🛡 HLINIX
EU AI Act Implementation Guide — Chapter 3 of 15

Chapter 3: The Five Risk Categories — Where Does Your AI Sit?

Published 26 March 2026 · 18 min read

What you will know after reading this chapter:

By the end of this chapter, you will be able to classify every AI system in your organisation into one of the five risk categories defined by the EU AI Act — and understand exactly why each system belongs where it does.

Why classification is the key to everything

In Chapter 2, you determined your role — provider, deployer, or both. Now you need to determine the risk classification of each AI system you identified. These two factors together — your role and your risk classification — determine your entire set of obligations under the EU AI Act.

This is not an abstract exercise. A deployer of a minimal-risk AI system has one obligation: AI literacy training. A deployer of a high-risk AI system has seven obligations requiring 30 to 90 hours of work. The same organisation, using two different AI tools, can face completely different compliance requirements. Classification is what tells you which set of rules applies to which system.

The five categories

The EU AI Act organises all AI systems into five risk categories. From highest to lowest:

Prohibited — Banned outright. No compliance pathway.
High-Risk — Significant obligations for both providers and deployers.
Limited-Risk — Transparency and disclosure obligations.
Minimal-Risk — AI literacy training only.
Out-of-Scope — Not covered by the AI Act.

The categories are mutually exclusive. Each AI system falls into exactly one. But a single organisation can have systems in multiple categories — which is why you need to classify each system individually.

Category 1: Prohibited AI (Article 5)

These are AI practices the EU considers fundamentally unacceptable. They are banned entirely, with no exceptions (unless explicitly stated in the law). Operating a prohibited AI system carries the highest fine under the AI Act: up to €35 million or 7% of global annual turnover.

The prohibited practices are:

Social scoring

AI systems that evaluate or classify people over a period of time based on their social behaviour or known, inferred or predicted personal or personality characteristics, where the resulting social score leads to detrimental treatment in a context unrelated to the one the data came from, or to detrimental treatment that is unjustified or disproportionate. Article 5(1)(c) applies to public and private actors alike — there is no public-authority limitation. For example, a government system that assigns citizens a “trustworthiness score” based on their online activity and uses it to restrict access to public services; or a private platform that scores users on off-platform social behaviour and uses that score to deny them unrelated services.

Exploitation of vulnerabilities

AI systems that deliberately exploit the vulnerabilities of specific groups — due to age, disability, or social or economic situation — to materially distort their behaviour in a way likely to cause significant harm. For example, an AI-powered marketing system that targets elderly people with misleading financial product advertisements, designed to exploit cognitive decline.

Real-time remote biometric identification in public spaces

Using AI to identify individuals in real-time through facial recognition or other biometric data in publicly accessible spaces for law enforcement purposes. There are narrow exceptions: searching for specific victims of crime (including missing children), preventing a genuine and imminent threat to life or a terrorist attack, and locating or identifying a person suspected of an offence listed in Annex II that is punishable in the Member State concerned by a custodial sentence or detention order of at least four years. Each use requires prior authorisation from a judicial authority or an independent administrative authority whose decision is binding — except in duly justified cases of urgency, where authorisation must be requested without undue delay and at the latest within 24 hours.

Emotion recognition in workplaces and educational institutions

AI systems that infer emotions of individuals in the workplace or in educational settings, except where the system is intended for medical or safety reasons. For example, an AI system that monitors employees’ facial expressions during meetings to assess their engagement levels is prohibited. An AI system that detects driver drowsiness for safety purposes is not.

Biometric categorisation based on sensitive attributes

AI systems that categorise individuals based on biometric data to infer sensitive characteristics such as race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation. An exception exists for law enforcement filtering of biometric datasets acquired lawfully.

Untargeted scraping for facial recognition databases

AI systems that create or expand facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

Predictive policing based solely on profiling

AI systems that make risk assessments of individuals to predict the likelihood of committing a criminal offence, based solely on profiling or personality traits. This does not apply to AI systems that support human assessment based on objective, verifiable facts directly linked to criminal activity.

Subliminal manipulation

AI systems that deploy subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques, to materially distort behaviour in a way likely to cause significant harm.

