EU AI Act Risk Classification: Unacceptable, High, Limited, Minimal

Shubham S.
October 6, 2026
•
25
mins

EU AI Act risk classification comes down to one question you can answer feature by feature: what is this system intended to be used for? Two features can run on the same model and land in different tiers, with different duties and different dates.

EU AI Act risk classification sorts AI systems into four tiers by intended use, not by technology: unacceptable risk (banned), high risk (strict requirements), transparency risk (disclosure duties, often called limited risk), and minimal risk (no specific rules). The tier follows the feature you build, not the model underneath it.

Quick answer, as of 30 September 2026 Bans have applied since 2 February 2025, and Article 50 transparency duties since 2 August 2026. High-risk duties for Annex III systems now start on 2 December 2027, and for Annex I products on 2 August 2028, after Regulation (EU) 2026/1744 entered into force on 27 July 2026.

This piece is about placing a system in a tier. For who the Act applies to, provider and deployer duties, penalties, and a startup plan, see our EU AI Act compliance guide.

By the end you will be able to put each of your AI features in a tier, say why, and point to the sentence of the law or the Commission guidance behind the call.

Here is what I will cover:

  • The four tiers side by side, with the date each one applies
  • The Article 5 bans, including the ones that catch SaaS teams off guard
  • The two routes into high risk, the eight Annex III areas, and the Article 6(3) exemption with its profiling trap
  • Transparency duties, minimal risk, and where general-purpose AI fits
  • A five-step method and a worked table of common SaaS features

EU AI Act Risk Classification: How the Four Tiers Fit Together

Here is the whole structure in one table, covering all four EU AI Act risk categories. Every later section unpacks one row.

Tier What it means Legal basis Typical example Applies from
Unacceptable risk Banned outright Article 5 Social scoring, emotion inference at work 2 Feb 2025 (two new bans 2 Dec 2026)
High risk Strict requirements before and after market placement Article 6, Annexes I and III Résumé ranking, credit scoring 2 Dec 2027 (Annex III), 2 Aug 2028 (Annex I)
Transparency risk ("limited") Disclosure and content-marking duties Article 50 Customer-facing chatbot, AI-generated images 2 Aug 2026
Minimal risk No specific AI Act obligations None, it is the default Spam filters, video game AI Not applicable
Pyramid of the four EU AI Act risk tiers with the date each applies: unacceptable risk banned from 2 February 2025, high risk from 2 December 2027 and 2 August 2028, transparency risk from 2 August 2026, and minimal risk with no specific rules.

The dates come from the AI Act Service Desk timeline and the consolidated text of Article 113 as amended by the Digital Omnibus. The hub guide explains the Omnibus in full, so I will not repeat it here.

AI Management System
Classified your AI features? Give the decisions a home.
ISO 42001 gives AI risk assessment, impact assessment, and documentation a certifiable structure. See how ComplyJet supports it.
See ISO 42001 support

EU AI Act Risk Levels at a Glance

The Regulation's operative articles do not label four tiers. They ban certain practices (Article 5), define high-risk systems (Article 6), and attach transparency duties to certain systems (Article 50). Everything else is left unregulated by default.

The four labels are shorthand for the EU AI Act risk levels, and the Commission's overview frames the third one around transparency. Many guides call it limited risk, and I use both terms.

Note A system can sit in two boxes at once. A résumé-screening chatbot is high-risk and also owes Article 50 disclosure, because Article 50(6) says the transparency duties do not affect the high-risk requirements.

General-purpose AI models sit beside the pyramid rather than inside it. They have their own regime, covered below.

Why EU AI Act Risk Classification Follows Use, Not Technology

The anchor concept is intended purpose.

Quick take The Act defines intended purpose as "the use for which that system is intended by the provider", including the context and conditions of use stated in the instructions, sales material, and technical documentation. The Commission's draft classification guidelines (paragraph 10) quote that definition and build on it.

So the same résumé-parsing model can be minimal risk in one product and high-risk in another. What changes is what you say it is for, and who it affects.

A developer writing on DEV Community in March 2026 made the same point about HR chatbots: one that only answers FAQs may be limited risk, but once it filters candidates it becomes high-risk, and the boundary is "extremely blurry." The post promotes the author's own quiz tool, so read it as a practitioner's framing, not authority. The legal test underneath is still intended purpose.

