The four bands of the EU AI Act explained
There are four tiers under the act. And after 2nd August 2026, ‘we didn’t know’ won’t save you from a hefty fine if you’re non-compliant.
A business’s AI usage will fall into one or multiple of these categories, depending on what the system does:
Band 1: Prohibited risk

What is prohibited risk in the EU AI Act, and what are examples of it?
These are practices that the EU has decided are simply too harmful to allow and are banned outright, regardless of safeguards. These include but are not limited to:
-
Social scoring systems that ranks or judges people based on behaviour or characteristics, used by public or private actors. (Note: this is not to be confused with a lead scoring system.)
-
AI that uses manipulative or deceptive techniques to distort someone’s decision-making in a way that causes harm.
-
AI that exploits vulnerabilities related to age, disability, or socio-economic situation.
-
Emotion recognition in workplaces or educational institutions, with few medical and safety exceptions.
-
Real-time remote biometric identification by law enforcement in public settings
If a business is caught in this band, they will be fined up to 7% of their global annual turnover or €35 million, whichever is higher.
For most businesses, however, this tier will not be an issue.
Four ways your business can avoid prohibited risk
Here’s four ways you can make sure your business is nowhere near this band:
-
Audit any AI used for scoring, ranking, or profiling people, make sure it's tied to a specific, relevant purpose (like lead scoring), not a general trustworthiness judgement.
-
Avoid AI tools that target people's emotions, vulnerabilities, or decision-making in ways that could be seen as manipulative, even in marketing.
-
If you use any emotion-recognition or biometric tools in the workplace, check whether they fall under the narrow medical/safety exceptions, or remove them.
-
When in doubt, ask: "could this practice unfairly disadvantage someone based on who they are, not what they've done?" If yes, stop and review.
Band 2: High risk

What are high-risk systems in the EU AI Act, and what are some practical examples?
These are systems that are allowed, but only under strict controls, because of the risk they pose to people's rights and safety. They include but are not limited to:
-
CV-screening and recruitment tools that decide who gets shortlisted for a job.
-
Credit-scoring and lending systems that affect someone's access to finance.
-
Biometric identification systems, such as facial recognition used for ID verification.
-
AI used in critical infrastructure such as energy, water, or transport networks.
Businesses providing these systems must prove the tool is safe before it goes to market and continue to prove it throughout the AI’s life through conformity assessments, documentation, and registration in an EU database.
If a business is caught being non-compliant here, they will be fined up to 3% of their global annual turnover or €15 million, whichever is higher.
For most businesses, this tier is also unlikely to apply unless you're building or using tools that fall into categories like those above.
How to stay compliant within the EU AI Act using high-risk tools
Depending on whether you’re a provider or a user of these systems, how you stay compliant will look a little different.
As a rule of thumb:
-
Identify whether any tool you use or provide falls into a high-risk category (hiring, credit, biometric ID, critical infrastructure).
-
If you're a provider, budget time and resources for conformity assessment, documentation, and EU database registration well before 2 August 2026.
-
If you're a deployer, assign a named, trained person responsible for oversight. Don't leave it undefined.
If you’re a business using these systems, you’ll be audited too. From 2nd August 2026, you’ll have to:
-
Follow the provider's instructions.
-
Assign a trained person to oversee the system.
-
Keep clear usage logs on file, not just in your inbox.
-
Be able to step in or shut the programme down if something goes wrong.
Unsure which band your business’s AI usage will fall under? Download your free EU AI Act compliance checklist now to understand where your gaps are, not just whether you’ve got any.
Band 3: Low risk

What is defined as 'low risk' under the EU AI Act?
This is the band that's less about what your AI does and more about how honest you are with your audience, or regulators once you’re audited. It covers situations like:
-
AI that talks directly to people (chatbots, virtual assistants) must say it's AI upfront.
-
AI-generated content (text, image, audio, video) must be detectable as AI-generated.
-
Emotion recognition or biometric categorisation must be disclosed to the people it's used on.
Unlike Bands 1 and 2, this is the tier that most ordinary businesses using AI content tools or chatbots will fall into.
If a business is caught being non-compliant here, they will be fined up to 3% of their global annual turnover or €15 million, whichever is higher.
How to stay compliant in Band 3
Here's four ways you can make sure you're actually disclosing AI use where it's needed:
-
Make sure any chatbot or virtual assistant tells people it's AI at the very start of the conversation.
-
Label any AI-generated image, audio or video that could pass as real. There are no exceptions for this one.
-
For AI-written content published to inform the public on a public interest matter, either disclose it's AI-generated or make sure it's been through genuine human review with someone accountable for the final version.
-
If you’re using emotion recognition or biometric categorisation, tell the people it’s being used on.
However, it’s important to be honest with your audience and label content as AI-generated rather than risk non-compliance in the future.
Band 4: No risk