If any AI system in your organisation matches these descriptions, it must be discontinued immediately. There is no transition period — the prohibition has been in force since 2 February 2025.

Category 2: High-Risk AI (Annex III and Article 6)

High-risk classification is where most compliance complexity lies. There are two pathways into this category:

Pathway 1: Annex III listed areas

The AI Act provides a specific list of domains where AI systems are automatically classified as high-risk. These are areas where AI errors, bias, or failures can cause serious harm to individuals’ health, safety, or fundamental rights.

(1) Biometrics — AI systems intended for remote biometric identification — excluding systems used for biometric verification whose sole purpose is to confirm that a person is who they claim to be — biometric categorisation according to sensitive or protected attributes, and emotion recognition. (Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is prohibited under Article 5(1)(h) rather than high-risk; outside law enforcement it falls here.)

(2) Critical infrastructure — AI systems used as safety components in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity.

(3) Education and vocational training — AI systems that determine access to or admission to educational or vocational training institutions, evaluate learning outcomes, assess the appropriate level of education for an individual, or monitor and detect prohibited behaviour during tests.

(4) Employment, workers management, and access to self-employment — AI systems used for recruitment and selection (screening or filtering applications, evaluating candidates), making decisions affecting terms of work (promotion, termination, task allocation, performance monitoring), or evaluating work-based contractual relationships.

(5) Access to essential private services and public services and benefits — This includes four distinct sub-categories. Point 5(a) covers AI systems used by or on behalf of public authorities to evaluate the eligibility of individuals for essential public assistance benefits and services, including healthcare services, or to grant, reduce, revoke, or reclaim such benefits and services. Point 5(b) covers AI systems used to evaluate the creditworthiness of individuals or establish their credit score, with the exception of AI systems used for detecting financial fraud. Point 5(c) covers AI systems used for risk assessment and pricing in relation to individuals in the case of life and health insurance. Point 5(d) covers AI systems used to evaluate and classify emergency calls, dispatch or prioritise emergency first response services (police, firefighters, medical aid), and emergency healthcare patient triage systems.

(6) Law enforcement — five items: AI systems used to assess the risk of individuals becoming victims of criminal offences; as polygraphs or similar tools; to evaluate the reliability of evidence during investigation or prosecution; to assess the risk of a person offending or re-offending not solely on the basis of profiling, or to assess personality traits, characteristics or past criminal behaviour; and to profile individuals in the course of detection, investigation or prosecution.

(7) Migration, asylum, and border control management — AI systems used as polygraphs or similar tools, to assess risks posed by individuals entering the territory, to assist in the examination of asylum or visa applications, and for detecting, recognising, or identifying individuals (excluding document verification).

(8) Administration of justice and democratic processes — AI systems used to assist judicial authorities in researching and interpreting facts and the law, and in applying the law to facts, and AI systems intended to influence the outcome of elections or referendums (excluding systems not directly interacting with individuals, such as tools used to organise or count ballots).

Pathway 2: Safety components under EU product legislation

Article 6(1) provides a second pathway. If an AI system is a safety component of a product that is already regulated under certain EU product safety laws (such as the Medical Devices Regulation, the Machinery Regulation, or the Toys Safety Directive), and that product is required to undergo a third-party conformity assessment, then the AI system is also classified as high-risk. This is relevant primarily for AI in medical devices, industrial machinery, vehicles, and similar regulated products.

The exception clause (Article 6(3))

An AI system listed in Annex III is not automatically high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights. Specifically, an Annex III system may be excluded from high-risk classification if it is intended to perform a narrow procedural task (such as an AI system that only sorts incoming documents by file type before a human reviews them), is intended to improve the result of a previously completed human activity, detects decision-making patterns without replacing or influencing human assessment, or performs a preparatory task for an assessment relevant to the use cases listed in Annex III.

However, this exception does not apply if the AI system performs profiling of natural persons. If you believe your system qualifies for this exception, document your reasoning carefully — the burden of proof is on you.

Category 3: Limited-Risk AI (Article 50)

Limited-risk AI systems are those that interact with people or generate content in ways where transparency is essential. The obligations here are not about how the system is built or operated — they are about making sure people know they are dealing with AI.

