Minimal-Risk and Out-of-Scope AI — Why “Low Risk” Does Not Mean “No Rules”
Most AI systems deployed by SMEs and developers are minimal-risk. That is the good news. The bad news is that minimal-risk is not the same as no obligation. One requirement applies universally, regardless of risk category: Article 4 AI literacy. It has been in force since 2 February 2025. And if you have misclassified your system, you are exposed to some of the largest fines in the entire regulation.
What minimal-risk actually means
Minimal-risk is the default category. If your AI system is not prohibited under Article 5, not high-risk under Article 6 and Annex III, and not subject to limited-risk transparency obligations under Article 50, it is minimal-risk. Spam filters, recommendation engines, translation tools, code-completion assistants, and analytics dashboards are typical examples. There is no conformity assessment, no FRIA, no EU database registration, no human-oversight officer, no six-month log retention, no CE marking. The single obligation is Article 4: AI literacy for your staff and anyone who operates AI on your behalf.
Article 4: the universal obligation
Article 4 applies to every provider and deployer of an AI system — minimal-risk, high-risk, or anywhere in between. It requires reasonable, proportionate steps to ensure that staff have sufficient AI literacy for their role and the systems they use. A practical three-layer framework: all-staff awareness training (30–60 minutes), role-specific training for those who regularly use AI tools, and specialist training for procurement, legal, compliance, and technical leads. Calibrated hours: 4–8 hours for micro-enterprises, 20–40 hours for SMEs, 100–300 hours for large enterprises. Document who attended, what was covered, and when. The standard is proportionality and documented effort — not a specific exam or certification.
Out-of-scope: narrower than you think
Out-of-scope means genuinely outside the AI Act — not even Article 4 applies. The Article 2 exclusions are: military and national security (Article 2(3)), scientific research not placed on the market (Article 2(6)), personal non-professional use (Article 2(10)), and qualifying open-source AI (Article 2(12)). Each exclusion applies to specific deployment contexts. A commercial product with an open-source component is not excluded. A research system used to generate client reports is not excluded. Evaluate the exclusion system by system, deployment by deployment.
The misclassification risk
The most dangerous assumption is that minimal-risk means you have done the classification work. Common errors: an internal HR screening tool is high-risk under Annex III (employment domain) regardless of being internal; an open-source component integrated into a credit-scoring product is not excluded from provider obligations; a customer-service chatbot classified as minimal-risk may still trigger Article 50 transparency obligations. Misclassifying a high-risk system as minimal-risk carries fines of up to €15 million or 3% of global annual turnover. Misclassifying a prohibited system carries fines of up to €35 million or 7%. A documented six-step classification exercise — ruling out prohibited, high-risk, and limited-risk in sequence — is the only reliable defence.
What’s in the full chapter
The full chapter covers the three-layer Article 4 training framework with calibrated hours by organisation size, a detailed breakdown of all Article 2 out-of-scope exclusions, four misclassification scenarios with penalty exposure, the six-step classification verification sequence, and a 9-item self-check for every system you classify as minimal-risk or out-of-scope.
Read the Full Chapter
Get the complete Chapter 10 with training frameworks, misclassification scenarios, and the 9-item self-check.
Read the Full Chapter Check Your AI Risk Level — Free