high-risk use case with its own compliance obligations.
The fine structure in Article 99 scales with the severity of the violation. Deploying a system that hits an Article 5 prohibition: up to €35 million or 7% of worldwide annual turnover (whichever is higher) under Article 99(3). Non-compliance with Tier 2 high-risk obligations: up to €15 million or 3% under Article 99(4). Providing inaccurate or misleading information to regulators: up to €7.5 million or 1% under Article 99(5). These are ceilings. National supervisory authorities exercise discretion in individual cases.
Next Steps
Classification is the first step, not the finish line. If you landed in Tier 2, there's real programme work ahead: conformity assessment, data governance, human oversight, post-market monitoring. None of it is lightweight, and none of it can wait until closer to the deadline. If you haven't yet inventoried your AI systems, that comes before any of this. You can't classify what you don't know you're running.
Talk to a procurement expert.
Tell us your challenge. We will show you exactly where JAGGAER One fits into your current setup — with specifics, not a generic demo.
- Direct or indirect?
We handle both — on one platform. - Already have an ERP?
JAGGAER Link connects to 1,000+ systems, no rip-and-replace. - Need to show ROI fast?
We define outcomes and KPIs before you sign. - Vertical-specific?
Manufacturing, higher ed, public sector — configured, not customized.