AI systems that interact with people

If your AI system is designed to interact directly with individuals — a chatbot, a virtual assistant, a voice agent — you must ensure that people are informed they are interacting with an AI system. The disclosure must be clear and timely, made at the latest at the time of first interaction.

Emotion recognition and biometric categorisation systems

If your system performs emotion recognition or biometric categorisation (and is not prohibited under Article 5, and is not classified as high-risk under Annex III), you must inform the individuals being subjected to it, and process personal data in accordance with GDPR and the Law Enforcement Directive.

AI-generated content (deepfakes and synthetic media)

If your AI system generates or manipulates image, audio, or video content that appreciably resembles existing persons, objects, places, or events, and could falsely appear to be authentic (commonly known as deepfakes), you must disclose that the content has been artificially generated or manipulated. This includes labelling the content in a machine-readable format using technical standards where feasible. There are exceptions for content that is obviously artistic, creative, satirical, or fictional, and for content authorised by law for law enforcement purposes.

AI-generated text published to inform the public

If your AI system generates text that is published for the purpose of informing the public on matters of public interest, you must disclose that the text was AI-generated. This does not apply if the content has been subject to human review and editorial control, and a natural or legal person holds editorial responsibility for the publication.

Category 4: Minimal-Risk AI

This is the default category. If your AI system does not fall into any of the categories above — it is not prohibited, not high-risk, not subject to transparency obligations — it is minimal-risk. The vast majority of AI systems currently in use fall here.

The only binding obligation is Article 4: AI literacy training. Every organisation that provides or uses AI systems must ensure that their staff and personnel have a sufficient level of AI literacy. This is a universal obligation that applies regardless of risk classification, but for minimal-risk systems, it is the only obligation.

Examples of minimal-risk AI systems include spam filters, AI-powered search engines, recommendation algorithms (for products, content, or music), predictive text and autocomplete features, inventory management optimisation, internal analytics dashboards with AI components, and AI-powered translation tools used internally.

Do not mistake “minimal-risk” for “no-risk.” These systems may still be subject to GDPR, product liability laws, consumer protection rules, or sector-specific regulations. Minimal-risk under the AI Act means the AI Act itself imposes only the literacy obligation — but other laws still apply.

Category 5: Out-of-Scope AI (Article 2)

Some AI systems are explicitly excluded from the AI Act entirely. If your system falls into one of these categories, the regulation does not apply:

Military and defence (Article 2(3))

AI systems developed or used exclusively for military purposes. If the system has dual use (military and civilian), the civilian use remains in scope.

Scientific research (Article 2(6))

AI systems used solely for scientific research and development purposes that are not placed on the market or put into service. The moment you deploy a research system in a commercial or operational context, it comes into scope.

Personal use (Article 2(10))

AI systems used by individuals in the course of a purely personal, non-professional activity. If you use AI for a hobby or personal project, you are excluded. If you use the same AI in a business context, you are in scope.

Open-source AI (Article 2(12))

AI systems released under free and open-source licences are excluded from most obligations — but there are important exceptions. If the open-source AI system is classified as high-risk under Annex III, falls under a prohibited practice (Article 5), or is subject to transparency obligations (Article 50), the relevant obligations still apply. Additionally, if the open-source system is placed on the EU market as part of a commercial product, the exclusion does not apply.

Third-country government use (Article 2(4))

AI systems from countries outside the EU that are used under international agreements for law enforcement and judicial cooperation — provided there are adequate data protection safeguards.

If you believe your system is out of scope, verify carefully. The consequences of mis-classification are severe. If a system you classified as out-of-scope turns out to be prohibited, you face fines of up to €35 million or 7% of turnover. Even for high-risk mis-classification, fines reach €15 million or 3%.

The classification flowchart

Use this decision tree to classify each AI system in your organisation:

Step 1: Is the AI system used for any of the practices listed in Article 5?

  Yes → Prohibited. Stop using it immediately.

  No → Continue to Step 2.

Step 2: Is the AI system used in any of the domains listed in Annex III?

  Yes → Continue to Step 2a.

  No → Continue to Step 3.

Step 2a: Does the Article 6(3) exception apply? (Narrow procedural task, no profiling, no significant risk of harm)

  Yes → Continue to Step 3.

