Picture a normal Tuesday afternoon and three tools your company already runs: a Slackbot that answers staff questions, a CRM feature that scores which leads sales should call first, and an ATS plugin that ranks job applicants' CVs. Same building, same IT budget — and three completely different positions under the EU AI Act. One is a transparency duty. One is arguably high-risk. One is probably nothing at all.
The regulation itself sorts them in Annex-speak: Annex III listings, Article 50 obligations, deployer-versus-provider distinctions. Useful to lawyers. Useless to an MD trying to work out whether the hiring tool needs paperwork. What follows is the working translation: a decision shortcut you can apply to a Slackbot, a lead-scoring feature and a CV-screening tool in the same afternoon. It sits within our full guide to the EU AI Act for UK and Irish businesses — start there if you're new, then come back to sort your stack.
The four categories in one screen
Category 1 · Article 5
Prohibited (unacceptable risk)
Banned outright in the EU — social scoring, manipulative systems, emotion inference at work. Using one isn't a compliance project; it's an exit project. Rare territory for B2B SMEs.
Category 2 · Article 6 + Annex III
High-risk
Legal to use, but attached to real obligations: documentation, logging, human oversight, incident reporting. Think hiring, credit and worker evaluation. This is where the paperwork lives.
Category 3 · Article 50
Limited risk (transparency)
People must know they're dealing with AI — chatbots disclose, synthetic content is marked. Cheap to comply with. Embarrassing to be caught skipping.
Category 4
Minimal risk
Spam filters, forecasting, code copilots, most internal productivity AI. No specific new obligations beyond AI literacy for staff. The calm zone — and bigger than you think.
Here's the frame that matters: most business AI lands in the bottom two — but you don't get to assume that, you get to prove it. "It's just a chatbot" is a guess. A row in an inventory that says limited risk, transparency duty met is an answer. The difference between the two is what the rest of this article gives you.
The 10-second sorting questions
Before the detail, the triage. Ask these in order — the first one that bites sets the category:
- Does it manipulate, socially score, or infer emotions in ways the Act bans? Subliminal techniques, scoring people against unrelated behaviour, emotion inference at work or in education → Prohibited. Rare for B2B SMEs — but check what your vendors embed.
- Is it used for a regulated purpose listed in Annex III? HR and hiring (CV screening, candidate ranking), credit scoring, worker monitoring and evaluation, biometrics, education access, critical-infrastructure decisions — or is it a safety component of a product → High-risk.
- Does it interact with people without them realising it's AI? Customer chatbots, generated content, synthetic voice or images → Limited risk. The fix is disclosure, not paperwork.
- Everything else. Spam filters, demand forecasting, code copilots, meeting summarisers, most internal productivity AI → Minimal risk. Literacy obligations only.
Bookmark this section. Applied to a list of tools, it's two minutes per tool — and it converts an anxious "are we compliant?" into a tagged spreadsheet and a shortlist of things that need a closer look.
Prohibited: the short list
Article 5 bans a specific set of practices outright. In business terms: social scoring (ranking people by behaviour unrelated to the decision at hand), manipulative or subliminal techniques that cause real harm, untargeted scraping of facial images, emotion inference in workplaces and schools, and certain forms of predictive policing. Since February 2025, using these in the EU market isn't a fineable offence waiting to be fixed — it's simply not allowed.
You're almost certainly not here. B2B SMEs don't build social-scoring engines. The realistic exposure is accidental: a feature embedded in something you bought. An engagement-analytics tool that claims to read employee sentiment from message tone is flirting with emotion inference. This is why vendor due-diligence matters even in the calm zone — you inherit the compliance position of what you deploy, banned features included.
High-risk: where the paperwork lives
High-risk doesn't mean dangerous or futuristic. It means the tool makes or shapes consequential decisions about people — their jobs, their money, their access to opportunities. Annex III lists the regulated purposes; in business language the ones that actually catch SMEs are:
- Hiring and HR — CV screening, candidate ranking, promotion-adjacent analytics.
- Credit — creditworthiness scoring, beyond basic fraud checks.
- Workers — monitoring and evaluating performance or behaviour.
- Biometrics, education access, and critical-infrastructure decisions — less common in SME stacks, same class.
Now the reframe that saves SMEs from panic: you're usually the deployer, not the provider. The vendor who built the CV-ranking algorithm carries the heaviest duties — risk management, technical documentation, model quality. Your duties as the deployer are real but lighter: get the documentation from the vendor, keep the logs it generates, ensure meaningful human oversight (a human who actually reviews flagged candidates, not a rubber stamp), train your staff under Article 4 literacy, and report serious incidents. The bottom line: what getting it wrong costs scales with risk class, and the obligations bite on a schedule — so start by building an AI inventory that shows which tools carry these duties.
Limited risk: the transparency layer
Article 50 is the honesty clause. If a customer interacts with your AI, they must be told it's AI. Your support chatbot opens with a disclosure. Synthetic content you publish — generated images, cloned voice, AI-written copy where it matters — gets marked. Deepfake-adjacent media gets labelled as such.
Compliance cost: a sentence in your chat widget's greeting and a workflow step in your content pipeline. Non-compliance cost: low in euros, real in reputation. The fastest way to burn trust in 2026 is a customer discovering your "support agent Sarah" is a language model. If you do one thing this week, make it this — it's the cheapest risk class to close.
Minimal risk: the calm zone
Most current business AI lives here. Spam filters. Demand forecasting. Code copilots. Meeting summaries. Grammar tools. The AI features quietly arriving inside SaaS you already pay for. The Act imposes no specific new obligations on these beyond Article 4 — ensuring your staff are competent users of the AI they use, in force since February 2025.
Two mistakes to avoid in the calm zone. The first is over-complying — running a governance programme over your spam filter because a consultant scared someone. Don't. The second is assuming — treating "probably minimal" as the classification without a line of documentation to back it. The discipline that resolves both is the same: a register that says, per tool, this is what it does, this is why it's minimal. That's exactly what an AI inventory gives you.
How to actually sort your stack this week
Three steps, sized for a 20–250 person business:
- List your tools. Spend records plus a short anonymous team survey — the method in the AI inventory guide surfaces the shadow list, which is always longer than the official one.
- Tag each tool with the four sorting questions above. Most will fall to minimal in under a minute. Log the category and the reason — the reason is the part that survives an information request.
- Flag anything touching hiring, credit or worker evaluation. Those get a closer look: what exactly does the tool decide, what does the vendor's documentation say, who provides human oversight. That's your high-risk shortlist — short, but load-bearing.
By the end of the week you hold a sorted register: four categories, each tool tagged and justified. That's the artefact an information request asks for, a customer's procurement team probes for, and your own board should want to see. Not sure your sort is right? Take the AI Act quiz — two minutes, six questions, and it flags exactly where the gaps in a setup like yours tend to hide.
The ladder from there is the same one the rest of this cluster climbs: quiz → Exposure Assessment → a conversation about AI Act Readiness for firms that want the full map. But the sorting itself? One afternoon, one spreadsheet, no platform. In compliance terms, that's about as good as ROI gets.