Chapter 3 of 11
Risk Categories in Practice: From Banned to Minimal-Risk AI
Not all AI is treated equally: discover how the EU AI Act slices the AI landscape into four risk tiers and what that really means for chatbots, scoring systems, computer vision, and more in your portfolio.
From Big Picture To Four Risk Buckets
The Four Risk Categories
The EU AI Act groups AI into four categories: unacceptable risk (prohibited), high-risk, limited risk, and minimal or no risk. Each category has very different legal consequences.
A Triage Mindset
Use the risk categories like a triage tool: 1) Is it banned? 2) If not, is it high-risk? 3) If not, does it trigger limited-risk transparency rules? 4) If none of these, it is usually minimal risk.
Why This Matters Now
By mid-2026 the AI Act is adopted and its risk logic is fixed. Even if some obligations apply later, businesses already need to map AI systems to these categories for compliance planning.
Step 1 – Spotting Unacceptable-Risk (Prohibited) AI
Why Start With Banned Uses
Unacceptable-risk AI under Article 5 is prohibited. No amount of paperwork can fix it. When classifying any AI use case, your first question should always be: does it fall into a banned practice?
Manipulation and Exploitation
Article 5 bans AI that uses subliminal techniques or exploits vulnerabilities (like age or disability) to materially distort behavior and cause significant harm. Think of systems nudging self-harm or risky financial behavior.
Social Scoring and Biometric Misuse
Public-sector social scoring, certain biometric categorization (e.g. inferring political views from faces), emotion recognition at work or school, predictive policing of individuals, and mass scraping for face databases are all prohibited.
Examples: Is This Unacceptable-Risk AI?
Workplace and Classroom Emotion AI
AI cameras that infer emotions of employees or students (e.g. labelling them as engaged or bored) are unacceptable risk, because emotion recognition in workplaces and educational settings is explicitly prohibited.
Mass Face Scraping
Building face databases by scraping images from social media or CCTV for law enforcement is prohibited. The AI Act bans untargeted scraping of facial images to create or expand recognition databases.
Persuasion vs Manipulation
A recommender chatbot nudging you to buy products is not automatically banned. It crosses into Article 5 territory only if it exploits vulnerabilities or significantly distorts behavior in a harmful way.
Public Social Scoring vs Credit Advice
The social scoring ban targets public authorities assigning broad scores that affect people across life domains. A private app helping you improve a financial credit score is not automatically covered by this prohibition.
Step 2 – Recognizing High-Risk AI (Annex III and Safety Components)
Two Paths to High-Risk
High-risk AI arises either when AI is a safety component of a regulated product (like a medical device) or when it is a standalone system listed in Annex III (e.g. credit scoring, HR screening, grading exams).
Annex III by Sector
Annex III groups high-risk uses by sector and purpose: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration/border, and justice/democracy.
Sector Is Not Enough
Being in a sensitive sector alone does not make an AI high-risk. The specific purpose must match Annex III. For instance, an HR chatbot giving interview tips is not high-risk, but an AI that ranks job applicants is.
Examples: Classifying High-Risk vs Limited vs Minimal
High-Risk in HR and Finance
AI ranking job applicants or deciding on consumer loans is high-risk. These uses affect access to employment and essential services like credit, which are explicitly listed in Annex III.
Chatbots and Recommenders
A customer support chatbot is typically limited risk (transparency duties apply). A simple product recommender is usually minimal risk, as long as it is not manipulative or high-stakes.
Biometrics and Medical AI
Face-recognition gates for access control and AI used in medical diagnosis are high-risk. They involve biometrics and safety components of regulated products, both captured by the AI Act.
Step 3 – Limited-Risk AI and Transparency Obligations
What Is Limited Risk?
Limited-risk AI is allowed but must be transparent. It includes chatbots, some emotion recognition systems, and tools that generate or manipulate realistic content like deepfakes.
Transparency Duties
Typical duties: tell users they are interacting with AI, disclose when emotion recognition or biometric categorization occurs, and label AI-generated or manipulated content when it could be mistaken for real.
Minimal Risk by Exclusion
If an AI system is not prohibited, not high-risk, and not clearly in a transparency-trigger category, it is generally minimal risk and faces no AI Act-specific obligations beyond existing laws.
Interactive: Classify AI Uses in Your Own Words
Try this thought exercise to solidify the four categories. For each scenario, write down:
- Which risk category you think applies (unacceptable, high, limited, minimal).
- Why, using at least one keyword: Article 5, Annex III, transparency, or none.
Scenarios:
- Smart classroom assistant
- AI that transcribes lectures and automatically generates quizzes for students. It does not measure emotions or attention.
- City traffic optimizer
- AI controlling traffic lights in a large city to reduce congestion and emergency response times.
- Mental health support chatbot
- A 24/7 chat assistant that gives coping tips for stress and anxiety but clearly states it is not a human and not a substitute for professional therapy.