EU AI Act Unacceptable Risk: The Article 5 Prohibited Practices

The top tier is the simplest to state and the most expensive to get wrong. EU AI Act unacceptable risk means the practice is banned, not regulated. The Article 5 prohibitions have applied since 2 February 2025, and the Commission published non-binding guidelines on prohibited practices on 4 February 2025.

The ceiling for breaching a ban is the top fine tier: up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher (Article 99(3)). For SMEs, including start-ups, the lower of the two figures applies (Article 99(6)).

Article 5(1) Banned practice Notable limit
(a) Subliminal, purposefully manipulative, or deceptive techniques that materially distort behaviour Needs significant harm, actual or reasonably likely
(b) Exploiting vulnerabilities linked to age, disability, or a specific social or economic situation Same material-distortion and significant-harm test
(ba) new Generating or manipulating realistic intimate imagery of an identifiable person without explicit consent Applies from 2 Dec 2026
(bb) new Generating or manipulating child sexual abuse material, by reference to Directive 2011/93/EU Applies from 2 Dec 2026
(c) Social scoring that leads to unrelated-context or disproportionate detrimental treatment Not limited to public authorities in the text
(d) Predicting criminal offences based solely on profiling or personality traits Allowed as support for a human assessment based on objective facts
(e) Building facial recognition databases by untargeted scraping of the internet or CCTV None
(f) Inferring emotions in the workplace and education institutions Medical or safety reasons are excepted
(g) Biometric categorisation to infer race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation Lawful labelling of datasets, and law enforcement categorising, are excepted
(h) Real-time remote biometric identification in public spaces for law enforcement Three narrow, strictly necessary exceptions

The two new rows come from the Digital Omnibus. Article 5(1a) narrows them: a general system is caught only where the prohibited output is its intended purpose, or where it makes that output a reasonably foreseeable and reproducible result without adequate safeguards.

EU AI Act Prohibited Practices That Surprise SaaS Teams

Much of the list is aimed at law enforcement and surveillance uses. Three of the EU AI Act prohibited practices are different, because ordinary software can drift into them.

  • Emotion inference at work or school. Article 5(1)(f) bans AI systems that infer emotions of a natural person in workplaces and education institutions, unless intended for medical or safety reasons. A feature that scores employee mood from faces or voices on calls belongs in this conversation.
  • Social scoring by private companies. The text of Article 5(1)(c) covers evaluating people over time by behaviour or inferred characteristics, with detrimental treatment as the result. It does not say the scorer must be a public authority.
  • Manipulation and exploitation. Both (a) and (b) require material distortion of behaviour and significant harm. Persuasive design is not automatically banned, but exploiting a vulnerable group's situation to push a harmful decision is what (b) targets.
Watch out Whether a given "engagement" or "sentiment" feature infers emotions is a legal question, not a product label. If a feature touches faces, voices, or typing patterns of employees or students, put it in front of counsel before you ship it, and read the Commission's prohibited-practices guidelines first.

EU AI Act High-Risk AI Systems: Two Routes Into the Strictest Tier

EU AI Act high-risk AI systems are defined in Article 6, and there are two ways in. Miss both and you are outside the tier, whatever your marketing says.

  • Route 1, Article 6(1) and Annex I. The system is a safety component of a product covered by the Union harmonisation legislation in Annex I, or is itself such a product, and that product needs a third-party conformity assessment. Applies from 2 August 2028.
  • Route 2, Article 6(2) and Annex III. The system falls within one of the use cases listed in Annex III. Applies from 2 December 2027.

Route 1 rarely catches a pure SaaS product. It matters if you build AI into a regulated physical product, or supply a component to someone who does.

Note The Omnibus tightened the definition of a safety component. AI used solely for non-safety aspects such as user assistance, performance optimisation, service efficiency, automation, convenience, or quality control does not qualify, unless its failure would endanger health and safety (Article 6(1a) and 6(1b)).

Route 2 is where SaaS teams land. Once a system is one of the EU AI Act high-risk AI systems, the provider owes a risk management system, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity measures, a quality management system, conformity assessment, and EU database registration. The hub guide sets out those duties by role.