  No → High-Risk.

Step 3: Is the AI system a safety component of a product regulated under EU product safety legislation that requires third-party conformity assessment?

  Yes → High-Risk.

  No → Continue to Step 4.

Step 4: Does the AI system interact directly with individuals, generate synthetic content, perform emotion recognition, or perform biometric categorisation?

  Yes → Limited-Risk (Article 50 transparency obligations apply).

  No → Continue to Step 5.

Step 5: Is the AI system excluded under Article 2 (military, research-only, personal use, qualifying open-source, or third-country government)?

  Yes → Out-of-Scope.

  No → Minimal-Risk (Article 4 AI literacy obligation applies).

Common classification mistakes

Mistake 1: “We only use the AI internally, so it must be minimal-risk.”

Internal use does not determine risk classification. If you use an AI system internally to screen job applicants, it is high-risk under Annex III point 4, regardless of whether it is internal or customer-facing.

Mistake 2: “The AI just assists humans — it does not make decisions.”

Many Annex III categories cover AI systems that assist or support human decisions, not only those that make autonomous decisions. An AI system that ranks job candidates for a human recruiter to review is still high-risk.

Mistake 3: “Our AI provider told us the system is minimal-risk.”

The provider’s classification is based on the system’s intended purpose. If you use the system for a different purpose — for example, using a general analytics tool for credit assessment — the classification may change based on your actual use. Deployers are responsible for verifying that their use matches the provider’s intended purpose.

Mistake 4: “It is open-source, so it is out of scope.”

The open-source exclusion under Article 2(12) does not apply if the system is high-risk, prohibited, or subject to Article 50 transparency obligations. An open-source recruitment screening model deployed in the EU is still high-risk.

Mistake 5: “Emotion recognition is always prohibited.”

Emotion recognition is prohibited in workplaces and educational institutions (Article 5). In other contexts, it may be classified as high-risk under Annex III point 1(c), which lists AI systems intended to be used for emotion recognition, or limited-risk under Article 50(3). The classification depends on the specific use case.

Self-Check: Classify Your AI Systems

Take the list you created in Chapter 2 and add the risk classification for each system:

AI System 1: ____________________
  My role: Provider / Deployer / Both
  Risk classification: Prohibited / High-Risk / Limited-Risk / Minimal-Risk / Out-of-Scope

AI System 2: ____________________
  My role: Provider / Deployer / Both
  Risk classification: Prohibited / High-Risk / Limited-Risk / Minimal-Risk / Out-of-Scope

AI System 3: ____________________
  My role: Provider / Deployer / Both
  Risk classification: Prohibited / High-Risk / Limited-Risk / Minimal-Risk / Out-of-Scope

If you are unsure about any classification, run the system through the flowchart above. If it still is not clear, err on the side of the higher risk category and seek professional advice.

Your reading route

You now have your role and your risk classification for each AI system. Together, these two factors determine exactly which chapters of this guide you need to focus on:

Your situationRead next
Any system classified as ProhibitedChapter 4 (immediately)
High-Risk system, you are a DeployerChapters 5, 6, 8
High-Risk system, you are a ProviderChapters 5, 7, 8
Limited-Risk systemChapter 9
Minimal-Risk systemChapter 11
Out-of-Scope systemChapter 10
EveryoneChapters 11, 12, 13, 14, 15

Summary

The EU AI Act classifies all AI systems into five mutually exclusive risk categories: prohibited, high-risk, limited-risk, minimal-risk, and out-of-scope. Prohibited AI practices are banned outright and carry fines of up to €35 million or 7% of turnover. High-risk classification is triggered either by being listed in one of the Annex III domains or by being a safety component of a product regulated under EU product safety legislation. Limited-risk systems have transparency and disclosure obligations. Minimal-risk systems require only AI literacy training. Out-of-scope systems are excluded from the AI Act but may still be subject to GDPR and other laws. Your obligations under the AI Act are determined by the combination of your role (Chapter 2) and your risk classification (this chapter). The following chapters address each category in detail, starting with prohibited AI in Chapter 4.

← Back to Blog Summary

Check your AI system now

Use our free compliance checker to find out your risk classification in 2 minutes.

Check Your AI Risk Level — Free