The EU AI Act Risk Tiers
How the Act classifies systems into prohibited, high-risk, transparency-obligated and minimal, why the classification turns on use rather than technology, and where the boundaries are genuinely unclear.
The EU AI Act is the first comprehensive horizontal regulation of artificial intelligence, and its central design decision is that obligations attach to use rather than to technology. The same model in two applications can fall in two tiers. Getting the classification right is therefore the first compliance task, and it is not a technical judgement.
The four tiers
Prohibited practices are banned outright. The list includes manipulative techniques that materially distort behaviour and cause significant harm, exploitation of vulnerabilities due to age or disability, social scoring by public authorities leading to detrimental treatment in unrelated contexts, untargeted scraping of facial images to build recognition databases, emotion inference in the workplace and education outside medical and safety uses, and biometric categorisation to infer sensitive attributes. Real-time remote biometric identification in public spaces for law enforcement is prohibited with narrow, authorised exceptions.
High-risk systems carry the heaviest compliance burden. Two routes qualify a system. Annex I covers AI that is a safety component of a product already regulated under EU product-safety law. Annex III lists standalone use cases: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services including credit scoring, law enforcement, migration and border control, and administration of justice.
High-risk systems require a risk management system, data governance, technical documentation, logging, transparency to deployers, human oversight, and appropriate accuracy, robustness and cybersecurity, plus conformity assessment and registration.
Limited risk attracts transparency obligations under Article 50: telling people they are interacting with an AI system unless obvious, marking synthetic content in a machine-readable form, disclosing deepfakes, and disclosing AI-generated text published to inform the public on matters of public interest unless it had human editorial review.
Minimal risk covers everything else, with no obligations beyond general law.
General-purpose AI models
GPAI models sit outside the tiers with their own regime. All providers owe technical documentation, information to downstream providers, a copyright policy, and a publicly available sufficiently detailed summary of training content following an AI Office template. Models presenting systemic risk, identified by capability including a compute threshold, carry additional obligations covering evaluation, adversarial testing, incident reporting and cybersecurity.
When it breaks
The classification is a use-case judgement, not a model property. A team asking "is our model high-risk" has asked the wrong question. The answer depends on what decision the system informs and about whom, which means legal and product input rather than engineering alone.
General-purpose systems resist classification. An assistant that can be used for many things has a tier that depends on deployment, which is why obligations were split between model providers and deployers. A deployer putting a general assistant into a hiring workflow has taken on high-risk obligations that the model provider did not.
Boundaries are unclear at the edges. Whether a given emotion-adjacent inference is prohibited, whether a scoring system is "social scoring", and whether a use falls within an Annex III category are questions where guidance is still developing and where reasonable readings differ.
Extraterritorial reach is broad. The Act applies to providers placing systems on the EU market and to deployers established in the EU, and to providers outside the EU where the output is used in the EU. Being outside Europe is not by itself an exemption.
12 flashcards for this concept
Click a card to reveal the answer.