EU AI Act risk categories: which one is my product actually in?
Last updated 30 July 2026
Most AI Act anxiety comes from reading high-risk obligations that don’t apply to you. The Act is risk-tiered, and the tier determines everything about your workload. Here is the map, with realistic SaaS examples.
Tier 1 — Prohibited practices (Article 5)
Banned outright since 2 February 2025: social scoring by public authorities, exploitative manipulation of vulnerable groups, untargeted scraping of facial images for recognition databases, emotion recognition in workplaces and schools (with narrow exceptions), and similar. If you’re reading a SaaS-focused guide, you are very unlikely to be here — but check Article 5 if your product touches biometrics or behavioral manipulation.
Tier 2 — High-risk systems (Article 6 + Annex III)
High-risk covers AI used in specific sensitive contexts listed in Annex III — employment and worker management (CV screening, promotion decisions), education (exam scoring, admission), essential services (credit scoring, insurance pricing), law enforcement, migration, justice — plus AI that is a safety component of regulated products. High-risk means the heavy regime: risk management systems, data governance, technical documentation, human oversight, conformity assessment, registration.
The trap: it’s the use context, not the technology. A generic LLM API is not high-risk; the same model wired into a CV-ranking feature of your HR product is. If you sell into HR, edtech, fintech or insurance, read Annex III carefully.
Tier 3 — Transparency risk (Article 50) — where most SaaS lands
This is the tier this site exists for. If your product includes a chatbot or voice agent that talks to users, or generates synthetic text, images, audio or video, you have transparency obligations from 2 August 2026:
- Tell users they’re interacting with AI — 50(1), the chatbot test and wording examples that pass.
- Mark AI-generated content machine-readably — 50(2) via C2PA.
- Disclose deep fakes and AI text published to inform the public — 50(4).
These duties are real and fined (up to €15M or 3% of worldwide turnover), but they are days of work, not quarters — disclosure UX, marking, documentation. The checklist walks through all of it.
Tier 4 — Minimal risk
Everything else — spam filters, recommendation logic, code assistants used internally, AI features that neither converse with users nor generate public-facing synthetic content. No new obligations beyond existing law, though voluntary codes of conduct are encouraged.
Two cross-cutting notes
- Tiers stack. A high-risk system that also chats with users has Article 50 duties on top of the high-risk regime. GPAI model obligations (Chapter V) are a separate axis again and hit model providers, not typical SaaS deployers.
- The tiers don’t care where you’re headquartered. Serving EU users puts non-EU companies in scope — see the extraterritoriality guide.
Find your tier in two minutes
The free compliance checkerasks about your product’s actual features and tells you which Article 50 obligations apply. And if you’ve heard the whole law slipped to 2027 — only parts of the high-risk regime were ever in that debate; the transparency tier applies from 2 August 2026.
Not sure which obligations apply to you?
Run the free 3-minute Article 50 check