Understanding Risk Levels

Prohibited, high, limited, minimal — and what each means for you.

Every obligation in the EU AI Act flows from one question: which risk level does your system fall into?

Prohibited (Art. 5)

Banned outright since February 2, 2025. Includes social scoring by public authorities, exploitative manipulation, emotion recognition in workplaces and schools, untargeted facial-image scraping, and most real-time remote biometric identification in public spaces.

High-risk (Art. 6 + Annex III)

Allowed, but heavily regulated. Two routes in:

  1. The AI is a safety component of a product already regulated by EU law (Annex I — machinery, medical devices, etc.).
  2. The use case appears in Annex III — see Complete List of High-Risk AI. Employment screening, credit scoring, and education assessment are the categories that catch most software companies by surprise.

High-risk means: risk management system, data governance, Annex IV documentation, logging, human oversight, conformity assessment, EU database registration, and post-market monitoring.

Limited risk (Art. 50)

Systems that interact with people or generate content. Main obligation: transparency — users must know they're talking to an AI, and AI-generated content must be disclosed. Chatbots and generative features live here.

Minimal risk

Everything else — spam filters, recommendation engines for non-sensitive content, game AI. No new obligations, though voluntary codes of conduct are encouraged.

Guardia AI's risk classification walks you through this decision tree question by question.

Didn't find what you need?

Guardia AI provides compliance tooling, not legal advice. For official regulatory text, see EU Regulation 2024/1689.