Latest Trending Discover Timelines Categories
←All explainers

Technology explainer

How Does the EU AI Act Classify Artificial Intelligence by Risk?

The EU AI Act applies several filters: prohibited practices, two routes to high-risk status, transparency duties, and a separate regime for general-purpose AI models. Classification depends on intended use, deployment context, legal role, and current transition dates, while other EU laws still govern systems outside the high-risk category.

The EU AI Act classifies artificial intelligence mainly by what a system does, where it is used, and the harm it can create, not simply by how advanced the underlying model is. It bans a narrow set of practices, imposes extensive controls on defined high-risk systems, requires transparency for certain human-facing or synthetic-content uses, creates a separate regime for general-purpose AI models, and leaves most low-risk applications without additional AI Act duties.

The 30-second summary

  • Unacceptable risk: specified practices are prohibited rather than approved with safeguards.
  • High risk: safety components of regulated products and listed sensitive uses face lifecycle obligations.
  • Transparency risk: some chatbots, emotion or biometric systems, deepfakes, and generated public-interest content require notice or technical marking.
  • General-purpose models: model providers have documentation, copyright, information-sharing, and sometimes systemic-risk duties.
  • Minimal risk: most AI-enabled software remains outside special AI Act controls, though other EU laws still apply.

The Act regulates roles and use cases

The same model can sit in different legal positions. A provider develops or places a system on the market. A deployer uses it under its authority. Importers, distributors, product manufacturers, and authorized representatives may have separate duties. A company outside the EU can still be covered when it supplies the European market or when an output produced abroad is used in the Union under the Act's territorial rules.

Classification begins with the intended purpose, reasonably foreseeable misuse, context, affected people, and the actor's role. Calling a product “assistive,” “experimental,” or “a copilot” does not settle its category if it performs a regulated function.

A practical map of the risk structure

Regulatory layer Typical examples Main consequence
Prohibited practice Specific manipulative, exploitative, social-scoring, biometric, or predictive-policing uses meeting Article 5 conditions Use is banned, subject to precisely defined exceptions.
High-risk system Safety components in certain regulated products, or listed uses in biometrics, infrastructure, education, employment, essential services, law enforcement, migration, and justice Risk management, data governance, documentation, logs, human oversight, performance, cybersecurity, conformity, monitoring, and incident duties.
Transparency duty Direct AI interaction, synthetic media, emotion recognition, biometric categorization, and specified generated text Machine-readable marking or human-facing disclosure, depending on the actor and use.
General-purpose AI model A broadly capable model that can support many downstream systems Model documentation, downstream information, copyright policy, training-content summary, and extra systemic-risk controls for qualifying models.
Minimal or no added risk Many games, recommendation aids, spam filters, and ordinary software functions No special AI Act risk obligations, while privacy, consumer, safety, labor, and other laws remain applicable.

This is not a single ladder where every product occupies exactly one box. A general-purpose model can power a high-risk downstream system. A high-risk system may also carry transparency duties. A prohibited use remains prohibited even if the technology is accurate.

What counts as a prohibited practice?

Article 5 targets particular uses judged incompatible with fundamental rights and Union values. The legal tests contain conditions and exceptions, so shorthand lists can mislead. Broadly, the prohibited areas include:

  • harmful manipulation or deception that materially distorts behavior;
  • exploitation of vulnerability related to age, disability, or specific social or economic circumstances when significant harm is caused or likely;
  • certain public or private social scoring that leads to unjustified or disproportionate treatment;
  • individual criminal-risk assessment based solely on profiling or personality traits, outside permitted support for human assessment based on objective facts;
  • untargeted scraping of facial images to build or expand recognition databases;
  • emotion inference in workplaces and schools, except specified medical or safety uses;
  • biometric categorization that infers especially sensitive attributes;
  • real-time remote biometric identification by law enforcement in public spaces, except narrowly framed cases with safeguards.

The word “prohibited” does not mean every technology in the surrounding category is banned. Facial recognition, emotion analysis, or scoring can fall into different treatments depending on purpose, setting, data, actor, and exception.

Two routes into the high-risk category

Route 1: AI inside a regulated product

An AI system is high-risk under the product route when it is a safety component, or itself a covered product, under specified EU product legislation and the product requires third-party conformity assessment. Examples can involve certain medical devices, machinery, vehicles, lifts, toys, aviation, or protective equipment. Not every piece of AI inside such a product qualifies; the safety function and conformity conditions matter.

Route 2: a sensitive use listed in Annex III

The second route covers specified applications in areas where decisions can strongly affect rights or access:

  • biometric identification, categorization, or emotion recognition in defined cases;
  • management of safety-critical infrastructure;
  • education admission, assessment, placement, or monitoring;
  • recruitment, worker selection, task allocation, evaluation, and termination;
  • eligibility for essential public and private services, including certain credit and insurance uses;
  • law-enforcement assessment and evidence-related functions;
  • migration, asylum, border, visa, and security-risk decisions;
  • administration of justice and influence on democratic processes.

Annex III includes a limiting mechanism: a listed system may avoid high-risk classification when it does not pose a significant risk to health, safety, or fundamental rights and performs a narrow procedural or preparatory task. Profiling of natural persons in an Annex III context remains high-risk. The provider must document its assessment, and authorities can challenge it.

