AI Guide

Minimal-Risk AI System (EU AI Act): The no-obligation tier for everyday business AI

A minimal-risk AI system is an artificial intelligence system under the EU AI Act that falls outside the prohibited, high-risk, and limited-risk tiers, covering everyday tools such as spam filters, AI-enabled video games, and inventory management software. The regulation imposes no mandatory obligations on this tier, only voluntary codes of conduct, because the European Commission estimates it covers the vast majority of AI systems actually deployed in the EU. Learn below what qualifies as minimal-risk, how it contrasts with the Act's other three tiers, and why most everyday business AI stays here.

Key Facts
  • Minimal-risk AI systems carry no mandatory EU AI Act obligations, only the voluntary codes of conduct encouraged under Article 95.
  • The European Commission states that minimal-risk systems, such as spam filters and AI-enabled video games, make up the vast majority of AI systems currently used in the EU.
  • Minimal-risk is the lowest of four EU AI Act risk tiers, below limited-risk, high-risk, and prohibited AI practices.
  • Bitkom's 2026 survey found 41 percent of German companies actively use AI, while 53 percent cite legal uncertainty around the AI Act as a barrier, often without realizing most of their tools sit in the unregulated minimal-risk tier.
  • McKinsey's 2025 State of AI report found 78 percent of organizations use AI in at least one business function, the large majority of which are minimal-risk productivity and automation tools.

Definition: Minimal-Risk AI System (EU AI Act)

A minimal-risk AI system is an AI system under the EU AI Act that does not meet the criteria for a prohibited practice, a high-risk use case, or a limited-risk transparency duty, and therefore carries no mandatory legal obligations.

Core characteristics of minimal-risk AI systems

Minimal-risk is a residual category: a system lands here by default once it clears the other three tiers, not by meeting a specific checklist. Most AI tools a Mittelstand company already runs fall into this group.

  • No mandatory conformity assessment, documentation, or registration duties
  • Covers everyday use cases like spam filters, inventory management, and recommender systems
  • Providers may voluntarily adopt codes of conduct under Article 95
  • Classification can change if the same system is later reused for a higher-risk purpose

Minimal-Risk AI System vs. Limited-Risk AI System

A limited-risk AI system still triggers Article 50 transparency duties, such as disclosing that a chatbot is AI or labeling synthetic content. A minimal-risk system triggers no comparable duty at all, because it neither interacts directly with people in a way the Act regulates nor generates content requiring disclosure. An AI-enabled video game or a backend demand-forecasting tool stays minimal-risk; a customer-facing chatbot built on similar technology typically does not.

Importance of minimal-risk classification in enterprise AI

Because the European Commission estimates minimal-risk systems make up the vast majority of AI currently deployed in the EU, most of a company’s existing AI footprint needs no new compliance program at all. McKinsey’s 2025 State of AI report found 78 percent of organizations already use AI in at least one business function, and the bulk of that usage, from email filtering to internal search, sits squarely in this unregulated tier.

Methods and procedures for minimal-risk AI systems

Handling minimal-risk systems well is less about compliance paperwork and more about keeping classification current.

Confirming tier placement

Before assuming a tool is minimal-risk, a company should check it against the criteria for the three regulated tiers, since the label only holds as long as none of them apply.

  • Screen the use case against prohibited AI practices
  • Check Annex III and safety-component criteria for high-risk status
  • Check for Article 50 transparency triggers that would make it limited-risk
  • Document the reasoning briefly, even though no formal record is legally required

Adopting voluntary codes of conduct

Article 95 invites providers and deployers of minimal-risk systems to commit voluntarily to codes covering transparency, fairness, or environmental impact, giving customers reassurance without a regulatory mandate.

Monitoring for risk-tier drift

A system built for a minimal-risk purpose can drift into a higher tier if its scope expands, such as a recommendation engine later used to screen job applicants, so periodic review matters more than a one-time classification.

Important KPIs for minimal-risk AI systems

Because no mandatory metrics apply, tracking here focuses on keeping the inventory accurate rather than proving compliance.

Classification hygiene

  • Tools reviewed against risk-tier criteria: quarterly
  • Share of AI inventory confirmed minimal-risk: percentage tracked
  • Use-case changes flagged for re-classification: logged per quarter
  • Voluntary code adoption: yes/no per tool

Strategic resource allocation

Keeping an accurate minimal-risk inventory lets compliance teams focus effort on the smaller set of limited- and high-risk systems instead. Bitkom’s 2026 survey found 53 percent of German companies cite legal uncertainty about the AI Act as a barrier, often because they have not separated their minimal-risk tools from the ones that actually need attention.

