The EU AI Act's risk-based framework represents a nuanced approach to regulation that balances innovation with protection. Understanding exactly where your AI system falls within this framework is essential for compliance planning and resource allocation.
Tier 1: Prohibited AI Practices
The AI Act draws clear red lines around AI applications deemed fundamentally incompatible with European values and fundamental rights. These prohibitions took effect in February 2025.
What's Banned
Social scoring systems that evaluate citizens based on behavior or predicted behavior in ways that lead to detrimental treatment are explicitly prohibited. This targets government-run systems that aggregate data to score individuals and restrict access to services.
Subliminal manipulation techniques that deploy AI to manipulate persons beyond their consciousness, causing psychological or physical harm, are banned. This covers dark patterns and psychological manipulation at scale.

Exploitation of vulnerable groups through AI systems that target children, elderly, or cognitively impaired individuals in ways that materially distort their behavior is prohibited.
Real-time remote biometric identification in public spaces for law enforcement faces strict prohibition with narrow exceptions for serious crime, missing persons, and terrorism threats, subject to judicial authorization.
Limited Exceptions
Law enforcement may use real-time biometric identification in strictly limited circumstances including targeted search for specific crime victims, prevention of imminent terrorist threats, and location of suspects in specific serious crimes, always requiring prior judicial or independent administrative authorization.

Tier 2: High-Risk AI Systems
The most substantive regulatory requirements apply to high-risk AI systems, defined through two pathways: Annex II (product safety legislation) and Annex III (fundamental rights impact).
Annex II: Product Safety Integration
AI systems that are safety components of products already covered by EU harmonized legislation automatically qualify as high-risk. This includes medical devices and in-vitro diagnostics, machinery and equipment, toys and recreational equipment, aviation and marine equipment, motor vehicles and their components, and elevators and pressure equipment.
Annex III: Fundamental Rights Categories
AI systems in sensitive areas affecting fundamental rights are classified as high-risk by default. Employment applications including recruitment, promotion decisions, task allocation, and termination face high-risk classification. Educational systems for admissions, assessment, and proctoring fall under this category. Essential services access including credit scoring, emergency services, and utilities are covered. Law enforcement applications for individual risk assessment, polygraph alternatives, and evidence evaluation are high-risk. Migration and asylum systems for application processing and border control are included.

Tier 3: Limited Risk AI
AI systems with limited risk face transparency obligations but not the full compliance burden of high-risk systems. Chatbots and conversational AI must disclose their non-human nature to users. Emotion recognition systems must inform subjects when their emotions are being analyzed. Deepfake and synthetic content generators must label their outputs as artificially generated. Biometric categorization systems must inform individuals of their operation.
Tier 4: Minimal Risk AI
The vast majority of AI applications fall into the minimal risk category and face no AI Act-specific requirements. Video game AI, spam filters, content recommendation systems, inventory optimization, and most consumer applications operate without additional regulatory burden.
How to Classify Your AI System
Organizations should follow a systematic process to classify their AI systems. First, check for prohibited practices, if your system involves any banned application, it cannot be deployed. Second, review Annex II and III to determine if your system falls into listed categories. Third, assess transparency obligations for chatbots, deepfakes, or emotion recognition. Fourth, document your classification reasoning for regulatory review.
Next steps: Read [EU AI Act Compliance Requirements](/articles/eu-ai-act-compliance-requirements) for implementation guidance.