- Public benefits triage system
- AI that helps decide which applicants should be fast-tracked for housing assistance.
- Retail store security camera analytics
- AI that counts visitors and identifies popular areas in the store, but does not identify individuals or infer sensitive attributes.
Reflection prompts:
- For each scenario, ask yourself first: could this be prohibited under Article 5?
- If not, does it directly affect rights or access in a way that matches Annex III?
- If not, does it still interact with people or generate realistic content that would need transparency?
Write your answers in a table like this (on paper or in a notes app):
- Scenario
- Category guess
- Key legal hook (Article 5 / Annex III / transparency / none)
- One sentence justification
Quick Check: Risk Category Triage
Test your ability to quickly map AI use cases to the correct risk category.
A bank uses an AI model to automatically approve or reject small personal loans. Customers interact only with a web form, not a chatbot. Which category is **most** appropriate under the EU AI Act?
- Unacceptable risk (Article 5 prohibited practice)
- High-risk AI (Annex III: access to essential private services)
- Limited-risk AI (only transparency obligations apply)
- Minimal risk (no specific AI Act obligations)
Show Answer
Answer: B) High-risk AI (Annex III: access to essential private services)
Credit scoring and AI systems deciding access to essential private services such as loans are explicitly listed in Annex III as **high-risk**. They are not prohibited per se, but they trigger the full high-risk obligations. Transparency-only limited-risk rules are not enough here.
Flashcards: Key Risk Category Concepts
Use these cards to review the core ideas and legal hooks for each risk category.
- Unacceptable-risk AI (prohibited)
- AI practices banned under Article 5, such as certain manipulative systems, public authority social scoring, specific biometric uses (emotion recognition at work/school, sensitive attribute inference), predictive policing of individuals, and untargeted facial image scraping.
- High-risk AI
- AI systems that are safety components of regulated products or match Annex III use cases (e.g., biometrics for access control, grading exams, hiring decisions, credit scoring, social benefits decisions, some law enforcement and migration tools, judicial support systems).
- Limited-risk AI
- AI that is not prohibited or high-risk but triggers transparency duties, such as chatbots, some emotion recognition and biometric categorization systems, and tools that generate or manipulate realistic content like deepfakes.
- Minimal or no-risk AI
- AI systems that do not fall into prohibited, high-risk, or limited-risk transparency-trigger categories. They face no AI Act-specific obligations beyond general laws (e.g., data protection, consumer protection).
- Annex III
- An annex of the EU AI Act listing **standalone high-risk AI use cases** by sector and purpose. Used to decide when an AI system is high-risk even if it is not a safety component of a regulated product.
- Article 5
- The article in the EU AI Act that defines **prohibited AI practices**, such as certain manipulative systems, exploitative uses, social scoring by public authorities, some biometric applications, predictive policing of individuals, and mass facial scraping.
- Transparency obligation example
- A customer service chatbot must clearly inform users that they are interacting with AI, unless this is obvious from the context. Deepfake tools must label generated content as artificial when it could be mistaken for real.
Key Terms
- Annex III
- An annex to the EU AI Act listing categories of standalone high-risk AI systems by sector and purpose, such as AI for employment decisions, credit scoring, education access, social benefits, biometrics, law enforcement, migration, and judicial processes.
- Article 5
- The provision in the EU AI Act that defines prohibited AI practices, including certain manipulative systems, exploitative uses, social scoring by public authorities, specific biometric applications, predictive policing of individuals, and untargeted facial image scraping.
- High-risk AI
- AI systems that are either safety components of regulated products or fall under the use cases listed in Annex III (e.g., biometric identification, credit scoring, hiring, education access, social benefits decisions, some law enforcement and judicial tools).
- Social scoring
- The practice of evaluating or classifying individuals based on their social behavior or characteristics, especially when used by public authorities to impose unjustified or disproportionate treatment in different contexts.
- Limited-risk AI
- AI systems that are not prohibited or high-risk but are subject to specific transparency obligations, such as chatbots, some emotion recognition systems, biometric categorization, and AI-generated or manipulated media tools.
- Unacceptable-risk AI
- AI systems that are prohibited under Article 5 of the EU AI Act, such as certain manipulative, exploitative, social scoring, biometric, predictive policing, and mass facial scraping practices.
- Minimal or no-risk AI
- AI systems that do not fall into the prohibited, high-risk, or limited-risk transparency-trigger categories and therefore face no AI Act-specific obligations beyond general EU and national laws.
- Biometric identification
- The automated recognition of natural persons based on their biological or behavioral characteristics (e.g., face, fingerprint, iris), often used for authentication or access control.
- Transparency obligations
- Requirements under the EU AI Act for certain AI systems to inform users they are interacting with AI or that content is AI-generated or manipulated, or that emotion recognition or biometric categorization is occurring.
- Emotion recognition system
- AI that infers emotions or mental states of a person from biometric data such as facial expressions, voice, or physiological signals.