Hlinix.com

Chapter 10: Minimal-Risk and Out-of-Scope AI — What You Still Need to Do

EU AI Act Implementation Guide · Full Chapter

What you will learn: By the end of this chapter, you will understand what minimal-risk means in practice, why Article 4 AI literacy is the one obligation that applies universally, what “out-of-scope” exclusions actually cover, and why misclassifying a system as minimal-risk carries some of the highest penalties in the AI Act.

The Default Category

The EU AI Act classifies AI systems into four categories: prohibited, high-risk, limited-risk, and minimal-risk. Minimal-risk is the default: any AI system that is not prohibited under Article 5, not high-risk under Article 6 and Annex III, and not limited-risk under Article 50 falls here. It is not a category you are assigned to — it is the category you land in after ruling out everything else.

Examples of minimal-risk AI systems include spam filters, content recommendation engines, translation tools, code-completion assistants, and analytics dashboards. These are systems that process data, assist users, and generate outputs, but do not fall into the specific use-case domains that the AI Act treats as elevated risk.

Minimal-risk carries one substantive obligation: Article 4 AI literacy. It does not carry conformity assessments, fundamental rights impact assessments, EU database registration, human-oversight officers, six-month log retention, or CE marking. For most SMEs and developers deploying AI tools that are not in Annex III domains, minimal-risk is the realistic outcome of a classification exercise — and Article 4 is the only requirement to fulfil.

Article 4: AI Literacy — The One Obligation Everyone Has

Article 4 entered into force on 2 February 2025. It applies to every provider and deployer of an AI system, regardless of risk category. There are no exemptions based on company size, sector, or system type. A sole trader who deploys a code-completion tool has the same Article 4 obligation as a multinational that deploys a complex recommendation engine.

The obligation is a best-efforts standard: providers and deployers must take reasonable steps to ensure that their staff and anyone who operates AI systems on their behalf has a sufficient level of AI literacy — appropriate to their role, the systems they use, and the context in which those systems operate. The law does not prescribe a specific training curriculum, exam, or certification. It requires proportionate, documented effort.

The Three-Layer Training Framework

A practical three-layer framework satisfies the Article 4 obligation for most organisations:

Layer 1 — Awareness training (30–60 minutes): All staff who use any AI tool in a professional context. Covers what AI is, what the AI Act requires, and what constitutes a minimal-risk versus higher-risk use case. Designed to ensure every employee understands why AI literacy matters and what caution looks like in practice.

Layer 2 — Role-specific training: Staff who regularly use AI tools as part of their workflow — developers, analysts, content teams, operations staff. Covers the specific AI tools in use, their limitations, and the deployer obligations that apply in their domain. Training is tailored to the actual systems the role interacts with.

Layer 3 — Specialist training: Staff responsible for AI procurement, legal and compliance functions, technical architects, and senior decision-makers. Covers AI Act obligations in full, including risk classification methodology, documentation requirements, and oversight structures.

Calibrated training hours by organisation size serve as a practical benchmark: micro-enterprises (fewer than 10 employees) should budget 4–8 hours total; SMEs (10–249 employees) 20–40 hours across layers; large enterprises (250+ employees) 100–300 hours, scaled to headcount and AI exposure.

What Article 4 Requires You to Document

The AI Act does not specify a documentation format, but enforcement proceedings will ask what you did and when. Maintain records of: which training was delivered, who attended, when it was delivered, the content covered, and the date of the last update. For large organisations, this means a training registry. For a sole trader, a dated file with a record of what was read or completed is sufficient. The standard is proportionality, not perfection.