EU AI Act Annex III: The Eight Areas, Read for SaaS

Annex III lists eight areas. Several are qualified by "in so far as their use is permitted under relevant Union or national law", and most list specific use cases, not whole industries.

Annex III area What is listed SaaS reading (my view)
1. Biometrics Remote biometric identification, categorisation by sensitive attributes, emotion recognition Plain identity verification, confirming someone is who they claim to be, is carved out. Identification is not.
2. Critical infrastructure Safety components in managing digital infrastructure, road traffic, water, gas, heating, electricity Relevant if you sell AI into those operators
3. Education and vocational training Admission, evaluating learning outcomes, assessing education level, detecting prohibited behaviour in tests Edtech scoring, admissions, and proctoring features
4. Employment and workers' management Recruitment and selection, terms of work, promotion and termination, task allocation, performance monitoring HR tech and workforce analytics, the most common SaaS trigger
5. Essential services Public benefit eligibility, creditworthiness and credit scoring (fraud detection excepted), life and health insurance pricing, emergency call triage Fintech and insurtech underwriting features
6. Law enforcement Victim risk assessment, polygraph-type tools, evidence reliability, offending risk, profiling in investigations Only if you sell to police or act for them
7. Migration, asylum, border control Polygraph-type tools, risk assessment, visa and asylum examination, detection and identification Only if you sell to competent public authorities
8. Justice and democratic processes Assisting judicial authorities, influencing elections or voting behaviour Legal tech used by courts, and political persuasion tools
Grid of the eight EU AI Act Annex III high-risk areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and justice and democratic processes.

The Commission can amend this list by delegated act, and the annual review of Annex III use cases is built into the Act, so treat the eight areas as current, not permanent (Articles 7 and 112).

EU AI Act Article 6(3): How an Annex III System Can Stay Out of High-Risk

Being listed in Annex III is where the assessment starts, not where it ends. EU AI Act Article 6(3) lets a provider conclude that an Annex III system is not high-risk where it "does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons", including by not materially influencing the outcome of decision making.

That conclusion needs at least one of four conditions to apply:

  1. Narrow procedural task. Think converting unstructured data into structured data, or sorting documents into categories.
  2. Improving a previously completed human activity. The human work is done, and the AI polishes the result.
  3. Detecting decision-making patterns or deviations. It is not meant to replace or influence the earlier human assessment without proper human review.
  4. Preparatory task. It prepares an assessment relevant to an Annex III use case.

The Commission's draft guidelines say these conditions are exhaustive but alternative, and must be interpreted narrowly, because Article 6(3) is an exception to rules that protect fundamental rights. Three traps sit on top.

Important: the profiling override An Annex III system that performs profiling of natural persons is always high-risk, whatever else is true. Profiling means automated processing of personal data to evaluate personal aspects of a person, such as work performance or reliability. One tool that audits recruiters' decisions while evaluating the recruiters' own characteristics is the Commission's example of a system that loses the exemption for exactly this reason (draft guidelines, paragraph 112).

Trap two is the human in the loop. The draft guidelines state that a provider cannot categorise a system as low risk "simply by adding to it a requirement for human involvement" (paragraph 71). Human review can help show that the task is narrow or preparatory. It cannot replace that showing.

Myth debunking "We keep a human reviewer, so we are not high-risk." NO. Human oversight is a requirement for high-risk systems, not a way out of the tier.

Trap three is the paperwork. Under Article 6(4), the companion to EU AI Act Article 6(3), a provider that considers an Annex III system not high-risk must document that assessment before the system is placed on the market, and register it under Article 49(2). The draft guidelines say the record should cover the intended purpose, why the system is in Annex III, which condition applies and why, and why no profiling is involved (paragraph 115).

Get it wrong and the consequences are real. Market surveillance authorities can evaluate a system's classification, and where a provider misclassified to dodge the requirements, they can impose penalties under Article 99 (draft guidelines, paragraph 117).

The Commission's draft classification guidelines, published 19 May 2026, work through examples. The recruitment ones are the most useful for SaaS teams.

