Latest Trending Discover Timelines Categories
All explainers

Technology explainer

How Does the EU AI Act Classify Artificial Intelligence by Risk?

A practical guide to the EU AI Act’s risk-based structure, including prohibited practices, high-risk applications, transparency duties, general-purpose models and the limits of deciding an AI system’s category.

The European Union’s AI Act does not regulate every artificial intelligence system in the same way. It starts by asking what harm a system could cause, then assigns obligations according to the role of the company and the level of risk.

What is a risk-based approach?

A risk-based law focuses less on whether software uses a fashionable technical method and more on what it does, where it is used and whom it can affect. A spam filter and an automated recruitment system may both use machine learning, but the second can shape access to work and therefore faces much closer scrutiny.

The official European Commission overview of the AI Act describes four main levels: unacceptable risk, high risk, limited risk and minimal or no risk. General-purpose AI models also receive a separate set of duties because one model can support many downstream systems.

What counts as unacceptable risk?

Unacceptable-risk practices are banned rather than permitted with extra paperwork. Examples include certain manipulative uses, some forms of social scoring and narrowly defined biometric or emotion-related practices. The exact legal conditions matter because several prohibitions include exceptions, especially for law enforcement.

A ban applies to the prohibited practice, not automatically to every technology that could be used for it. Facial recognition, for example, is not treated as one undivided category across every setting.

When is an AI system considered high risk?

High-risk classification generally covers AI used as a safety component in certain regulated products, or in sensitive areas listed by the law. These include specified uses involving biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and the administration of justice.

Providers may need risk management, suitable data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity controls. Organisations that deploy the system also carry duties, which may include monitoring its operation and following the provider’s instructions.

Classification depends on the intended purpose and context. An AI model used to format a job description is not automatically equivalent to a system that ranks candidates and materially influences who receives an interview.

What does limited risk mean?

Some systems are allowed but must be transparent. People may need to be told when they are interacting with AI, while synthetic audio, images, video or text may require machine-readable marking or visible disclosure. Deepfakes and certain public-interest content receive particular attention.

Transparency does not certify that content is accurate. It provides information about how the content or interaction was produced, helping users and platforms make a more informed assessment.

How are general-purpose AI models treated?

A general-purpose model can perform many tasks and may be integrated into numerous products. Its provider therefore has obligations involving documentation, copyright compliance and information for downstream developers. Models capable of creating systemic risk face additional evaluation, reporting, security and risk-mitigation duties.

The model and the final application can sit in different legal categories. A broadly capable model may power a low-risk writing assistant and, through a separate deployment, contribute to a high-risk decision system.

What are the limits of the classification?

Risk categories do not eliminate interpretation. Intended purpose can change, software can be adapted after release and a chain of suppliers may share responsibility. Some important standards and detailed enforcement practices are also still developing.

The useful question is not simply, “Is this AI?” It is: what decision or content does the system produce, who may be harmed, how much control does a person retain and which organisation is responsible at each stage?

First appeared in

Europe Starts Enforcing Its AI Act, but Major High-Risk Rules Are Still Delayed

A new version of NewTqnia is ready.