AI governance guide

EU AI Act risk tiers explained

Most AI systems in most organisations fall into the lowest tier of the EU AI Act and attract no substantive obligations at all. That is the least reported fact about the regulation and the first one to establish, because the compliance effort for the tiers above it is large enough that classifying by anxiety rather than by the text is expensive. The Act sorts systems by what they are used for, not by how sophisticated they are, so a simple model in a hiring decision carries far more obligation than an advanced one writing marketing copy.

What are the four risk tiers?

Unacceptable risk, which is prohibited outright. High risk, which is permitted subject to a substantial set of requirements before and after it goes on the market. Limited or transparency risk, where the only duty is to tell people what they are dealing with. And minimal risk, which is everything else and carries no obligations under the Act. General-purpose AI models sit on a separate track with their own duties that apply to whoever supplies the model rather than to the tier of the application built on it.

Classification is driven by the intended purpose and the context of use. The same underlying model can be minimal risk in a document summariser and high risk in a system that ranks job applicants, and nothing about the model changes between the two. This is the single most useful thing to internalise, because teams instinctively classify by technical capability and the Act does not.

It also means classification is not a one-off. Changing what a system is used for can move it between tiers without a line of code changing, which is why the classification belongs on the running system in your inventory rather than in the project file that commissioned it.

What is actually prohibited?

A short, specific list in Article 5, and it is narrower than most summaries imply. Manipulative or subliminal techniques that materially distort behaviour and cause significant harm. Exploiting vulnerabilities of age, disability or social and economic situation. Social scoring leading to detrimental treatment in unrelated contexts or disproportionate to the behaviour. Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases. Emotion inference in the workplace and in education, outside medical and safety uses. Biometric categorisation to infer race, political opinions, trade union membership, religion, sex life or sexual orientation. Individual predictive policing based solely on profiling. And real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions.

Regulation (EU) 2026/1744 adds two more, and most published summaries still list eight. Systems that generate or manipulate realistic depictions of an identifiable natural person's intimate parts, or of an identifiable person engaged in sexually explicit activity, without that person's explicit consent. And systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU. Both are enacted law, both apply from 2 December 2026, and both sit in the top penalty band at up to 35 million euro or 7 per cent.

Three of these catch ordinary commercial systems rather than exotic ones. Emotion inference in the workplace covers sentiment analysis applied to employees, which appears inside contact centre quality tools and meeting analytics that were bought for other reasons. Biometric categorisation catches audience analytics that infer sensitive attributes from faces, which is a common feature of retail and out-of-home advertising measurement. And the new image prohibitions reach past products built for that purpose: a provider is caught where such output is a reasonably foreseeable and reproducible outcome without significant technical modification and adequate technical safeguards are absent, which puts any general-purpose image or video generator inside the question regardless of what it was sold to do.

The practical response is not a legal review of your whole estate. It is a targeted question to the two or three vendors whose products touch employee monitoring, contact centre analytics or camera-based audience measurement, asking specifically what attributes their product infers and whether inference can be disabled. If you ship, host or fine-tune an image or video generator, add a second question to your own team: what the safeguards against those outputs are, and what evidence exists that they have been tested.

What counts as high risk?

Two routes into the tier. The first is being a safety component of a product covered by the EU product legislation listed in Annex I Section A, where that legislation requires third-party conformity assessment: medical devices and lifts are the clearest examples. Motor vehicles are the example most often given and it is wrong. Regulation (EU) 2018/858 sits in Annex I Section B, and Article 2(2) limits the Act's application to Section B products to Article 6(1), Articles 102 to 109 and Article 112, so the substantive high-risk obligations do not reach them through the AI Act itself. Machinery was a correct Section A example when the Act was adopted, but Regulation (EU) 2026/1744 moves the Machinery Regulation (EU) 2023/1230 to Section B, so AI safety components in machinery are no longer routed into the AI Act's own high-risk regime and the requirements are integrated through the Machinery Regulation instead, with a Commission delegated act due by 2 August 2028. The same regulation narrows the Article 3(14) definition of a safety component to systems whose intended purpose is preventing or mitigating risks to health and safety, which takes assistance, optimisation and convenience functions out of this route altogether.

