AI GLOSSARY

AI Risk Classes

AI risk classes are at the heart of the EU AI Act. They categorize AI applications into four levels based on their potential risk—ranging from prohibited to minimal. For companies, they determine which obligations apply and how much effort compliance will require.

 

✓ 80+ AI experts ✓ 25+ years of technology expertise ✓ ISO-certified ✓ Made in Germany

4

Risk Classes
prohibited, high, limited, minimal

3

Key Criteria
Scope, Damage, Context

8

Requirements
Specific to each class

6

Best Practices
for Classification

Why AI Risk Classes Are Critical for Compliance

The EU AI Act does not regulate AI across the board—it differentiates based on risk. Those who misclassify the risk category risk fines or miss out on opportunities. Correct classification is the first and most important step in any AI compliance effort.

hands-holding-heart-light-full (1)

Basis for Obligations

The class determines which requirements apply to your AI system.

rocket-light-full

Cost Transparency

A high-risk classification means significantly higher compliance costs—important to know.

stars-sharp-light-full

Avoiding Fines

Prohibited uses can result in fines of up to 35 million EUR—this is no trivial offense.

heart-light-full (1)

Clarity in the Portfolio

AI registry with classes as the basis for control.

robot-light-full

Trust Among Stakeholders

Customers, partners, and regulators want to know how you assess risks.

mobile-light-full

Early Preparation

High-risk systems require 6–12 months of lead time—the earlier they are classified, the better.

What are AI risk classes?

AI risk classes are the categories into which the EU AI Act classifies AI applications. The classification is based on potential harm to people, fundamental rights, safety, or society.

An overview of the four classes: Prohibited (social scoring, manipulation, prohibited biometrics), High Risk (critical infrastructure, personnel selection, the judiciary), Limited Risk (chatbots, deepfakes—with transparency requirements), Minimal Risk (all others—no specific requirements).

Classification criteria: Scope of application (Where is AI used?), Potential for harm (What could go wrong?), Context (Who are the affected parties? How much control do they have?), General-Purpose AI (Large models like GPT have their own rules).

For small and medium-sized businesses, this classification means: First, classify each application. Then, determine the appropriate compliance measures. Misjudgments are costly—so proceed carefully and, when in doubt, seek external advice.

prodot ki risk classes

Risk Classes in Detail

These eight examples illustrate the range of classifications:

Social Scoring

Prohibited. Evaluation of individuals by government agencies based on social behavior.

AI for Recruitment

High risk. Systems for screening applicants or evaluating employees.

Lending AI

High Risk. Automated Decisions on Loans and Creditworthiness.

Education and Testing

High Risk. AI for Admission and Evaluation of Academic Performance.

Medical AI

High risk if subject to CE marking as a medical device—otherwise, depending on the application.

Customer Service Chatbot

Limited risk. Transparency requirement: Customers know they are talking to AI.

Deepfake Generator

Limited risk. Must be identified as artificially generated content.

Spelling Checker

Minimal risk. No specific AI Act obligations.

Best Practices for Risk Classification

These six principles have proven effective:

  • Describe in concrete terms: The more precise the application, the clearer the class.
  • Assess conservatively: When in doubt, err on the side of caution—this protects against fines.
  • Conduct cross-functional reviews: Involve business units, legal, compliance, and IT together.
  • Document the rationale: Why this classification? Make it transparent for audits.
  • Reevaluate when changes occur: New use cases or user groups change the class.
  • Seek external advice: Borderline cases are common—experience helps with decision-making.
prodot ki risk classes
Class 1

Prohibited

Practices considered to violate fundamental rights. No longer permitted as of February 2025.

Prohibition

Class 2

High Risk

Extensive obligations and conformity assessment. Effective as of August 2026.

Required

Grade 3

Limited/Minimal

Transparency or no obligations. Voluntary best practices recommended.

Free

Common Errors in Classification

We frequently encounter these pitfalls:

  • Description too general: A vague description of the application leads to misclassification.
  • Classified by the department alone: The legal perspective is missing—misclassification is possible.
  • Tendency toward underclassification: To save effort—risky during later audits.
  • No documentation: Class is known, but rationale is not—weak during an audit.
  • One-time classification: Changes to the application are not reevaluated.

Prohibited vs. High vs. Limited vs. Minimal

Comparison of the four classes:

  • Prohibited: No use permitted—social scoring, manipulative AI, prohibited biometrics.
  • High: Extensive obligations — risk management, documentation, human oversight.
  • Limited: Transparency requirements — labeling, disclosure.
  • Minimal: No specific obligations — voluntary compliance recommended.
prodot ki risk classes

Contact Us Now

Katja Kammilla as the contact person for AI consulting

Your contact person

Katja Kammilla
0203 3965080

Frequently Asked Questions About AI Risk Classes

Classifying AI Applications Correctly

In a free initial consultation, we’ll review your AI portfolio and outline a classification approach—complete with a clear roadmap for AI Act compliance.

As an AI partner for small and medium-sized businesses, we handle the classification using legal and technical expertise. Robust documentation, a practical roadmap, and assured compliance.

What We Offer

prodot ki risk classes