Skip to content

Regulation

How the EU AI Act's Risk Classification Maps to Legal AI Use Cases

By Editorial TeamPublished Jul 23, 2026
Effective date
Aug 2, 2026

For any legal department deploying or procuring AI tools, the single most consequential decision under the EU AI Act is not how to comply with high-risk obligations — it is whether those obligations apply at all. Misclassification cascades in both directions: classifying a high-risk system as minimal-risk exposes the organization to fines of up to €15 million or 3% of global annual turnover for non-compliance with Chapter 2 obligations; classifying a minimal-risk system as high-risk wastes resources on risk management systems, technical documentation, and conformity assessments that the regulation does not require.

This guide is designed for general counsel, heads of legal operations, compliance officers, and law firm managing partners who need to map their specific AI use cases — contract analysis, document review, legal research, litigation prediction, client risk scoring, administration of justice tools — to the correct EU AI Act risk tier. It is not a general overview of the regulation. It is a systematic classification exercise, with particular depth on the contested Annex III Category 8 (administration of justice) gray zone, the Article 6(3) exception pathway, and the profiling trap that automatically elevates any system to high-risk.

The EU AI Act classifies AI systems into four tiers based on the risk they pose to health, safety, and fundamental rights. Understanding this framework is a prerequisite for any classification exercise.

EU AI Act four-tier risk framework with obligations and penalties
Risk TierRegulatory TreatmentKey ObligationsMaximum Fine (Art. 99)
Unacceptable riskProhibitedNone — systems are banned outright (Art. 5)€35M or 7% of global annual turnover
High-riskRegulatedRisk management, data governance, technical documentation, human oversight, conformity assessment (Chapter 2)€15M or 3% of global annual turnover
Limited riskTransparency obligationsDisclosure that content is AI-generated (Art. 50)€15M or 3% of global annual turnover
Minimal riskUnregulated (except Art. 4)AI literacy obligation only (Art. 4, enforceable since Feb 2025)€7.5M or 1% for supplying false information

Operationalizing workflow

No workflow has been explicitly linked to this obligation yet. See Workflows generally.

Illustrative cases

No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.

← Back to Regulation

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →