EU AI Act: Four Risk Classes Explained
The EU AI Act categorizes AI systems based on risk level, applying stricter obligations for higher risks. Sanctions range from prohibitions and high-risk applications to transparency requirements and minimal risk systems.

The EU AI Act (Regulation (EU) 2024/1689), partially effective from August 2024 with the full scope applying from August 2026, classifies artificial intelligence applications into four distinct risk categories. This tiered approach dictates the stringency of regulatory obligations and potential penalties for non-compliance.
The highest risk level involves prohibited practices that violate EU fundamental rights, such as social scoring by public authorities and manipulative AI techniques exploiting vulnerabilities. Violations in this category can incur fines of up to €35 million or 7% of a company's global annual turnover.
High-risk AI systems, including those used in recruitment, credit scoring, and critical infrastructure management, face rigorous requirements. These encompass robust risk management, high-quality data governance, transparency, and human oversight. Non-compliance with these obligations can result in fines up to €15 million or 3% of global annual turnover.
Systems with limited risk are subject to transparency obligations, meaning users must be aware they are interacting with AI or consuming AI-generated content like deepfakes. Most everyday AI applications, such as spam filters and recommendation engines, fall into the minimal risk category with no specific AI Act obligations. Furthermore, Article 4 mandates a foundational understanding of AI for all users of AI systems.