Example in the draft guidelines Outcome Why
Tool that only generates job descriptions from a recruiter's list of tasks and qualifications Exempt Narrow procedural task, Article 6(3)(a)
Same tool, but it generates the qualifications itself, or scores CVs against the description and recommends suitability High-risk It substantially affects the application process
Retrospective audit of past hiring decisions on anonymised data to detect bias Exempt Pattern detection on completed assessments, Article 6(3)(c)
Personalised acknowledgement emails to applicants Exempt Narrow procedural task, no influence on selection
Sorting school applications into predefined grade categories, with no suitability evaluation Exempt Narrow procedural task
Note These guidelines are still a draft. They are non-binding, the Commission says it will consult the AI Board and seek further feedback before adopting them, and only the Court of Justice can give an authoritative interpretation (paragraphs 5 and 6). Use them as the Commission's current thinking, and re-check for the final version.
Decision gate for the EU AI Act Article 6(3) exemption: an Annex III system must meet one of four conditions, then pass the profiling check, and must still be documented and registered; any profiling means it stays high-risk.

Paperwork is the part teams forget, and the method later in this piece builds it into the routine.

Customer story
“ComplyJet’s hands-on support and clear guidance made SOC, GDPR, and ISO compliance smooth.”
Suhas Manangi, Co-Founder & CEO, Precognition Labs. Read what other early-stage teams say about working through frameworks with us.
Read customer stories

EU AI Act Limited Risk: The Transparency Tier

The EU AI Act limited risk tier is about honesty, not restriction. You can build the feature. You have to tell people what it is.

These duties apply from 2 August 2026, and they stack on top of any other tier. A chatbot that screens job candidates owes high-risk duties and the disclosure duty. A chatbot that answers product questions owes only the disclosure.

EU AI Act Transparency Obligations Under Article 50, Duty by Duty

Article 50 Who owes it The duty Main exception
50(1) Providers of systems that interact directly with people Design the system so people are told they are interacting with AI Where it is obvious to a reasonably well-informed, observant, and circumspect person
50(2) Providers of systems that generate synthetic audio, image, video, or text Mark outputs in a machine-readable format, detectable as AI-generated, as far as technically feasible Assistive editing, or no substantial alteration of the input
50(3) Deployers of emotion recognition or biometric categorisation systems Inform the people exposed to the system Certain law-enforcement uses
50(4) Deployers who generate deepfakes, or publish AI text on matters of public interest Disclose that the content is artificially generated or manipulated Text that went through human review under someone's editorial responsibility

Every one of these EU AI Act transparency obligations shares one delivery standard. Article 50(5) sets it: clear and distinguishable, at the latest at the first interaction or exposure, and accessible. A line buried in terms and conditions is hard to square with that wording.

Two dates and two documents are worth knowing:

  • Transitional deadline. A deadline of 2 December 2026 applies to certain providers for the Article 50(2) marking duty, per the AI Act Service Desk timeline.
  • Guidance. Law-firm coverage, including Jones Day and Paul Weiss, reports that the Commission published a final Code of Practice on marking and labelling AI-generated content on 10 June 2026, and final Article 50 guidelines on 20 July 2026. The Code is voluntary, but the Article 50 duties are not.
Note Breaching Article 50 falls in the middle fine tier: up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, and the lower figure for SMEs (Article 99(4)(g) and 99(6)).

EU AI Act Minimal Risk: Where Most Features Land

EU AI Act minimal risk is the default, and the Commission's overview says it covers the large majority of AI systems in use in the EU. Its examples are spam filters and video games.

No AI-specific obligations attach to this tier. GDPR still applies if you process personal data, and staff AI literacy expectations under Article 4 still sit in the background. The hub guide covers both.

One Hacker News commenter made the same point in June 2026, arguing that under the Act "Most of the AI applications are not regulated." That is one person's opinion in an argument about Europe's AI industry, but it matches the Commission's framing.

Watch out Minimal risk is the result of classification, not a label you pick. You reach it only after the ban check, the Annex I and III check, and the Article 50 check all come back clean.

EU AI Act General Purpose AI: Outside the Pyramid, Inside the Classification

The four tiers classify AI systems. EU AI Act general purpose AI models, the foundation models behind many products, have a separate chapter of the Act. A model is treated as one with systemic risk if it has high-impact capabilities, and is presumed to when the cumulative compute used in training exceeds 10^25 floating point operations, or FLOPs (Article 51). Those duties have applied since 2 August 2025.

One Hacker News commenter described why this sits awkwardly in March 2026: "the core of the AI act was written about supervised ML, not generative ML." That is an opinion, but it explains why you classify the model and the system on different tracks.

