The AI Act classifies AI systems into four risk categories: prohibited AI, high-risk AI, limited-risk AI, and minimal-risk AI. The greater the potential impact on fundamental rights, safety, or society, the more stringent the obligations. This classification directly determines which rules your organization must follow. In this article, we answer the most frequently asked questions about risk classification under the AI Act and what that means for you in practice.
What risk categories does the AI Act identify?
The AI Act distinguishes four risk categories: unacceptable risk (prohibited), high risk (heavily regulated), limited risk (transparency requirements), and minimal risk (virtually no requirements). This tiered approach ensures that the strictest rules apply to applications with the greatest potential for harm, while innovation in low-risk AI remains as unrestricted as possible.
The classification is based on the principle that the intensity of regulation must be proportional to the risks posed by an AI system. A spam filter in your email program falls into a completely different category than an AI system that evaluates job applicants or makes medical diagnoses. The regulation considers not only the system itself, but also the context in which it is used and the people directly affected by it.
Important to know: the classification is not static. A system that poses minimal risk in one context may be high-risk in another. The intended use and the sector in which you operate therefore determine which category applies.
Which AI applications are completely prohibited?
The AI Act prohibits AI applications that pose an unacceptable risk to fundamental rights and human dignity. This includes systems that manipulate people through subconscious techniques, exploit vulnerable groups, assign social scores by governments, and most forms of remote biometric identification in public spaces in real time.
Specifically, Section 5 of the AI Act prohibits the following categories:
- AI systems that use subliminal techniques to influence behavior without a person’s awareness
- Systems that deliberately manipulate vulnerable groups, such as children or people with disabilities
- Social scoring systems operated by or on behalf of governments that evaluate citizens based on their behavior in daily life
- Real-time remote biometric identification in public spaces by law enforcement, with limited exceptions
- AI that recognizes emotions in the workplace or in educational institutions, except for medical or security purposes
- Systems that use biometric categorization to infer sensitive characteristics such as political views or sexual orientation
These prohibitions were the first to take effect, specifically on February 2, 2025. Organizations that were already using such systems at that time were required to take immediate action. The fines for violations of these prohibitions are also the highest: up to 35 million euros or 7% of global annual revenue.
How do you determine whether an AI system is high-risk?
An AI system is considered high-risk if it falls within the sectors or applications listed in Annex III of the AI Act, or if it is a safety component of a product already covered by existing EU legislation (Annex I). The key question is always: Could the system have significant negative consequences for people’s health, safety, or fundamental rights?
Appendix III contains a specific list of high-risk application areas:
- Biometric Identification and Categorization of Individuals
- Management of critical infrastructure, such as energy, water, and transportation
- Education and vocational training, including student admission and evaluation
- Employment, Human Resources Management, and Access to Self-Employment
- Access to and use of essential private and public services, such as credit scoring
- Law enforcement, including risk assessment of individuals
- Migration, Asylum, and Border Control
- The Administration of Justice and Democratic Processes
There is one important exception: if a system appears at first glance to fall under Annex III but in reality has no significant impact on decision-making regarding people, the provider can argue that it is not high-risk after all. However, this requires a documented assessment and is not something you can simply assume.
What are the requirements for high-risk AI systems?
Providers of high-risk AI systems must meet a comprehensive set of requirements before bringing their systems to market. The core obligations include a robust risk management system, technical documentation, data governance, transparency toward users, human oversight, and registration in an EU database.
Specifically, these obligations are as follows:
- Risk management system: an ongoing process that identifies, evaluates, and mitigates risks throughout the system’s entire lifecycle
- Technical documentation: a detailed description of the system, its operation, the test results, and the conformity assessment procedure
- Data quality: training, validation, and test data must be relevant, sufficiently representative, and as free of errors as possible
- Transparency and user information: Users must understand what the system does, what its limitations are, and how they can use it safely
- Human oversight: The system must be designed so that people can understand, monitor, interrupt, or correct it
- Accuracy, robustness, and cybersecurity: demonstrably consistent performance, even in the face of unexpected input or attacks
- Conformity assessment and CE marking: depending on the type of system, either through self-assessment or through a notified body
- Registration: Registration in the EU database for high-risk AI prior to market introduction
Deployers—that is, organizations that use high-risk AI developed by others—also have obligations. They must ensure human oversight, use the system in accordance with the provider’s instructions, and report incidents. Responsibility is therefore shared between the party that builds the system and the party that deploys it.
What is the difference between limited risk and minimal risk?
Low-risk AI is subject to specific transparency requirements: users must be aware that they are interacting with an AI system. Minimal-risk AI is subject to virtually no obligations under the AI Act. The distinction lies in the extent to which the system interacts with people and can thereby influence their perceptions or decisions.
The low-risk category includes, among other things, chatbots, deepfakes, and AI-generated content. If your organization uses a chatbot for customer service, the user must always be aware that they are not speaking with a human. The same applies to synthetically generated audio, video, or text intended to mimic real people or events.
Low-risk AI accounts for the lion’s share of all AI applications in use today: spam filters, AI in video games, content recommendation systems, and simple automation tools. There is no legal obligation for this category, although the AI Act encourages providers to voluntarily follow codes of conduct.
