Skip to content
Beyond Prompt AI Studio
The EU AI Act in Practice

The Risk Pyramid in Detail: Where the AI Act Actually Applies

“Where do we actually stand?” is the first question every company has to answer about the EU AI Act – and the one most rarely answered with concrete categories instead of a vague gut feeling. This module replaces the gut feeling with the actual list: what's really prohibited, what really counts as high-risk, and an exercise to honestly classify your own tools.

Wider = more applications typically land here

Tap a level to see the real categories.

Four reality checks – worth remembering

One principle, four tiers

If you already know the module “The EU AI Act – what actually affects your business”: the principle stays the same – four tiers (prohibited, high-risk, limited, minimal), staggered by the risk a given AI system poses. What that module deliberately kept brief, this one goes deep on: the actual categories behind “prohibited” and “high-risk” – because those details decide whether a specific tool in your company is actually affected.

The prohibited practices (Art. 5) – the narrow top of the pyramid

At the very top of the pyramid sits a short, exhaustive list of practices that are banned outright – this is also where the much-cited fines of up to €35 million or 7% of global annual turnover apply. The list is deliberately narrow:

  • Social scoring by public authorities – evaluating people by their social behaviour with detrimental effects in unrelated contexts.
  • Manipulative or deceptive systems that deliberately exploit vulnerabilities of specific groups (age, disability, economic hardship) to distort decisions.
  • Real-time remote biometric identification in public spaces – with narrow, legally defined exceptions for law enforcement in serious crimes.
  • Emotion recognition in the workplace and in educational institutions – prohibited outright since 2 February 2025 (with narrow medical/safety exceptions).
  • Untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases.
  • Biometric categorisation that infers sensitive traits such as race, political opinion, or sexual orientation.
  • Predictive policing that bases a crime prediction for an individual solely on profiling, without objective, verifiable facts.

The Annex III list: what actually counts as high-risk

One tier down sits the high-risk category – noticeably larger than the prohibited practices, but still an exhaustive, concrete list of use areas, not an open-ended catch-all:

  • Biometric identification and categorisation of people.
  • Operation of critical infrastructure (energy, water, transport, digital infrastructure).
  • Education: access to educational institutions and assessment of learning outcomes.
  • Employment: candidate selection, promotion decisions, monitoring and evaluating employee performance.
  • Access to essential private and public services: creditworthiness assessment, insurance risk assessment, social benefits.
  • Law enforcement, where not already prohibited under Art. 5.
  • Migration, asylum, and border control management.
  • Administration of justice and democratic processes, e.g. supporting judicial decision-making.

The employment category catches more companies than most expect

The most commonly overlooked point on this list: “employment” doesn't end at candidate screening. An AI system that monitors or evaluates employee performance – say, a tool that measures productivity, analyses behaviour, or feeds into promotion decisions – falls into the same high-risk category as a hiring filter, structurally. Assuming “we only use this internally for our own team” is automatically low-stakes confuses who the rule targets with where it applies.

Why most applications still land at the bottom

Despite these lists, the core insight from the basics module still holds: an internal chat assistant for research, a standard website chatbot, an email-sorting automation – all of that almost always lands in the bottom two tiers (limited or minimal risk), because none of it matches the categories above. The lists don't exist to capture every use of AI, but to regulate a few, clearly defined high-risk areas – everything else stays deliberately lightly regulated.

Practice section: your own inventory in three questions

The practical value of this module isn't memorising the lists – it's applying them to your own tools. For every AI system in use, three questions help, in this order: first, does the purpose match one of the seven Art. 5 practices above – if so, stop immediately and get legal input. Second, does the purpose fall under one of the eight Annex III categories – if so, a closer review is needed (role, obligations, possibly an impact assessment), no panic, but no ignoring it either. Third, is it “just” a chatbot or a system generating content – then usually only a modest labelling duty applies. If the answer to both is no, that confirms minimal risk – written down, not just assumed, so the inventory is demonstrable if ever questioned. This classification doesn't replace case-by-case legal advice – when in doubt, especially on a possible high-risk match, bring in a specialist.

The key points

  • The prohibited practices (Art. 5) are a short, exhaustive list of seven items – this is where the €35 million fines sit, but they practically never touch normal business AI use.
  • The high-risk list (Annex III) covers eight concrete use areas, not an open-ended catch-all – from biometrics to critical infrastructure to employment.
  • The most overlooked category: “employment” also covers internal employee-monitoring and evaluation tools, not just candidate screening.
  • Normal SME use – chat assistants, standard chatbots, internal automation – almost always lands in the bottom two tiers.
  • The practical inventory runs in three steps: check against Art. 5, check against Annex III, document the rest as minimal risk – this doesn't replace case-by-case legal advice.

The EU AI Act: what companies really need to know – and what's just panic

Quick check: did it sink in?

1 / 3

What exactly is Art. 5 of the EU AI Act?

Want to know what the EU AI Act means for you personally?