The second route, and the one most organisations meet, is falling into one of the use cases listed in Annex III.

Annex III is a list of contexts, not technologies, and the recurring theme is decisions about access. If a system materially influences whether someone gets a job, a loan, a place on a course, a benefit, insurance cover or emergency help, assume high risk until you have read the exemption in the next paragraph and concluded otherwise.

Annex III areaTypical systemCommon misreading
Employment and worker managementCV screening, ranking of applicants, task allocation, promotion and termination decisionsAssuming it applies only to fully automated rejection, when influencing the shortlist is enough
Access to essential private servicesCreditworthiness scoring, life and health insurance pricing and risk assessmentTreating an internal risk score as out of scope because a human signs the letter
Education and vocational trainingAdmissions, proctoring, assessment scoring, allocation to programmesAssuming proctoring is a security tool rather than an assessment system
BiometricsRemote biometric identification, biometric categorisation, emotion recognitionConfusing one-to-one verification on a device with remote identification
Critical infrastructureSafety management of traffic, water, gas, heating, electricity, digital infrastructureReading it as covering all operational systems rather than safety components
Public services and benefitsEligibility assessment, fraud detection in benefits, emergency call triage and dispatchAssuming private contractors delivering the service are outside scope

Is there an exemption from high risk?

Yes, and it is the most commercially significant paragraph in the Act for ordinary businesses. A system that falls under Annex III is not high risk if it does not pose a significant risk of harm to health, safety or fundamental rights, and specifically where it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations without replacing or influencing the prior human assessment, or performs a preparatory task for an assessment.

The exemption has a hard limit: it never applies where the system profiles natural persons. It also carries a cost. To rely on it you must document the assessment before putting the system on the market or into service, and be able to produce that documentation on request, and registration duties still apply.

The line that decides most real cases is whether the system influences the human assessment or only formats it. A tool that extracts qualifications from a CV into a structured field is preparatory. A tool that ranks candidates by predicted suitability influences the assessment, whatever the interface says about the recruiter deciding. Write the assessment honestly, because it is the document a regulator reads first.

Are you a provider or a deployer?

This changes your obligations more than the tier does, and it is the question organisations get wrong most often. A provider develops an AI system or has one developed and places it on the market under its own name or trademark. A deployer uses one under its own authority. Providers carry the heavy load: risk management, data governance, technical documentation, logging, conformity assessment, registration and post-market monitoring. Deployers carry a shorter list centred on using the system as instructed, assigning competent human oversight, monitoring operation, keeping logs and informing affected workers.

The trap is Article 25. A deployer becomes a provider, with the full provider obligations, if it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or modifies the intended purpose of a system in a way that makes it high risk. Fine-tuning a supplier's model on your data, or wrapping a general-purpose model in your own branded hiring assistant, can move you across that line without anyone noticing that it happened.

So the question to answer before contracting is not only which tier the system is in, but whose name is on it and who decides its purpose. Get the allocation written into the contract, along with the obligation on the supplier to give you the information you need to meet your own duties.

What are the deadlines and the penalties?

The Act entered into force in August 2024 and applies in stages. The prohibitions and the AI literacy duty came first, in February 2025, with the exception of the two prohibitions added in 2026, which apply from 2 December 2026. Obligations on general-purpose AI models followed in August 2025. The high-risk deadlines have since moved, and the change is recent enough that a great deal of published guidance still quotes the original dates.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the Annex III high-risk deadline it displaced. Standalone Annex III high-risk obligations move from 2 August 2026 to 2 December 2027. Annex I product-embedded high-risk obligations move from 2 August 2027 to 2 August 2028. The regulatory sandbox deadline moves to 2 August 2027.