Internal trust and adoption

A clear, shared understanding of which tools are minimal-risk reduces unnecessary hesitation among staff who might otherwise over-apply AI Act caution to low-stakes tools like spell-checkers or spam filters.

Risk factors and controls for minimal-risk AI systems

The main risks with minimal-risk systems are not legal penalties but misjudgment and drift.

Misclassifying a higher-risk use case as minimal-risk

Treating a system as minimal-risk without checking it against the other tiers can leave a genuinely high-risk or limited-risk deployment unmanaged.

  • Reassess classification whenever a tool’s purpose changes
  • Involve compliance or legal review for borderline cases
  • Keep a lightweight AI compliance inventory even for minimal-risk tools

Over-governing low-stakes tools

Applying high-risk-level documentation and sign-off processes to a spam filter or inventory system wastes effort and slows adoption without reducing any real risk.

Ignoring voluntary codes entirely

Skipping Article 95 codes of conduct is legally fine, but it can leave a company without a reference framework when customers or partners ask how its AI tools handle fairness or transparency.

Practical example

A 90-employee wholesale distributor in Bavaria uses AI-based demand forecasting, an email spam filter, and a warehouse inventory management system, none of which interact directly with customers or process sensitive personal data for high-stakes decisions. After mapping its tools against the EU AI Act’s four tiers, the company confirmed all three sit in the minimal-risk category and require no conformity assessment or registration. It adopted a short internal voluntary code covering data handling transparency and scheduled a yearly check for any tool whose purpose expands.

  • Annual classification review covering every AI tool in use
  • A one-page internal register distinguishing minimal-risk from regulated tools
  • A voluntary transparency note shared with major customers on request
  • A trigger list for re-classification if a tool’s scope changes

Current developments and effects

Even the lightest-touch tier is shifting as the broader EU AI Act rollout matures.

Clarified Commission guidance on tier boundaries

The European Commission has published additional guidance distinguishing minimal-risk uses from Article 50 triggers, helping companies avoid both under- and over-classification.

  • More worked examples of borderline cases, like AI-assisted content moderation
  • Clearer guidance on when embedding an AI feature changes a product’s tier
  • Growing alignment between EU guidance and national market surveillance practice

Broader enterprise AI adoption inside the minimal-risk tier

As more routine business functions adopt AI, from inventory forecasting to scheduling, the minimal-risk tier keeps absorbing most of that growth rather than shrinking.

Vendor transparency becoming a differentiator

Software vendors increasingly publish their own risk-tier self-assessments for customers, turning Article 95’s voluntary codes into a competitive signal even where no law requires it.

Conclusion

Minimal-risk status covers the overwhelming majority of AI tools a typical business already runs, from spam filters to inventory management, and requires no mandatory compliance program under the EU AI Act. The real work is keeping classification current, since a tool built for a low-stakes purpose can drift toward limited-risk or high-risk obligations as its use case expands. Mittelstand companies that maintain a simple, honest inventory across all four tiers spend their compliance effort where it is actually needed. As enterprise AI adoption grows, this tier will keep absorbing most of that growth, making accurate classification more valuable, not less.

Frequently Asked Questions

What makes an AI system “minimal-risk” under the EU AI Act?

A system is minimal-risk if it does not meet the criteria for prohibited practices, high-risk classification, or limited-risk transparency duties. Most everyday AI tools, including spam filters and inventory systems, default into this tier.

No mandatory obligations apply. Article 95 only encourages providers to voluntarily adopt codes of conduct covering transparency and fairness, with no enforcement behind that invitation.

How is minimal-risk different from limited-risk under the AI Act?

Limited-risk systems, like customer-facing chatbots, must meet Article 50 transparency duties such as disclosing that a user is interacting with AI. Minimal-risk systems trigger no comparable disclosure requirement.

Does a Mittelstand company with 50 to 100 employees need to worry about EU AI Act compliance for its everyday tools?

Usually not for tools like spam filters, forecasting software, or internal search, since these typically qualify as minimal-risk. Compliance effort should focus on any tool that interacts directly with customers or affects high-stakes decisions like hiring or credit.

What does it cost to confirm a tool is minimal-risk?

Classifying a tool against the Act’s four tiers is usually a short internal exercise, often completed in a day or two per tool, since no formal conformity assessment is required for this tier.

Can a minimal-risk AI tool become high-risk or limited-risk later?

Yes. If a company repurposes a minimal-risk tool, such as using a recommendation engine to help screen job candidates, it can move into a regulated tier and require a fresh classification review.

Building better software Contact us together