EU AI Act risk tiers explained
Most AI systems in most organisations fall into the lowest tier of the EU AI Act and attract no substantive obligations at all. That is the least reported fact about the regulation and the first one to establish, because the compliance effort for the tiers above it is large enough that classifying by anxiety rather than by the text is expensive. The Act sorts systems by what they are used for, not by how sophisticated they are, so a simple model in a hiring decision carries far more obligation than an advanced one writing marketing copy.
What are the four risk tiers?
Unacceptable risk, which is prohibited outright. High risk, which is permitted subject to a substantial set of requirements before and after it goes on the market. Limited or transparency risk, where the only duty is to tell people what they are dealing with. And minimal risk, which is everything else and carries no obligations under the Act. General-purpose AI models sit on a separate track with their own duties that apply to whoever supplies the model rather than to the tier of the application built on it.
Classification is driven by the intended purpose and the context of use. The same underlying model can be minimal risk in a document summariser and high risk in a system that ranks job applicants, and nothing about the model changes between the two. This is the single most useful thing to internalise, because teams instinctively classify by technical capability and the Act does not.
It also means classification is not a one-off. Changing what a system is used for can move it between tiers without a line of code changing, which is why the classification belongs on the running system in your inventory rather than in the project file that commissioned it.
What is actually prohibited?
A short, specific list in Article 5, and it is narrower than most summaries imply. Manipulative or subliminal techniques that materially distort behaviour and cause significant harm. Exploiting vulnerabilities of age, disability or social and economic situation. Social scoring leading to detrimental treatment in unrelated contexts or disproportionate to the behaviour. Untargeted scraping of facial images from the internet or CCTV to build facial recognition databases. Emotion inference in the workplace and in education, outside medical and safety uses. Biometric categorisation to infer race, political opinions, trade union membership, religion, sex life or sexual orientation. Individual predictive policing based solely on profiling. And real-time remote biometric identification in public spaces for law enforcement, subject to narrow exceptions.
Regulation (EU) 2026/1744 adds two more, and most published summaries still list eight. Systems that generate or manipulate realistic depictions of an identifiable natural person's intimate parts, or of an identifiable person engaged in sexually explicit activity, without that person's explicit consent. And systems that generate or manipulate child sexual abuse material within the meaning of Directive 2011/93/EU. Both are enacted law, both apply from 2 December 2026, and both sit in the top penalty band at up to 35 million euro or 7 per cent.
Three of these catch ordinary commercial systems rather than exotic ones. Emotion inference in the workplace covers sentiment analysis applied to employees, which appears inside contact centre quality tools and meeting analytics that were bought for other reasons. Biometric categorisation catches audience analytics that infer sensitive attributes from faces, which is a common feature of retail and out-of-home advertising measurement. And the new image prohibitions reach past products built for that purpose: a provider is caught where such output is a reasonably foreseeable and reproducible outcome without significant technical modification and adequate technical safeguards are absent, which puts any general-purpose image or video generator inside the question regardless of what it was sold to do.
The practical response is not a legal review of your whole estate. It is a targeted question to the two or three vendors whose products touch employee monitoring, contact centre analytics or camera-based audience measurement, asking specifically what attributes their product infers and whether inference can be disabled. If you ship, host or fine-tune an image or video generator, add a second question to your own team: what the safeguards against those outputs are, and what evidence exists that they have been tested.
What counts as high risk?
Two routes into the tier. The first is being a safety component of a product covered by the EU product legislation listed in Annex I Section A, where that legislation requires third-party conformity assessment: medical devices and lifts are the clearest examples. Motor vehicles are the example most often given and it is wrong. Regulation (EU) 2018/858 sits in Annex I Section B, and Article 2(2) limits the Act's application to Section B products to Article 6(1), Articles 102 to 109 and Article 112, so the substantive high-risk obligations do not reach them through the AI Act itself. Machinery was a correct Section A example when the Act was adopted, but Regulation (EU) 2026/1744 moves the Machinery Regulation (EU) 2023/1230 to Section B, so AI safety components in machinery are no longer routed into the AI Act's own high-risk regime and the requirements are integrated through the Machinery Regulation instead, with a Commission delegated act due by 2 August 2028. The same regulation narrows the Article 3(14) definition of a safety component to systems whose intended purpose is preventing or mitigating risks to health and safety, which takes assistance, optimisation and convenience functions out of this route altogether.
