EU AI Act risk classification
Four tiers, two routes into the highest one, and two different dates. The single most useful thing to understand is that the tiers are not mutually exclusive: most compliance plans with a hole in them have one because they treated classification as a single choice.
The four tiers
| Tier | Reached how | Core obligation | Max fine | Applies |
|---|---|---|---|---|
| Unacceptable | Art. 5: ten prohibited practices | Complete prohibition | €35M / 7% Art. 99(3) | 2 Feb 2025 two new: 2 Dec 2026 |
| High | Art. 6(1) + Annex I (product), or Art. 6(2) + Annex III (use case) | Chapter III Section 2: Arts. 9–15, 17, 43–49, 72–73 | €15M / 3% Art. 99(4) | 2 Dec 2027 Annex I: 2 Aug 2028 |
| Transparency | Art. 50: what the system does, at any tier | Disclosure and marking | €15M / 3% Art. 99(4) | 2 Aug 2026 |
| Minimal | Everything else | Art. 4 AI literacy only | — | 2 Feb 2025 |
Tiers stack. They do not exclude.
A high-risk credit scoring system with a customer-facing chatbot owes Chapter III (from 2027) and Article 50 (now) and Article 4 (since February 2025). Reading the table as single-choice produces a plan that is late on the obligation already in force.
General-purpose AI models are not in this table. Chapter V applies to model providers on its own terms, has applied since 2 August 2025, and was not changed in substance by the Digital Omnibus. GPAI →
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Two routes into high-risk, two dates
Art. 6(1) — product route
The AI is a safety component of, or is itself, a product covered by the Annex I harmonisation legislation — medical devices, machinery, toys, vehicles, where that product requires third-party conformity assessment.
2 August 2028.
Art. 6(2) — use-case route
The AI’s intended purpose falls within one of the eight areas in Annex III, subject to the Article 6(3) derogation.
2 December 2027.
Any summary giving a single high-risk date has collapsed these two. A MedTech portfolio commonly holds both. Both routes in detail →
The derogation, and the override that usually ends it
Article 6(3) lets a provider rebut the Annex III presumption where the system does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making, and meets one of four conditions: a narrow procedural task; improving the result of a previously completed human activity; detecting decision-making patterns without replacing or influencing a prior human assessment without proper review; or a preparatory task.
Profiling removes it outright
Notwithstanding all four conditions, an Annex III system is always high-risk where it performs profiling of natural persons. Any system that evaluates personal aspects of identified individuals is profiling under GDPR Article 4(4) — which is most recruitment, credit and insurance AI. The derogation in full →
Whatever you conclude, Article 6(4) requires the assessment documented before market placement, you still register under Article 49, and Article 80 lets an authority challenge it.
Status labels on this page
Verified fact: The four tiers, the two Article 6 routes and their dates, the Art. 6(3) conditions and profiling override, and the Art. 99 penalty tiers.
Expert analysis: The 'tiers stack' framing and the assessment of where the derogation typically fails.
Unsettled: The Commission's Annex III guidelines remain in draft and may narrow several domain scopes.
Classify per system, not per company
The classifier walks the sequence in the order the Regulation applies it and returns every tier that attaches, not just the highest one.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What are the risk levels in the EU AI Act?
Four. Unacceptable risk, covered by the Article 5 prohibitions. High risk, reached either through Article 6(1) and Annex I as a product safety component, or through Article 6(2) and Annex III as a listed use case. Limited or transparency risk, covered by the Article 50 disclosure duties. Minimal risk, which carries no mandatory requirement under the Act other than Article 4 AI literacy, which applies at every tier. General-purpose AI models sit outside this structure in Chapter V.
Are the EU AI Act risk tiers mutually exclusive?
No, and treating them as a single-choice classification is the most common structural error. A high-risk recruitment system that also interacts with candidates owes both the Chapter III obligations and the Article 50 transparency duties. Article 50 attaches to what a system does, not to its risk tier, so a minimal-risk chatbot is caught by it.
How do you determine the risk level of an AI system?
In sequence. Confirm it is an AI system under Article 3(1). Confirm there is an EU nexus under Article 2. Check Article 5 first, because a prohibited practice is prohibited regardless of anything else. Then check the Annex I product route and the Annex III use-case route, applying the Article 6(3) derogation and its absolute profiling override. Then check Article 50 independently. Classification turns on the intended purpose of the specific system.