So the practical difference for your organization is significant. Do you only use low-risk AI? Then the compliance requirements are minimal. Are you using a chatbot that could pass itself off as a human? Then a transparency requirement applies. And as soon as you use AI for employee evaluations or credit decisions, you quickly fall into the high-risk category.
When does the risk classification under the AI Act take effect?
The risk classification will take effect in phases. The prohibitions on unacceptable risks (Article 5) will apply as of February 2, 2025. The requirements for high-risk systems listed in Annex III will take effect on August 2, 2026. Systems used as safety components in regulated products (Annex I) will not be subject to these requirements until August 2, 2027.
The full implementation will proceed as follows:
- February 2, 2025: Prohibitions under Article 5 and the requirement for AI literacy (Article 4)
- August 2, 2025: Requirements for GPAI models, governance structure, and penalty provisions
- August 2, 2026: Most requirements for high-risk Annex III systems
- August 2, 2027: Requirements for high-risk AI as a safety component (Annex I) and compliance deadline for GPAI models that were already on the market before August 2025
In practical terms, this means that by 2026, organizations that offer or use high-risk Annex III systems must already be working on their compliance preparations. The deadline is fast approaching, and setting up a risk management system, preparing technical documentation, and establishing human oversight takes time.
Reviews of the regulation are scheduled for 2028 and 2029, with a final report on enforcement in 2031. The AI Act is therefore not a static document, but a living framework that evolves alongside technological developments.
How Pegamento Helps You with AI Compliance and the Responsible Use of AI
The AI Act sets specific requirements for how you develop, deploy, and manage AI. This calls for a partner who is not only technically strong but also understands what responsible AI means in practice. At Pegamento, we combine in-depth AI expertise with a clear focus on ethical, human-centered technology.
What we can do for you:
- Mapping Risk Classification: We’ll help you determine which category your AI applications fall into and what obligations arise from that
- Responsible Implementation of Agentic AI: Our Agentic AI solutions for customer service are designed with human oversight as a core principle, ensuring that you comply with the transparency and oversight requirements of the AI Act
- Everything under one roof: from consulting and development to implementation, management, and support—without complex supplier structures
- Customized solutions using standard building blocks: no costly custom work, but a smart combination of proven modules tailored to your situation and industry
- Certified quality: Pegamento is ISO 27001 certified (information security), supplemented by ISO 9001 and ISO 26000, so you can be sure that information security and quality are systematically guaranteed
Would you like to know where your organization currently stands in terms of AI compliance, or are you curious about how to use AI responsibly within the framework of the AI Act? Please contact us, and we’d be happy to help you figure it out.
Frequently Asked Questions
What should I do if my AI system falls on the border between two risk categories?
If it is not immediately clear which category your system falls into, a documented risk assessment is the recommended course of action. In it, outline the intended use, the target audience, the sector, and the potential impact on fundamental rights. When in doubt, it’s wise to assume the higher risk category and seek legal or technical advice to avoid facing non-compliance issues later on.
Does the AI Act also apply to AI systems that our organization purchases from an external supplier?
Yes, even as a deployer—the party that deploys an AI system from another provider—you have obligations under the AI Act. You are responsible for human oversight, using the system in accordance with the provider’s instructions, and reporting serious incidents. It is therefore essential to specify in the contract when purchasing AI systems which party bears which obligations and what documentation the provider must supply.
How often do I need to reassess the risk category of my AI system?
The classification is not a one-time exercise. If you make significant changes to the system, deploy it in a new context, or change the target audience, the risk category may change. For high-risk systems, the AI Act also mandates a continuous risk management system, which means that monitoring and reassessment must be a structural part of your AI governance.
What are the most common mistakes made when preparing for AI Act compliance?
A common mistake is that organizations start too late and underestimate the complexity of the required documentation and processes—in particular, setting up a risk management system and ensuring human oversight takes more time than expected. In addition, many organizations overestimate the scope of the exemption for non-significant impact: arguing that an Annex III system is not high-risk after all requires a thorough and documented justification, not an assumption.
As a small or medium-sized enterprise, do we also have to fully comply with the AI Act?
Yes, in principle, the AI Act makes no distinction based on company size when it comes to the applicability of the rules. However, there are less burdensome procedures available for small providers during the conformity assessment, and regulators take the size of the organization into account when imposing fines. Nevertheless, it is wise for SMEs to start early, precisely because their capacity to make quick adjustments is often more limited.
How does the AI Act relate to the GDPR if my AI system processes personal data?
The AI Act and the GDPR complement each other and both apply if your AI system processes personal data. While the GDPR focuses on the lawfulness and protection of data processing, the AI Act sets requirements for the system itself—such as data quality, transparency, and human oversight. In practice, this means that for high-risk AI systems, you must conduct both a data protection impact assessment (DPIA) under the GDPR and a conformity assessment under the AI Act.
How do I actually start mapping out the AI applications within my organization?
A good first step is an AI inventory: identify all systems and tools that use AI or contain AI components, including purchased software and third-party cloud solutions. Then, for each application, assess its intended function, the sector, and the impact on people. Based on this, you can create a preliminary classification and determine which systems should be prioritized for further compliance preparation. External guidance during this step helps prevent blind spots and ensures the assessment is legally sound.


