Minimal Risk Free Use Limited Risk Transparency Obligations High Risk Mandatory Compliance Prohibited Unacceptable Risk
Select a layer
Unacceptable Risk — Prohibited
High Risk — Strict Obligations
Limited Risk — Transparency
Minimal Risk — Free Use
Minimal Risk

Free Use

The vast majority of AI systems in use today fall into this category. The AI Act imposes no specific obligations — organisations may develop and deploy them under existing legislation.

Examples Spam filters, content recommendation engines, AI-powered video games, writing assistants, creative tools, basic support chatbots
What the law requires No mandatory obligations. Voluntary adoption of codes of conduct is encouraged but not required.
Organisational impact Low. Teams can continue to innovate without additional regulatory overhead.
✓ No specific obligations under the AI Act
Limited Risk

Transparency
Obligations

Limited-risk systems must comply with specific transparency requirements — users have the right to know they are interacting with AI or consuming AI-generated content.

Examples Chatbots, emotion recognition systems, deepfakes, synthetic audio/video/image content, recommendation systems that materially influence user choices
Disclosure obligation Users must be informed they are interacting with an AI system. AI-generated content must be labelled as such (except in clearly artistic or satirical contexts).
Organisational impact Moderate. Requires updates to interfaces and communications, but no heavy compliance processes.
⚠ Obligation to disclose and label AI-generated content
High Risk

Mandatory
Compliance

High-risk AI systems are subject to stringent requirements before they can be placed on the European market. They represent the core of the regulation and the greatest operational challenge for organisations.

Covered domains Critical infrastructure, education and vocational training, employment and workforce management, access to essential services, law enforcement, migration and border control, administration of justice
Mandatory requirements Risk management system, data governance, technical documentation, activity logging, user transparency, human oversight, conformity assessment, registration in the EU database
Organisational impact High. Requires dedicated processes, documentation and governance structures — comparable to quality management in regulated sectors (healthcare, finance).
⚠ Mandatory conformity assessment before market entry
Unacceptable Risk

Prohibited
in the European Union

These systems are deemed an unacceptable threat to fundamental rights and European Union values. Their use is strictly forbidden, with fines of up to €35 million or 7% of global annual turnover.

Prohibited practices Social scoring by government entities, real-time biometric surveillance in public spaces (with limited exceptions), subliminal manipulation systems, exploitation of vulnerabilities of specific groups
Also prohibited Emotion inference in workplace and educational contexts, biometric categorisation based on sensitive characteristics (race, religion, sexual orientation, political opinions)
Consequences of non-compliance Fines up to €35,000,000 or 7% of total worldwide annual turnover, whichever is higher. Enforcement from February 2025.
✕ Absolute prohibition — compliance is not possible, only abstention