For your features, the rule is straightforward: the system you build on a model is classified on its own intended purpose. Three points from the Commission's draft guidelines matter here.

  • Broad positioning backfires. If your documentation, terms, and sales material present a system as broadly applicable and do not consistently exclude high-risk uses, the intended purpose is deemed to include them (paragraph 12). Saying "no HR use" in the terms of service is not enough if your demos and examples show HR use.
  • Split architectures are assessed as a whole. Where several AI components jointly influence an individual decision, the combined system is classified together. That includes agentic setups that chain actions toward a high-risk purpose (paragraph 75).
  • You can become the provider. A deployer or distributor who changes the intended purpose of a non-high-risk system, including a general-purpose one, so that it becomes high-risk takes on provider obligations under Article 25(1) (paragraph 14).

How to Run an EU AI Act Risk Classification on Your Own Features

The law gives you the tiers. You still have to do the placing, and a written record of how you did it is what a customer or regulator will ask for.

A Five-Step EU AI Act Risk Classification Method

  1. Confirm it is an AI system. Article 3(1) requires a machine-based system that infers from its input how to generate outputs such as predictions, content, recommendations, or decisions. Not every automated feature qualifies.
  2. Write the intended purpose in one sentence. Use the same words as your documentation, website, and sales material. Mismatched wording is how broad positioning happens.
  3. Check the bans. Compare the purpose to Article 5. A hit here ends the analysis.
  4. Check Annex I and Annex III. If an Annex III use case matches, test the four Article 6(3) conditions and the profiling override, then document the result.
  5. Check Article 50, then record the decision. Log the feature, purpose, tier, legal basis, owner, date, and the event that would trigger a re-check.
Five-step flow for EU AI Act risk classification: confirm it is an AI system, write the intended purpose, check Article 5 bans, check Annex I and Annex III with the Article 6(3) filter, then check Article 50 transparency and record the decision.
Try this yourself Ask someone in sales and someone in support to describe, in one sentence, what a feature is for. If either version differs from the intended purpose you wrote in step two, your classification rests on a purpose you do not describe consistently, and the Commission's draft guidelines say that inconsistency can widen the purpose to include high-risk uses.

Worked Examples of EU AI Act Risk Classification in SaaS Products

These are my reads from the legal text and the Commission's draft examples. They are not legal advice, and borderline cases belong with counsel.

Feature Likely tier Basis
FAQ chatbot on your site answering product questions Transparency Article 50(1) disclosure, unless obvious. Not an Annex III use.
University admissions chatbot giving general information, no personalised recommendations Not high-risk The draft guidelines say such a chatbot does not materially influence admissions decisions
Résumé screening or candidate ranking feature High risk Annex III point 4(a). Scoring candidates is likely profiling, which removes the Article 6(3) exemption.
Job-description generator working from a recruiter's list Exempt, but documented Draft guidelines example, Article 6(3)(a), with Article 6(4) record and registration
Mood scoring of employees on video calls Prohibited Article 5(1)(f), unless intended for medical or safety reasons
Creditworthiness scoring add-on for lenders High risk Annex III point 5(b), fraud detection excepted
AI image generator inside your product Transparency Article 50(2) marking. From 2 Dec 2026, the new Article 5 bans also apply if it can reproducibly produce banned imagery without safeguards.
Spam filter for inbound support tickets Minimal The Commission names spam filters as minimal risk

EU AI Act Risk Classification Mistakes That Change the Answer

  • Classifying by technology. "It is just an LLM" is not an answer. The tier follows intended purpose and the people affected.
  • Treating human review as an exemption. The draft guidelines say adding a human requirement does not take a system out of Annex III.
  • Forgetting the profiling override. A system can meet an Article 6(3) condition and still be high-risk because it profiles people.
  • Claiming Article 6(3) without the record. The exemption comes with a documented assessment and an EU database registration.
  • Letting marketing widen the purpose. Demos, case studies, and sales decks count as much as the terms of service.
  • Classifying once. Changing a feature's purpose, or modifying a system, can move it up a tier, and the Commission can amend Annex III over time.
  • Planning against the old date. The 2 August 2026 high-risk deadline was replaced on 27 July 2026. Bans and transparency duties were not moved.

