Inquisitor Labs

EU AI Act – System Categories

Do not be misled by the labels. Terms like high risk, limited risk and minimal risk sound narrow and technical, but in practice they cover a wide range of real systems. Many AI services operating today fall into these categories immediately, including systems that appear simple, harmless or purely assistive.

This page explains what the categories mean in operational terms so you can identify where your system sits and what obligations follow.

Important

It does not matter whether you operate a local model or rely on a service provided by a large company. The responsibility sits with you, and the obligations follow your use of the system, not the size or reputation of the provider behind it.

Why System Categories Matter

Your category determines:

Misclassification is one of the fastest ways to fall out of compliance.

Prohibited AI Systems

These systems are banned outright because they present unacceptable risks. Examples include:

If your system falls here, it cannot be placed on the EU market under any circumstances.

High Risk AI Systems

These systems are allowed but heavily regulated. High risk systems include:

High risk systems must meet strict requirements covering data quality, documentation, testing, monitoring and human oversight. This category captures far more systems than most teams expect.

Limited Risk AI Systems

These systems must meet transparency requirements. Examples include:

Users must be informed they are interacting with AI and given clear instructions for safe use.

Minimal Risk AI Systems

Most everyday AI falls here. Examples include:

Minimal risk systems have no mandatory obligations, but good practice still applies.

Foundation Models

These are large scale models trained on broad data and used for many downstream tasks. They must meet:

This applies whether you are the original developer or a downstream deployer adapting the model.

General Purpose AI

General purpose AI covers systems that can be used for many tasks across different contexts. They require:

If a general purpose system is integrated into a high risk context, the high risk rules apply.

General Purpose AI with Systemic Risk

This category covers the largest and most capable models with the potential to cause widespread harm if misused. They require:

This category is reserved for systems with exceptional scale and impact.

How to Identify Your Category

You can classify your system by checking:

If you are unsure, start with the Check if the EU AI Act Applies to You page and follow the workflow.

Where To Go Next

For further resources on checking your liability, getting started with compliance and testing your AI systems, go to the Inquisitor Labs EU AI Act hub on Leanpub. You will find:

These resources give you a clear starting point for understanding your obligations, reducing your exposure under the Act and evaluating your AI systems in real conditions.

Get Compliant Now

(C) William Argo