Last updated: 24 June 2026
The EU AI Act sorts AI systems by risk, four levels in the usual shorthand, plus a separate track for general-purpose models, and the level you land in sets your obligations, your deadline and the size of fine you are exposed to. The four-tier idea is easy to recite. Working out which tier your own system sits in is where teams stall, because the answer runs through Article 5, Annex III, the Article 6(3) exemption and the rules for general-purpose models, often at once.
This AI Act risk classification tool works through that path in the order the Regulation does. Answer six questions about your system and you get a preliminary classification, the obligations attached to it by Article, the statutory penalty ceiling for your turnover, and the application date that applies to you. Every step is tied to a specific Article of Regulation (EU) 2024/1689, so you can check the reasoning instead of trusting a black box.
It is built for compliance officers, DPOs, product leads and founders who need a fast, documented starting point. It is a preliminary orientation, not legal advice. The Article 6(3) exemption in particular wants a lawyer’s eye before you rely on it.
What the Classifier Checks, and What It Leaves to a Lawyer
The classifier follows the Regulation’s own order of priority. It checks scope first (Article 2), then the prohibited practices (Article 5), then high-risk status through Annex III and Annex I with the Article 6(3) exemption, then transparency duties (Article 50), and the general-purpose model track (Articles 51 to 55). The one real calculation, the penalty ceiling, comes from Article 99 and Article 101 with the SME rule in Article 99(6). Where an answer is unclear, it defaults to the higher-risk reading, on the basis that over-preparing costs less than missing the regime.
It does not cover everything. It will not resolve the so-called one-third of FLOP threshold for downstream model modifiers, where the official sources still disagree, and there is no “30% rule” in the AI Act to begin with. It treats any real-time biometric identification as prohibited even though Article 5 carves out three narrow law-enforcement exceptions. And it gives general-purpose models the statutory penalty ceiling rather than a turnover-based figure. For anything close to the line, an Article 6(3) exemption above all, confirm the result with counsel.
Questions People Ask About AI Act Risk Classification
What are the risk levels under the EU AI Act?
Officials describe four. Unacceptable risk is prohibited outright (Article 5), high-risk is heavily regulated (Article 6), limited risk carries transparency duties (Article 50), and minimal risk is left unregulated. The Regulation itself does not set out a literal four-rung ladder, so treat the four levels as a useful shorthand rather than a legal category. General-purpose models sit in a separate track (Articles 51 to 55) that can apply on top of the rest.
What makes an AI system high-risk under the AI Act?
A system is high-risk in two situations. It is a safety component of a product already regulated under EU harmonisation law and needing third-party conformity assessment (Annex I, Article 6(1)), or it is used in one of the eight areas listed in Annex III, such as employment, credit scoring or education (Article 6(2)). An Annex III system can fall back out of high-risk through the Article 6(3) exemption, but only if it does not profile people.
What is the Article 6(3) exemption?
Article 6(3) lets an Annex III system avoid high-risk status if it does only limited work, such as a narrow procedural task or improving a result a person already produced. It never applies to a system that profiles individuals, which stays high-risk regardless of how narrow its task is. You also have to document the assessment and register the system, so the exemption is a smaller burden, not no burden.
What are the penalties under the EU AI Act?
The top fine is 35 million euros or 7% of worldwide annual turnover, whichever is higher, for breaching the Article 5 prohibitions (Article 99(3)). Most other breaches cap at 15 million or 3% (Article 99(4)), and supplying false information caps at 7.5 million or 1% (Article 99(5)). SMEs and start-ups face the lower of the two amounts rather than the higher (Article 99(6)), which our AI Act fines explainer walks through with worked examples.
When does the AI Act apply, and what are the deadlines?
Most obligations apply from 2 August 2026, the Article 5 bans have applied since 2 February 2025, and high-risk systems embedded in regulated products follow on 2 August 2027 (Article 113). The Digital Omnibus, adopted by Parliament on 16 June 2026 and awaiting formal Council adoption, would move standalone Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. The Union is amending the AI Act, before the AI Act fully applies, to delay the AI Act, and until the Omnibus is published in the Official Journal the original dates stand. Our EU compliance deadline tracker keeps the live dates against the proposed ones.
Is a general-purpose AI model high-risk?
No. General-purpose models are classified on a separate track, not as high-risk. A model is presumed to carry systemic risk once its cumulative training compute passes 10^25 FLOP (Article 51(2)), which adds the Article 55 duties on top of the baseline documentation and transparency obligations in Article 53.
Is there a “30% rule” in the AI Act?
No. There is no “30% rule” anywhere in Regulation (EU) 2024/1689. The figure people half-remember points to a guideline threshold of roughly one third of the relevant FLOP level for downstream providers who fine-tune another company’s model, and even there the official sources disagree on the exact number. If a vendor cites a “30% rule” as AI Act law, that is your signal to check the source.
Does the AI Act apply if we only use AI rather than build it?
Yes. If you deploy a high-risk system you carry your own duties under Article 26, separate from the provider’s, so building the system yourself is not the trigger. The narrow way out of scope is using a system strictly for personal, non-professional purposes or purely for pre-market research (Article 2), and that exemption falls away the moment the system goes into professional use.
Classification Is the Work You Can Start Before the Standards Land
The hardest part of AI Act compliance is not the documentation template. It is finding every AI system you build, deploy or procure and deciding which category each one falls into, and none of that depends on the harmonised standards being final. Run your main systems through the classifier above, then take the free AI Act Readiness Assessment to see where your largest gaps sit across the wider regulation set, and if penalties are the number your board cares about, the AI Act fines calculator puts a figure on the exposure.
This tool provides general guidance based on Regulation (EU) 2024/1689 (the EU AI Act). It is a preliminary orientation, not legal advice. Consult qualified legal counsel for your specific situation. Last verified: 24 June 2026.