Two things did not move, and assuming otherwise is the expensive mistake here. The Article 50 transparency duties and the general-purpose AI regime applied from 2 August 2026 as originally scheduled. So the deferral buys time on the high-risk conformity work and none at all on disclosure. Check the current consolidated text before committing a budget, because this timetable has now changed once inside a fortnight of its own deadline.

Penalties are set as the higher of a fixed sum or a percentage of worldwide annual turnover, with the lower of the two applying to small and medium enterprises. Prohibited practices carry the top band at up to 35 million euro or 7 per cent. Most other breaches sit at up to 15 million euro or 3 per cent. Supplying incorrect, incomplete or misleading information to authorities sits at up to 7.5 million euro or 1 per cent.

The practical planning point is that the long lead item is not the paperwork, it is evidence. High-risk requirements ask for records of testing, data governance and post-market monitoring that can only be produced by having done those things over time. An organisation that starts generating that evidence a quarter before a deadline cannot retrofit it.

Common questions

What are the risk categories in the EU AI Act?
Four. Unacceptable risk is prohibited outright. High risk is allowed but carries substantial obligations before and after deployment. Limited or transparency risk requires only that people are told what they are interacting with. Minimal risk covers everything else and carries no obligations. General-purpose AI models are handled on a separate track with duties falling on whoever supplies the model.
How do I know if my AI system is high risk under the EU AI Act?
Check two routes. First, is it a safety component of a product covered by the EU product legislation in Annex I Section A that requires third-party conformity assessment, such as medical devices and lifts. Section B products, including motor vehicles and, since Regulation (EU) 2026/1744, machinery, are handled through their own product legislation rather than the AI Act's high-risk regime. Second, does its use fall within Annex III, which lists contexts including employment, creditworthiness and insurance, education, biometrics, critical infrastructure safety, law enforcement, migration and public benefits. Classification follows the intended purpose and context of use, not the technical sophistication of the model.
Can a system in Annex III avoid being high risk?
Yes, where it does not pose a significant risk to health, safety or fundamental rights, and it performs a narrow procedural task, improves the output of a completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task. The exemption never applies where the system profiles natural persons, and relying on it requires documenting the assessment before deployment and being able to produce it.
What is the difference between a provider and a deployer under the EU AI Act?
A provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses one under its own authority. Providers carry the heavier obligations covering risk management, technical documentation, conformity assessment and post-market monitoring. Deployers must use the system as instructed, assign competent human oversight, monitor it, keep logs and inform affected workers.
Can a company using someone else's AI become a provider?
Yes. Under Article 25, an organisation that puts its own name or trademark on a high-risk system, substantially modifies one, or changes the intended purpose so that a system becomes high risk, takes on the full provider obligations. Fine-tuning a supplier's model on internal data or wrapping a general model in a branded hiring tool can cross that line without any deliberate decision to do so.
What are the fines under the EU AI Act?
Penalties are set as the higher of a fixed amount or a share of worldwide annual turnover, with small and medium enterprises subject to the lower figure. Prohibited practices attract up to 35 million euro or 7 per cent. Most other breaches attract up to 15 million euro or 3 per cent. Supplying incorrect or misleading information to authorities attracts up to 7.5 million euro or 1 per cent.

More on AI ethics and governance

Let’s create something out of this world together.

Have a project in mind? Contact us for expert design and development solutions. Let’s discuss how we can help grow your business.

Azaadi Offer

Claim a free security assessment

Until 31 August we're covering the cost of a full vulnerability assessment and penetration test. Mention it in your message and we'll scope it with you.

  • Web application testing, authenticated and unauthenticated
  • Mobile application testing across iOS and Android
  • External network and infrastructure assessment
  • Manual exploitation by engineers, not scanner output

Testing and the report are free. Fixing what we find is quoted separately, with no obligation to accept.

Read the full offer

Tell us what you are trying to build and we will tell you plainly whether we are the right people for it. Book a call with an expert to work through the detail, or ask for a fixed quote if the scope is already clear. No obligation either way.

Four fields is all we need to get started.

Fastnexa Logo

© 2026 fastnexa. All rights reserved.