What high-risk compliance requires

  1. Risk management: identify, evaluate, mitigate, test, and revisit foreseeable risks throughout the lifecycle.
  2. Data governance: ensure training, validation, and test data meet relevant quality and representativeness requirements.
  3. Technical documentation: explain the system, intended purpose, design, testing, limitations, and compliance.
  4. Automatic logging: retain records that support traceability and investigation.
  5. Instructions and transparency: give deployers the information needed to operate and interpret the system properly.
  6. Human oversight: enable competent people to understand limits, detect automation bias, intervene, or stop operation.
  7. Accuracy, robustness, and cybersecurity: maintain appropriate performance and resistance to errors, manipulation, and attack.
  8. Conformity and registration: complete the applicable assessment, declarations, marking, and database obligations before market entry.
  9. Post-market monitoring: collect performance information and report serious incidents after deployment.

These are lifecycle duties, not a one-time fairness test. A compliant launch does not end monitoring when data, users, environment, or failure modes change.

Transparency duties are not the same as high-risk status

Article 50 addresses situations where people need to understand AI involvement. A provider of an interactive system generally must design it so a person is informed that they are interacting with AI unless this is obvious. Providers of generative systems must support machine-readable identification of synthetic or manipulated outputs, subject to technical feasibility and specified exceptions.

Deployers have different obligations. They may need to disclose emotion-recognition or biometric-categorization use, label a deepfake or other deepfake content, and identify certain AI-generated public-interest text. Editorial review and responsibility can affect some text-disclosure requirements.

A visible notice and hidden provenance signal solve different problems. Neither guarantees truth. Authentic material can deceive through context, while synthetic material can be clearly labeled and factually accurate. Cropping, screenshots, or re-encoding can also damage technical marks.

Where general-purpose AI fits

A general-purpose AI model (GPAI) is trained at scale, displays significant generality, and can perform a wide range of distinct tasks or support many downstream systems. The model is not automatically “high-risk” in the same sense as an employment-screening system. It has its own provider obligations because downstream developers need information to build compliant applications.

GPAI providers generally face technical-documentation, downstream-information, copyright-policy, and training-content-summary obligations. An open-source release can receive limited exemptions from some duties when conditions are met, but openness does not remove systemic-risk obligations.

What is a GPAI model with systemic risk?

A GPAI model may be classified as presenting systemic risk when it has high-impact capabilities evaluated through appropriate technical tools, including a rebuttable presumption linked in the Act to training compute above (10^{25}) floating-point operations, or when the Commission designates it based on capability criteria.

Its provider must go further: conduct standardized evaluations and adversarial testing, assess and mitigate systemic risks, track and report serious incidents, and maintain adequate cybersecurity. The threshold is a trigger for scrutiny, not proof that compute alone measures every risk.

Who is responsible in a supply chain?

A foundation-model provider supplies capabilities and documentation. A downstream provider may fine-tune, wrap, or integrate the model into a particular system. A deployer selects how it is used with people. Responsibility can shift when an actor places a system under its own name, makes a substantial modification, or changes its intended purpose into a high-risk one.

Contracts help allocate operational tasks but cannot erase statutory duties. Organizations need a map connecting model version, system purpose, data, users, decisions, deployment region, and responsible legal role.

How classification should be performed

  1. Confirm that the software is an AI system under the Act.
  2. Identify every intended use and affected person.
  3. Check Article 5 prohibitions before anything else.
  4. Test the product-safety route under Article 6(1) and Annex I.
  5. Test the sensitive-use route under Article 6(2) and Annex III.
  6. Document any Annex III exception analysis and whether profiling occurs.
  7. Assess Article 50 transparency duties separately.
  8. Determine whether a GPAI model is supplied or integrated and map supply-chain duties.
  9. Check territorial scope, transition dates, and other applicable EU or national law.
  10. Repeat the assessment after a substantial modification or purpose change.

The implementation timetable matters

The Act entered into force on 1 August 2024 and applies in phases. Prohibitions and AI-literacy duties began applying in February 2025. GPAI rules began applying in August 2025, with enforcement and transparency milestones in August 2026. The European Commission's current implementation page states that many Annex III high-risk rules apply from 2 December 2027 and high-risk AI embedded in specified regulated products from 2 August 2028 following the agreed simplification timetable.

NewTqnia's report on the 2026 enforcement milestone explains the practical shift. Dates and implementing details can change through legislation, standards, and official guidance, so organizations should verify the current official text rather than rely on an old compliance slide.

Reality check

  • The Act classifies use cases, roles, and risks, not industries or model brands in isolation.
  • “Not high-risk” does not mean unregulated; GDPR, consumer, product-safety, labor, copyright, and sector rules may still apply.
  • A high-risk label does not mean the use is prohibited. It means strict requirements must be satisfied.
  • Transparency labels disclose AI involvement, not accuracy, impartiality, or legality.
  • A provider's self-classification can be reviewed by market-surveillance authorities.
  • This explainer is an educational map, not legal advice for a specific product.

The mental model

Think of the AI Act as several filters rather than one risk score. First ask whether the practice is banned. Then ask whether the system enters a high-risk route through a regulated product or sensitive use. Separately check transparency. Then map any general-purpose model and supply-chain role. The answer depends on purpose and deployment, which is why the same underlying model can support a low-risk writing tool, a transparent chatbot, or a tightly regulated employment or medical system.

First appeared in

Europe Starts Enforcing Its AI Act, but Major High-Risk Rules Are Still Delayed

A new version of NewTqnia is ready.