ISO 42001 and EU AI Act Risk Classification: Where a Management System Helps

ISO 42001 is a voluntary, certifiable standard for an AI management system. The EU AI Act is law. Certifying against the standard does not place a system in a tier, and it does not make a system compliant.

What it does give you is a structure for the work around classification: documented AI risk assessment, impact assessment, and defined roles. A classification register with owners, evidence, and re-check triggers fits naturally into that.

We list ISO 42001 and NIST AI RMF among the frameworks ComplyJet supports, and the EU AI Act appears in our framework list too. We do not classify your systems for you, and we do not give legal advice. Deciding whether something is high-risk is a question for counsel.

If you want the standard itself, see our ISO 42001 guide and the ISO 42001 certification cost breakdown.

Free demo
Want a second pair of eyes on your AI compliance roadmap?
Book a walkthrough and see how ComplyJet handles ISO 42001 and the frameworks your EU customers already ask about, at flat per-company pricing.
Book a demo

FAQs

What Are the Four EU AI Act Risk Categories?

Unacceptable risk (banned practices under Article 5), high risk (Annex I and Annex III systems under Article 6), transparency or limited risk (Article 50 duties), and minimal risk (everything else). The tiers attach to a system's intended use, and general-purpose AI models have a separate regime.

How Do I Know If My AI System Is High-Risk Under the EU AI Act?

Check whether its intended purpose matches an Annex III use case, such as recruitment, credit scoring, or education assessment, or whether it is a safety component of an Annex I product that needs third-party assessment. If it matches Annex III, test the Article 6(3) exemption and the profiling override, then document the result.

What AI Practices Are Banned Under the EU AI Act?

Article 5 bans harmful manipulation, exploiting vulnerabilities, social scoring, criminal-offence prediction based solely on profiling, untargeted facial-image scraping, emotion inference at work and school, sensitive biometric categorisation, and most real-time remote biometric identification by law enforcement. Two new bans on intimate-imagery and child-abuse-material generation apply from 2 December 2026.

What Is the Article 6(3) Exemption in EU AI Act Risk Classification?

It lets a provider conclude that an Annex III system is not high-risk if it does not materially influence decisions and meets one of four conditions: narrow procedural task, improving completed human work, detecting decision patterns, or a preparatory task. It never applies to profiling, and the provider must document the assessment and register the system.

Is a Chatbot High-Risk Under the EU AI Act?

Usually not on its own. A chatbot normally owes Article 50(1) disclosure. It becomes high-risk if its intended purpose falls into Annex III, for example evaluating job candidates. The Commission's draft guidelines treat a university chatbot that gives only general admissions information as not materially influencing decisions.

What Is Limited Risk Under the EU AI Act?

It is the common name for the transparency tier. The Regulation does not use it as a statutory category. Article 50 attaches disclosure and content-marking duties to chatbots, synthetic content, emotion recognition, and deepfakes, and those duties have applied since 2 August 2026.

Where Does General Purpose AI Fit in EU AI Act Risk Classification?

Models and systems are classified separately. General-purpose AI models have their own obligations since 2 August 2025, with a systemic-risk presumption above 10^25 training FLOPs. The product you build on a model is classified on its own intended purpose, which is why consistent positioning matters.

What Happens If You Misclassify an AI System Under the EU AI Act?

Market surveillance authorities can evaluate the classification and require corrective action. Where a provider misclassified a system to avoid the high-risk requirements, penalties under Article 99 can follow, up to EUR 15 million or 3% of worldwide turnover for operator obligations, with the lower figure for SMEs.

Related Reading

Sources and as-of date: All dates and status statements are as of 30 September 2026.

Operative wording of Articles 3, 5, 6, 50, 51, 99, 113 and Annex III, including the Digital Omnibus amendments, from the consolidated text in the AI Act Explorer, cross-checked against the European Commission's AI Act Service Desk article pages. Milestone dates from the AI Act Service Desk implementation timeline. Publication and entry-into-force dates of Regulation (EU) 2026/1744 from Cooley's July 2026 client alert.

Risk-tier descriptions from the Commission's AI Act overview. Paragraph references to the Commission's draft high-risk classification guidelines (19 May 2026, draft, non-binding). Article 50 guidelines and Code of Practice dates as reported by Jones Day and Paul Weiss.