← All lessons
Level 2 · Emerging8 min read

Risk classification: prohibited, high-risk, limited, minimal

Once you know what you use, sort it by how much harm it could do. The EU AI Act's four tiers are the clearest model, and the US and Canadian rules map onto them well enough to use one scheme for everything.

The EU's four tiers

  • Prohibited (Article 5): banned outright since 2 February 2025. Examples: social scoring by public bodies, manipulative techniques that cause significant harm, exploiting vulnerabilities of age or disability, emotion recognition in workplaces and schools (with narrow exceptions), untargeted scraping of faces from the internet or CCTV to build recognition databases, and, from 2 December 2026 under the Digital Omnibus, generating non-consensual intimate imagery.
  • High-risk (Article 6 and Annex III): AI used for biometric identification, critical infrastructure, education and exam scoring, hiring, promotion and worker management, access to essential services such as credit, insurance and public benefits, law enforcement, migration, and justice. Also AI that is a safety component in regulated products (Annex I). Obligations include risk management, data governance, documentation, logging, human oversight, accuracy and robustness, and for deployers a fundamental-rights impact assessment in some cases. Stand-alone high-risk duties apply from 2 December 2027; Annex I product duties from 2 August 2028.
  • Limited risk (Article 50): chatbots, emotion-recognition and biometric categorisation, deepfakes and synthetic content. The duty is transparency: tell people, label content. Applies since 2 August 2026.
  • Minimal risk: spam filters, inventory forecasting, code assistants. No specific AI Act duties beyond ordinary law.

The US and Canadian equivalents

  • Colorado SB 26-189 regulates "automated decision-making technology" used in "consequential decisions" about education, employment, housing, financial services, insurance, healthcare and government benefits. That list is almost identical to the EU's Annex III. Obligations start 1 January 2027.
  • Texas TRAIGA has a short prohibited list (AI intended to incite self-harm, to discriminate unlawfully, to produce child sexual abuse material or certain deepfakes, and government social scoring or biometric identification without consent) and otherwise relies on existing law.
  • Illinois HB 3773 and NYC Local Law 144 treat hiring and promotion tools as the sensitive category, matching the EU's employment heading.
  • Utah's AI Policy Act singles out "high-risk" consumer interactions (health, financial, legal advice; biometric or sensitive data) for disclosure.
  • Canada's Directive on Automated Decision-Making scores federal systems on four impact levels (I to IV) based on the reversibility and duration of the decision's effect on rights, health, economic interests and the environment. Level III and IV systems need human intervention and peer review.

A practical scoring rubric

For each inventory entry ask:

  • Does it decide, or materially shape, a decision about a person's job, money, housing, health, education, or legal status? If yes: treat as high-risk / consequential.
  • Does it interact directly with people or generate content they might mistake for human or real? If yes: transparency tier at minimum.
  • Does it touch any prohibited practice? If yes: stop and get legal advice.
  • Otherwise: minimal, but keep it in the inventory.

Record the tier, the reasoning, and the date. Classification is a judgement call and the law will ask you to show your reasoning, not just the label.

The case that shows the top tier

Clearview AI's face database was built by scraping the open web. Under the AI Act that is now a prohibited practice; under the GDPR it drew fines totalling more than EUR 90 million across five European regulators. Deployers were warned they could be fined for using it.

What this means for you

Add a 'risk tier' column to your inventory and fill it using the four questions above. Anything you mark high-risk or consequential becomes the focus of the Level 3 lessons on oversight, fairness, vendors and records. Write one sentence of reasoning per entry; it will be worth a lot in an audit.

Real case

Fine2024 · EU

Clearview AI — EUR 90 million-plus in GDPR fines across Europe

Fines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.

Read the case →

Related laws

Quick check · 3 questions

  1. 1.A tool ranks job applicants for recruiters. Under the EU AI Act, which tier is it?

  2. 2.Which of these is a prohibited practice under Article 5 of the EU AI Act?

  3. 3.How does Canada's Directive on Automated Decision-Making sort systems?

0 of 3 answered

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.