EU AI Act — risk classification

The EU AI Act takes a risk-based approach. The same system can be in different classes depending on its use. This page walks the risk pyramid and what each class means.

Unacceptable risk (Article 5 — prohibited)

These systems are banned across the EU. Listed at Article 5.

High risk (Annex III — strict)

Listed in Annex III. Strict requirements: data governance, documentation, transparency, human oversight, accuracy, robustness, cybersecurity, conformity assessment.

See High-Risk walk for the eight categories.

Limited risk (Article 50 — transparency)

Interaction transparency: users must know they are talking to an AI system.

CSOAI's Article 50 Passport is a free signed record for the transparency obligation.

Minimal risk (no specific obligations)

Spam filters, AI in video games, basic inventory optimisers. No specific obligations in the Act. Voluntary codes of conduct encouraged.

Where CSOAI measures

CSOAI publishes measurement harnesses for:

What we do not measure: the legal classification of "is this system Annex III?". That is a regulator's call, not a measurement body's.