What Minimal-Risk Does NOT Require

For a system correctly classified as minimal-risk, the following are not required:

ObligationRequired for Minimal-Risk?
Fundamental Rights Impact Assessment (FRIA) under Article 27No
Conformity assessment under Article 43No
EU database registration under Article 71No
Human-oversight officerNo
Six-month log retention under Article 26(6)No
Article 26(7) worker notificationNo
Annex IV technical documentationNo
CE markingNo
Article 4 AI literacyYes — universal obligation

The table above assumes correct classification. The entire minimal-risk framework depends on the classification exercise being accurate. If a system is incorrectly classified as minimal-risk when it is in fact high-risk or prohibited, none of these exemptions apply — and the penalties for misclassification are among the highest in the regulation.

Out-of-Scope: Genuinely Outside the AI Act

Out-of-scope is distinct from minimal-risk. An out-of-scope AI system is not subject to the AI Act at all — not even Article 4. Out-of-scope status derives from Article 2 exclusions, which are narrow and specific.

The Article 2 Exclusions

Military and national security (Article 2(3)): AI systems developed or used exclusively for military purposes, national defence, or national security are excluded from the AI Act. This exclusion applies to sovereign defence activities, not to commercial security products or dual-use technology. A vendor selling a surveillance product to both civilian law enforcement and military customers does not fall outside the AI Act on the basis of the military exclusion — civilian law enforcement deployments remain in scope.

Scientific research and development (Article 2(6)): AI systems developed and used solely for the purpose of scientific research and development are excluded, provided the system is not placed on the market or put into service. A model trained and used internally within a university research group is excluded. The same model, once published as an API or integrated into a commercial product, is no longer excluded.

Personal non-professional use (Article 2(10)): AI systems used solely for personal, non-professional purposes are excluded. Using a generative AI tool to plan a holiday or write a personal blog post falls outside the AI Act. Using the same tool to process client data, generate customer communications, or support any business function does not — regardless of the scale of use.

Open-source AI with exceptions (Article 2(12)): Open-source AI components made available under open licences are generally excluded from provider obligations, unless they are placed on the market or put into service as high-risk AI systems, or as an AI system falling under Article 5 (prohibited practices) or Article 50 (transparency obligations). Releasing model weights under an open licence does not automatically exclude the model from the AI Act if it is used in regulated ways. The exclusion is narrower than many open-source advocates assume.

Third-country government use: AI systems used by governments of non-EU countries in the course of international agreements are excluded when specific conditions are met.

The Critical Distinction

Out-of-scope exclusions are narrow. They apply to specific use-case contexts, not to organisations or sectors generally. A research lab that also has commercial activities is not wholly excluded. A developer who releases open-source model weights is not wholly excluded. A business that uses AI for both personal and professional tasks is not excluded on the basis of personal use. The exclusion must be evaluated system by system, deployment by deployment.

The Misclassification Risk

The most significant risk for organisations that believe they operate minimal-risk AI is misclassification. Four common scenarios illustrate the problem:

Scenario 1 — The internal tool: A company deploys an AI-powered HR screening tool to filter job applications. The company classifies it as minimal-risk because it is internal. Employment-domain AI systems that influence access to employment are high-risk under Annex III, paragraph 4. The fact that the system is used internally rather than sold externally does not change the classification. The fine for deploying a high-risk system without a conformity assessment can reach €15 million or 3% of global annual turnover.

Scenario 2 — The open-source component: A developer integrates an open-source model into a credit-scoring product and assumes the open-source exclusion applies. Credit assessment is high-risk under Annex III, paragraph 5(b). Once the open-source component is integrated into a high-risk application and placed on the market, the exclusion no longer applies. The provider obligations under Articles 16 to 22 apply in full.

Scenario 3 — The chatbot: A customer service chatbot is classified as minimal-risk because it is not in an Annex III domain. If the chatbot interacts directly with users without disclosing that it is AI, it triggers the Article 50(1) transparency obligation regardless of the minimal-risk classification. Minimal-risk and limited-risk can overlap: a system classified as minimal-risk for the purposes of high-risk obligations may still trigger Article 50.