How does the EU AI Act define ‘no risk’?
This is where the majority of everyday AI use sits. These are the tools that pose little to no risk to people's rights or safety, and the EU AI Act largely leaves them alone.
Examples include but are not limited to:
-
Spam filters and email categorisation.
-
AI-powered recommendation engines, like "you might also like" suggestions.
-
AI-enabled video games and generative art tools used for entertainment.
-
Most everyday productivity tools with AI features built in.
There's no conformity assessment, no registration, and no oversight requirement for tools in this category, and therefore, no fine. The main obligation that still applies across the board, including here, is AI literacy, making sure the people in your business who use AI tools understand what they can and can't do.
If most of what your team uses day to day looks like the list above, take this as the reassurance it's meant to be: you're not sitting on a hidden compliance risk here.
How to keep your business at no risk under the EU AI Act
Here's how to make sure your business sits at band four and close the gap that could turn "no risk" into a real problem.
-
Keep a simple internal list of what AI tools are approved for use, and which devices they're approved on.
-
Build basic AI literacy into onboarding, even a short internal guide on what your team's AI tools can and can't do.
-
Revisit the list periodically; tools move between tiers as features change, so "low risk" today isn't guaranteed forever.
That said, if your company allows AI use on work devices, but hasn't extended that policy to cover personal devices, or if an administrator has explicitly restricted certain tools, that boundary must be made clear and monitored. Employees using AI on personal devices to get around a company restriction puts usage outside any oversight your business has put in place, which means nobody can vouch for what data's gone in, what's come out, or where it's ended up.
Honestly? It’s not really an EU AI Act issue at that point. It's a wider data governance and accountability gap. But it's the kind of thing that turns a low-risk tool into a serious business risk (usually without anyone noticing until something's already gone wrong.)
Think your business falls under no risk? The first mistake is assuming you’re compliant. Make sure your business is safe by downloading a free copy of the EU AI Act compliance checklist now.

Does the EU AI Act apply to the UK?
Although the UK is no longer in the European Union, and therefore the act doesn’t automatically apply, your business may still be audited under the EU AI Act.
The Act follows AI output, not the postcode of where your business is registered.
This means that the Act is automatically applied based on whether your content or AI systems respectively reach an EU audience, not where your company is based.
Ask yourself:
-
Do you have EU-based customers, clients, or website visitors?
-
Do you sell into EU markets?
-
Is your content, including AI assisted, published somewhere an EU audience can see it and be influenced?
If you’re a genuine UK-only business with little EU reach, you’re significantly lower risk.
But if you’ve answered yes to any of these questions, being based in the UK does not make you automatically exempt from the EU AI Act.
Does this logic sound familiar? It should.
It’s the same reach GDPR already has. So, if your business has done any hefty GDPR work in the past, you’ll recognise the shape of this immediately. As a UK company, you can’t opt out of the EU data protection law just because you’re not physically in the EU.
The same principle is applied to the EU AI Act.
However, even if your business is not affected, it’s worth playing the long game and making sure still covered.
The UK has a track record of following the EU’s lead on these kinds of regulation, the UK’s GDPR regulations being a prime example of this, as it arrived a few years after the EU’s version and looked incredibly similar.
Getting ahead of this compliance now isn’t just making sure you’re safe for the EU AI Act from 2nd August 2026, it’s about not having to scramble to retrofit everything under a deadline in a few years’ time, when the UK almost inevitably introduces its own version.
How to make sure you’re compliant with the EU AI Act
Now you understand what the EU AI Act is and how to stay compliant, how can you easily know where you stand?
The fastest way to check is to run through all your AI usage properly, rather than just go through all the obligations in your head.
To help you audit your business, we’ve created a free, easy-to-use compliance checklist. It’s built for a proper, repeatable self-audit that covers:
-
Your business’ exposure
-
AI touchpoints
-
Your review process
It helps you see where the gaps are in your business, not whether you’ve got any.
One more thing worth noting: regardless of which band your AI use falls into, giving false or incomplete information to a regulator during an investigation carries its own fine, up to €7.5 million or 1% of global turnover.
If you're ever contacted by a regulator, respond honestly, hand over documentation when asked, and correct your paperwork if it's wrong rather than defending it. It's a fine that's entirely avoidable just by being straightforward.
To avoid an unnecessary fine, it’s vital to understand where you are now, so you can improve usage and stay ahead of the EU AI Act, or whatever comes next.
Free download: EU AI Act Compliance Checklist
Most agencies and marketing teams are closer to compliance than they think, but "probably fine" isn't the same as knowing.
Our free checklist walks you through your exposure, your AI touchpoints, your disclosure practices, and your review process, so you know exactly where you stand before it becomes a live issue.
Download your copy today.
