AI GLOSSARY
AI Risk Classes
AI risk classes are at the heart of the EU AI Act. They categorize AI applications into four levels based on their potential risk—ranging from prohibited to minimal. For companies, they determine which obligations apply and how much effort compliance will require.
✓ 80+ AI experts ✓ 25+ years of technology expertise ✓ ISO-certified ✓ Made in Germany
Risk Classes
prohibited, high, limited, minimal
Key Criteria
Scope, Damage, Context
Requirements
Specific to each class
Best Practices
for Classification
Why AI Risk Classes Are Critical for Compliance
The EU AI Act does not regulate AI across the board—it differentiates based on risk. Those who misclassify the risk category risk fines or miss out on opportunities. Correct classification is the first and most important step in any AI compliance effort.
Basis for Obligations
The class determines which requirements apply to your AI system.
Cost Transparency
A high-risk classification means significantly higher compliance costs—important to know.
Avoiding Fines
Prohibited uses can result in fines of up to 35 million EUR—this is no trivial offense.
Clarity in the Portfolio
AI registry with classes as the basis for control.
Trust Among Stakeholders
Customers, partners, and regulators want to know how you assess risks.
Early Preparation
High-risk systems require 6–12 months of lead time—the earlier they are classified, the better.
What are AI risk classes?
AI risk classes are the categories into which the EU AI Act classifies AI applications. The classification is based on potential harm to people, fundamental rights, safety, or society.
An overview of the four classes: Prohibited (social scoring, manipulation, prohibited biometrics), High Risk (critical infrastructure, personnel selection, the judiciary), Limited Risk (chatbots, deepfakes—with transparency requirements), Minimal Risk (all others—no specific requirements).
Classification criteria: Scope of application (Where is AI used?), Potential for harm (What could go wrong?), Context (Who are the affected parties? How much control do they have?), General-Purpose AI (Large models like GPT have their own rules).
For small and medium-sized businesses, this classification means: First, classify each application. Then, determine the appropriate compliance measures. Misjudgments are costly—so proceed carefully and, when in doubt, seek external advice.
Risk Classes in Detail
These eight examples illustrate the range of classifications:
Social Scoring
AI for Recruitment
Lending AI
Education and Testing
Medical AI
Customer Service Chatbot
Deepfake Generator
Spelling Checker
Best Practices for Risk Classification
These six principles have proven effective:
- Describe in concrete terms: The more precise the application, the clearer the class.
- Assess conservatively: When in doubt, err on the side of caution—this protects against fines.
- Conduct cross-functional reviews: Involve business units, legal, compliance, and IT together.
- Document the rationale: Why this classification? Make it transparent for audits.
- Reevaluate when changes occur: New use cases or user groups change the class.
- Seek external advice: Borderline cases are common—experience helps with decision-making.
Class 1
Prohibited
Practices considered to violate fundamental rights. No longer permitted as of February 2025.
Prohibition
Class 2
High Risk
Extensive obligations and conformity assessment. Effective as of August 2026.
Required
Grade 3
Limited/Minimal
Transparency or no obligations. Voluntary best practices recommended.
Free
Common Errors in Classification
We frequently encounter these pitfalls:
- Description too general: A vague description of the application leads to misclassification.
- Classified by the department alone: The legal perspective is missing—misclassification is possible.
- Tendency toward underclassification: To save effort—risky during later audits.
- No documentation: Class is known, but rationale is not—weak during an audit.
- One-time classification: Changes to the application are not reevaluated.
Prohibited vs. High vs. Limited vs. Minimal
Comparison of the four classes:
- Prohibited: No use permitted—social scoring, manipulative AI, prohibited biometrics.
- High: Extensive obligations — risk management, documentation, human oversight.
- Limited: Transparency requirements — labeling, disclosure.
- Minimal: No specific obligations — voluntary compliance recommended.
Contact Us Now
Frequently Asked Questions About AI Risk Classes
-
Who determines the risk class?
The operator of the AI application. In case of doubt: seek legal advice and an external review. Regulatory authorities may verify the classification.
-
What happens if there is an incorrect classification?
Subclassification: Fines of up to 15 million EUR or 3 percent of consolidated revenue. Overclassification: just a waste of effort.
-
Are all chatbots associated with some level of risk?
Standard chatbots, yes. Chatbots designed for specific purposes (e.g., credit counseling) can be highly risky.
-
Can an application have multiple classes?
No, every application has a class. However, the same technology used in different applications can have different classes.
-
What about General-Purpose AI?
GPT, Claude & Co. have their own rules as "general-purpose AI models." These rules apply primarily to providers, rather than to users.
-
When do I need to start classifying?
Effective immediately. Prohibited practices as of February 2025. High-risk applications must be fully compliant as of August 2026.
-
How does classification help with prioritization?
It shows where compliance efforts are most intensive. High-risk applications take priority—that's where time is of the essence.
Classifying AI Applications Correctly
In a free initial consultation, we’ll review your AI portfolio and outline a classification approach—complete with a clear roadmap for AI Act compliance.
As an AI partner for small and medium-sized businesses, we handle the classification using legal and technical expertise. Robust documentation, a practical roadmap, and assured compliance.
What We Offer
- AI Consulting — Classification and AI Act Preparation.
- EU AI Act Glossary — the regulatory framework in detail.
- High-Risk AI in the Glossary — the most critical class.
- AI Compliance in the Glossary — Implementation of obligations.