← All guides
Guide · Governance & Law

EU AI Act for Companies: Which Risk Class Applies to Your System — and What Needs to Happen by When?

Last reviewed: 23 July 2026

The AI Act doesn't classify AI systems by model, but by purpose: the same foundation model can be minimal-risk in one use case and high-risk in the next. Four classes determine the obligations: prohibited, high-risk, limited-risk, minimal-risk. The costliest misconception for companies: AI-powered recruiting is almost always high-risk — even if it feels like just an add-on feature in existing applicant software.

Which four risk classes does the AI Act distinguish?

The classification depends on purpose, not model: the same foundation model can be minimal-risk in one use case and high-risk in the next. The class is thus a property of the specific application — not the technology behind it. Most enterprise use cases fall into the two middle classes.

Prohibited

Art. 5 — since February 2025

Social scoring, manipulative systems, real-time biometric surveillance in public spaces. Absolute ban, no exceptions.

High-risk

Annex III

Applicant screening, performance evaluation, credit scoring, predictive policing. Conformity assessment, documentation, human oversight, registration.

Limited-risk

Art. 50 — labeling requirement

Chatbots, AI-generated content, emotion recognition. Users must know they are interacting with an AI.

Minimal-risk

The vast majority of systems

AI-powered search, spam filters, recommendation systems, simple automation. No AI Act obligations, but GDPR still applies.

By when does my system need to meet the requirements?

The deadlines are staggered, not a single cutoff: bans and transparency duties have long applied, general-purpose AI obligations since August 2025. The big shift affects high-risk Annex III systems — their obligations were pushed back 16 months to December 2027 by the Digital Omnibus, while labeling and transparency duties still kick in earlier, unchanged.

Feb 2, 2025

Prohibited practices take effect: Art. 5 (social scoring, manipulative systems, etc.) and AI literacy obligations (Art. 4) apply from this date.

Aug 2, 2025

Obligations for general-purpose AI: foundation model provider duties, governance structures, and the fine regime take effect.

Aug 2, 2026

Transparency & registration duties: general information and registration obligations for AI systems become applicable.

Dec 2, 2026

Labeling requirement for AI content: Art. 50(2) (labeling of AI-generated content) becomes applicable.

Dec 2, 2027

High-risk systems (Annex III) — postponed: new deadline via the Digital Omnibus (agreement May 7, 2026) — 16 months later than originally planned. Substantive obligations (Art. 6–27) unchanged.

Aug 2, 2028

High-risk as a safety component (Annex I): AI as a safety component in already-regulated products (e.g. machinery, medical devices) — its own, later deadline.

What exactly did the Digital Omnibus change?

The Digital Omnibus only shifts deadlines, not the substantive requirements. Reason: harmonized standards for companies to follow were not available before the end of 2026 — the EU didn't want to impose an obligation without a reliable benchmark, but deliberately chose not to water down the content itself.

Important: no framework replaces another. GDPR, the voluntary GPAI Code of Practice (with "safe harbor" effect), and the ISO/IEC 42001 certification standard all apply in parallel and cumulatively with the AI Act — focusing on just one deadline means missing the other three. Waiting through 2026 also wastes lead time: risk management and documentation can be built up independent of the exact deadline.

Anti-pattern

The misconception I encounter most often in projects: HR AI is almost always high-risk. Annex III point 4 explicitly names employment and workforce management — including AI-powered candidate screening, promotion decisions, and performance evaluation. Activating AI recruiting features in existing HR software very likely makes you a high-risk deployer. That classification belongs checked before go-live, not after.

Glossary

High-Risk AIConformity AssessmentAnnex IIIGPAI

Know where you stand in 10 minutes

The Compliance Center maps your system to the four risk classes and shows the concrete obligations and deadlines that apply.

Open the EU AI Act Compliance Tool →

FAQ

Does the new deadline (December 2027) also apply to systems already in operation?

Yes — the postponement applies to all Annex III systems regardless of whether they're newly introduced or already in use. Companies that are already prepared don't need to wait for the deadline and can become compliant earlier.

Is AI-powered recruiting automatically high-risk?

In the vast majority of cases, yes. Annex III explicitly names employment and workforce management as a high-risk area — including AI add-on features in existing HR software like applicant screening. The classification belongs checked before rollout, not after.

Does the AI Act affect me outside the EU too?

Yes, if your system's output is used in the EU (market-location principle) — regardless of where the provider or deployer is based.

Is the 2027 deadline enough reason to do nothing yet?

Technically yes, practically no: conformity assessment, risk management, and documentation need several months of lead time for more complex systems — the extended deadline is a buffer, not a free pass.

DO

Daniel Ostner

From Chapter 4 of the Enterprise AI Guide book

View book →

Related guides