Minimal risk AI under the EU AI Act

5 min readLast reviewed 28 July 2026
In short

Most AI in everyday use, spam filters, recommendation engines, games, internal automation, falls into the EU AI Act's minimal-risk tier, which carries no mandatory obligations. The one exception: Article 4's AI literacy duty applies to every provider and deployer regardless of risk tier, and classification itself isn't permanent.

Minimal risk AI defined by what it doesn’t require

Minimal risk is the largest of the EU AI Act’s four tiers by volume, and the least understood, because it’s defined mostly by what it doesn’t require rather than what it does. This piece focuses on that one tier in depth, for how it fits alongside the other three, see EU AI Act risk classification: The 4-tier system explained

If an AI system isn’t banned under Article 5, doesn’t fall into one of the eight Annex III high-risk domains or an Annex I regulated product, and doesn’t interact with people in a way that triggers Article 50 transparency duties, it lands here by default. Spam filters, recommendation engines, AI-enabled games, and most internal process automation fit this description. No risk management system, no technical documentation dossier, no conformity assessment, no CE marking. That doesn’t mean an organisation building or using one of these systems has zero obligations under EU law. Generally, GDPR, consumer protection, and product liability rules don’t disappear just because the AI Act stays quiet, and it doesn’t mean the classification is permanent. What follows is what minimal risk actually exempts an organisation from, what it doesn’t, and the one Act-wide obligation that reaches even here.

Getting to minimal risk classification: The process of elimination

QuestionIf yesIf no, check next 
Is the system’s intended use listed as a prohibited practice under Article 5?Prohibited. Stop.Continue 
Is it a safety component of an Annex I regulated product, or listed in Annex III?Likely high-riskContinue 
Does it interact with people in a way they could mistake for human, or generate synthetic content?Limited risk: Article 50 transparency appliesContinue 
None of the above?Minimal risk/ 

What “No compliance work” actually covers

 
ObligationRequired for minimal-risk systems?Where it comes from
Risk management systemNoArticle 9 (high-risk only)
Data governance requirementsNoArticle 10 (high-risk only)
Technical documentation dossierNoArticle 11 (high-risk only)
Automatic loggingNoArticle 12 (high-risk only)
Human oversight designNoArticle 14 (high-risk only)
Conformity assessmentNoArticle 43 (high-risk only)
CE markingNoArticle 48 (high-risk only)
EU database registrationNoArticle 49 (high-risk only)
Fundamental Rights Impact AssessmentNoArticle 27 (specific deployer categories only)

In practice, this is the shortest compliance list on the entire site, because it’s a list of things that simply don’t apply. A team building an internal scheduling tool or a product recommendation engine is not going to find itself drafting Annex IV technical documentation, because that requirement never reaches this tier.

The one obligation that reaches every AI system anyway

Article 4 requires providers and deployers to take measures ensuring a sufficient level of AI literacy among their staff and anyone else operating AI systems on their behalf. Unlike every requirement in the table above, this one is not tied to risk classification at all. It has applied since 2 February 2025, to every provider and deployer, for every kind of AI system, minimal risk included. The Digital Omnibus softened the wording from an obl,igation to “ensure” literacy to “support the development of” it, but the underlying expectation, documented and proportionate training for the people actually working with the system, remains.

In practice, a company running nothing but a minimal-risk recommendation engine still needs to be able to show that the people operating it have a basic, proportionate understanding of what it does and where its limits are. That is a considerably lighter lift than a conformity assessment, but it is not nothing.

What minimal risk classification doesn’t exempt an organisation from

General EU and national law does not pause because the AI Act does not apply. GDPR still governs any personal data the system processes. Consumer protection and product liability rules still apply to whatever the system is embedded in. Sector-specific regulation, financial services rules, employment law, does not care whether the AI Act classifies the tool as minimal risk.

Article 95 also encourages, without requiring, providers and deployers of non-high-risk systems to adopt voluntary codes of conduct, facilitated by the AI Office and the member states, applying some or all of the Chapter III, Section 2 requirements on a voluntary basis. No enforcement consequence attaches to skipping this, but it is worth knowing it exists, particularly for systems that interact with large numbers of people even without crossing into a regulated tier.

Classification is also not a one-time event. If a minimal-risk system is redeployed for an Annex III use case, or substantially modified in a way that changes its risk profile, the classification has to be reassessed. For example, a recommendation engine repurposed to screen job candidates does not carry its old minimal-risk label with it into that new use.

How Deeploy applies to minimal risk systems

The systems that cause the most trouble are rarely the ones classified high-risk from day one. They are the minimal-risk tools that quietly get repurposed into a higher-risk context without anyone updating the classification. Deeploy’s system inventory and monitoring make that drift visible, so a tool’s actual use in production stays matched to the classification it was originally given, rather than the two quietly drifting apart. Deeploy monitors and governs AI systems efficiently in line with the EU AI Act – all oversight in one platform.

Frequently asked questions

Disclaimer

This is general information, not legal advice. Please consult your legal/compliance team to confirm your organisation’s specific obligations. Deeploy supports your governance process; it does not constitute a guarantee of regulatory compliance.

Reading about compliance is step one. Operating it is Deeploy.See how teams use Deeploy to monitor, document and govern their AI against the EU AI Act.
Book a Demo

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one