The Risk Pyramid
Unacceptable risk - banned outright (Article 5). Eight prohibited
practices: manipulative or subliminal techniques causing harm; exploiting
vulnerabilities of children, disabled people, or economically
disadvantaged groups; social scoring; predicting criminal risk based
solely on profiling or personality traits; untargeted facial-image
scraping for recognition databases; emotion recognition in workplaces or
schools; biometric categorization inferring race, political opinion,
religion, sexual orientation, or union membership; and real-time remote
biometric identification in public spaces by law enforcement (narrow,
judicially-authorized exceptions).
High risk - heavily regulated, not banned. Employment, credit scoring,
critical infrastructure, law enforcement, migration, essential services.
Detailed obligations: risk management, data governance, technical
documentation, human oversight, accuracy/robustness testing, conformity
assessment before market placement. Full detail on the dedicated
High-Risk AI Systems page.
Limited risk - transparency obligations (Article 50). Disclose AI
interaction (unless obvious); label AI-generated content as such, in
machine-readable form; inform people exposed to emotion-recognition or
biometric-categorization systems; disclose deepfakes and AI-generated
text on matters of public interest (exceptions for clearly
artistic/satirical work and editorially-reviewed content). In effect
from 2 August 2026.
Minimal risk - no obligations under the Act. Most ordinary commercial AI
use falls here, though other law (data protection in particular) can
still apply.