Scenario 4 — The research system: A company classifies an AI system as out-of-scope on the basis of the scientific research exclusion, then uses the same system to generate reports for clients. The moment the system is used in a commercial or professional context, or its outputs are shared beyond the research group, the research exclusion no longer applies. Because the exclusion no longer covers that use, the system must be classified on its actual purpose and the corresponding obligations met — with exposure of up to €15 million or 3% of global annual turnover under Article 99(4) if it turns out to be high-risk. The €35 million / 7% tier under Article 99(3) applies only to Article 5 prohibited practices.

Penalty Exposure for Misclassification

Misclassifying a high-risk system as minimal-risk and failing to meet high-risk obligations carries fines of up to €15 million or 3% of global annual turnover. Misclassifying a prohibited system as minimal-risk — for example, a social scoring system or a real-time remote biometric identification system — carries fines of up to €35 million or 7% of global annual turnover. These are the highest fines in the AI Act. A minimal-risk classification that is not supported by a documented classification exercise offers no protection in enforcement proceedings.

How to Verify Your Classification

A six-step verification sequence provides a documented basis for minimal-risk classification:

Step 1: Identify the AI system and document its purpose, inputs, outputs, and deployment context.

Step 2: Check Article 5. Does the system engage in any prohibited practice? If yes, the system is prohibited regardless of any other classification.

Step 3: Check Article 6 and Annex III. Does the system fall into one of the eight high-risk domains? Does it serve as a safety component of an EU-regulated product? If yes, the system is high-risk.

Step 4: Check Article 50. Does the system interact directly with people, process emotions or biometric characteristics, produce synthetic media, or generate text on matters of public interest? If yes, limited-risk transparency obligations apply regardless of risk category.

Step 5: Check Article 2. Does an out-of-scope exclusion apply to the specific deployment context? If yes, document the basis for the exclusion with specificity.

Step 6: If none of the above apply, document the system as minimal-risk, implement Article 4 AI literacy, and record the classification date. Review annually or when the system’s purpose, deployment context, or capabilities change materially.

Self-Check: Minimal-Risk and Out-of-Scope Classification

For each AI system you believe is minimal-risk or out-of-scope, verify the following:

#QuestionStatus
1Have you documented the system’s purpose, inputs, outputs, and deployment context?
2Have you confirmed the system does not engage in any Article 5 prohibited practice?
3Have you confirmed the system does not fall into any Annex III high-risk domain?
4Have you checked whether Article 50 transparency obligations apply, even if the system is minimal-risk in other respects?
5If claiming an out-of-scope exclusion, have you documented the specific Article 2 basis and confirmed it applies to the exact deployment context?
6Have you implemented Article 4 AI literacy for all staff who operate this system?
7Is AI literacy training documented with records of who attended, what was covered, and when?
8Is there a process to re-evaluate the classification if the system’s purpose, capabilities, or deployment context changes?
9Has the classification been dated and signed off by a responsible person?

Any item marked incomplete is a gap. A minimal-risk or out-of-scope classification that cannot be supported by documentation offers no protection in enforcement proceedings.

Summary

Minimal-risk is the default category for AI systems that are not prohibited, high-risk, or limited-risk. It carries one substantive obligation: Article 4 AI literacy, which has been in force since 2 February 2025 and applies universally. Minimal-risk does not require conformity assessments, FRIAs, database registration, human-oversight officers, log retention, worker notifications, technical documentation under Annex IV, or CE marking. Out-of-scope exclusions under Article 2 are narrow: they apply to specific deployment contexts, not to organisations or sectors generally. The most significant risk for organisations that believe they operate minimal-risk or out-of-scope AI is misclassification: a documented six-step classification exercise and annual review is the only reliable defence. Penalties for misclassification can reach €15 million or 3% of global annual turnover for high-risk systems deployed without compliance, and €35 million or 7% for prohibited systems. Chapter 11 covers general-purpose AI models (GPAI) and the specific obligations that apply to providers of foundation models under Articles 51 to 56.

← Back to Blog Summary Chapter 11 →