# EU AI Act Risk Tiers

The EU AI Act Risk Tiers classify AI systems into four risk levels - unacceptable, high, limited, and minimal - plus a general-purpose AI category, imposing regulatory duties that scale with potential harm. The regulation entered into force on 1 August 2024.

The EU AI Act Risk Tiers are the risk-based classification framework established by the European Union's Artificial Intelligence Act (AI Act), a regulation that entered into force on 1 August 2024. The Act creates a common regulatory and legal framework for [artificial intelligence](https://www.wikiprompt.org/wiki/artificial-intelligence) across the EU, covering most AI systems in a wide range of sectors. It categorizes non-exempt AI applications into four levels - unacceptable, high, limited, and minimal risk - with an additional category for general-purpose AI. The risk tiers determine the obligations imposed on AI providers and deployers, following a product-safety model where duties become more demanding as the potential impact on health, safety, or fundamental rights increases.

The AI Act was proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024, and was unanimously approved by the EU Council on 21 May 2024. The draft was revised to address the rise of [generative AI](https://www.wikiprompt.org/wiki/generative-ai) systems, such as [large language models](https://www.wikiprompt.org/wiki/large-language-model), whose general-purpose capabilities did not fit the main framework. The regulation does not create individual rights but places duties on AI providers and professional users, and it can apply extraterritorially to providers outside the EU if they have users within the EU.

## Unacceptable Risk

Applications with unacceptable risk are banned outright, with specific exemptions. When no exemption applies, this category includes AI systems that manipulate human behaviour, those that use real-time remote biometric identification (such as facial recognition) in public spaces, and those used for social scoring - ranking individuals based on personal characteristics, socio-economic status, or behaviour. The ban is absolute, meaning that no conformity assessment or mitigation measure can allow such systems to be placed on the EU market.

## High Risk

High-risk AI applications are those expected to pose significant threats to health, safety, or fundamental rights of persons. Notably, AI systems used in health, education, recruitment, critical infrastructure management, law enforcement, or justice fall into this category. They must comply with security, transparency, and quality obligations, and undergo conformity assessments before deployment. In some cases, a Fundamental Rights Impact Assessment (FRIA) is required - an ex ante review to identify and mitigate potential impacts on fundamental rights. High-risk systems must be evaluated both before they are placed on the market and throughout their life cycle. The list of high-risk applications can be expanded over time without modifying the AI Act itself. Citizens have the right to submit complaints about AI systems and to receive explanations of decisions made by high-risk AI that affect their rights.

## Limited Risk

Limited-risk AI systems have transparency obligations, ensuring users are informed that they are interacting with an AI system and allowing them to make informed choices. This category includes applications that generate or manipulate images, sound, or videos - such as [deep learning](https://www.wikiprompt.org/wiki/deep-learning)-based deepfakes. The transparency duty is lighter than for high-risk systems, but it still requires clear disclosure to users.

## Minimal Risk

Minimal-risk AI systems are not regulated by the AI Act. This category includes, for example, AI used in video games or spam filters. Most AI applications are expected to fall into this category. Due to maximum harmonisation rules, EU member states cannot impose additional regulations on these systems, and existing national laws regarding their design or use are overridden. However, a voluntary code of conduct is suggested for providers.

## General-Purpose AI

Added in 2023, the general-purpose AI category includes foundation models that can perform a wide range of tasks, such as [OpenAI](https://www.wikiprompt.org/wiki/openai)'s ChatGPT or models from [Anthropic](https://www.wikiprompt.org/wiki/anthropic) and [Google DeepMind](https://www.wikiprompt.org/wiki/google-deepmind). If a model's weights and design are made open source, developers must publish a training data summary and a copyright policy; closed-source models must meet broader transparency requirements. High-impact models that pose systemic risks - requiring more than 10^25 floating-point operations to train - must undergo extra evaluation, including model evaluations, adversarial testing, risk mitigation for bias and security failures, serious incident reporting, and adequate cybersecurity. A General-Purpose AI Code of Practice, published on 10 July 2025, outlines three main chapters on transparency, copyright, and safety and security to help providers demonstrate compliance. Participation in the code is voluntary.

## Exemptions

Articles 2.3 and 2.6 of the AI Act exempt AI systems used exclusively for military, defence, or national security purposes, as well as those for pure scientific research and development. The regulation also does not apply to AI used for non-professional purposes. These exemptions are narrow and do not cover dual-use systems that have civilian applications.

## Implementation and Enforcement

The AI Act's provisions come into operation gradually over 6 to 36 months after entry into force. The Act creates a European Artificial Intelligence Board to promote national cooperation and ensure compliance. Like the EU's General Data Protection Regulation, the AI Act can apply extraterritorially to providers from outside the EU if they have users within the EU. The risk-based scheme is designed to focus oversight on systems likely to create significant risks while allowing lighter approaches for less sensitive uses. According to an initial appraisal by the European Parliamentary Research Service, the Commission's impact assessment drew on stakeholder consultations and a wide range of existing research when comparing policy options for this framework.

---
Source: https://www.wikiprompt.org/wiki/eu-ai-act-risk-tiers
License: CC BY-SA 4.0 (https://creativecommons.org/licenses/by-sa/4.0/)
Last updated: 2026-09-12T22:19:32.67638+00:00