The second route, and the one most organisations meet, is falling into one of the use cases listed in Annex III.
Annex III is a list of contexts, not technologies, and the recurring theme is decisions about access. If a system materially influences whether someone gets a job, a loan, a place on a course, a benefit, insurance cover or emergency help, assume high risk until you have read the exemption in the next paragraph and concluded otherwise.
| Annex III area | Typical system | Common misreading |
|---|---|---|
| Employment and worker management | CV screening, ranking of applicants, task allocation, promotion and termination decisions | Assuming it applies only to fully automated rejection, when influencing the shortlist is enough |
| Access to essential private services | Creditworthiness scoring, life and health insurance pricing and risk assessment | Treating an internal risk score as out of scope because a human signs the letter |
| Education and vocational training | Admissions, proctoring, assessment scoring, allocation to programmes | Assuming proctoring is a security tool rather than an assessment system |
| Biometrics | Remote biometric identification, biometric categorisation, emotion recognition | Confusing one-to-one verification on a device with remote identification |
| Critical infrastructure | Safety management of traffic, water, gas, heating, electricity, digital infrastructure | Reading it as covering all operational systems rather than safety components |
| Public services and benefits | Eligibility assessment, fraud detection in benefits, emergency call triage and dispatch | Assuming private contractors delivering the service are outside scope |
Is there an exemption from high risk?
Yes, and it is the most commercially significant paragraph in the Act for ordinary businesses. A system that falls under Annex III is not high risk if it does not pose a significant risk of harm to health, safety or fundamental rights, and specifically where it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations without replacing or influencing the prior human assessment, or performs a preparatory task for an assessment.
The exemption has a hard limit: it never applies where the system profiles natural persons. It also carries a cost. To rely on it you must document the assessment before putting the system on the market or into service, and be able to produce that documentation on request, and registration duties still apply.
The line that decides most real cases is whether the system influences the human assessment or only formats it. A tool that extracts qualifications from a CV into a structured field is preparatory. A tool that ranks candidates by predicted suitability influences the assessment, whatever the interface says about the recruiter deciding. Write the assessment honestly, because it is the document a regulator reads first.
Are you a provider or a deployer?
This changes your obligations more than the tier does, and it is the question organisations get wrong most often. A provider develops an AI system or has one developed and places it on the market under its own name or trademark. A deployer uses one under its own authority. Providers carry the heavy load: risk management, data governance, technical documentation, logging, conformity assessment, registration and post-market monitoring. Deployers carry a shorter list centred on using the system as instructed, assigning competent human oversight, monitoring operation, keeping logs and informing affected workers.
The trap is Article 25. A deployer becomes a provider, with the full provider obligations, if it puts its own name or trademark on a high-risk system, makes a substantial modification to one, or modifies the intended purpose of a system in a way that makes it high risk. Fine-tuning a supplier's model on your data, or wrapping a general-purpose model in your own branded hiring assistant, can move you across that line without anyone noticing that it happened.
So the question to answer before contracting is not only which tier the system is in, but whose name is on it and who decides its purpose. Get the allocation written into the contract, along with the obligation on the supplier to give you the information you need to meet your own duties.
What are the deadlines and the penalties?
The Act entered into force in August 2024 and applies in stages. The prohibitions and the AI literacy duty came first, in February 2025, with the exception of the two prohibitions added in 2026, which apply from 2 December 2026. Obligations on general-purpose AI models followed in August 2025. The high-risk deadlines have since moved, and the change is recent enough that a great deal of published guidance still quotes the original dates.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the Annex III high-risk deadline it displaced. Standalone Annex III high-risk obligations move from 2 August 2026 to 2 December 2027. Annex I product-embedded high-risk obligations move from 2 August 2027 to 2 August 2028. The regulatory sandbox deadline moves to 2 August 2027.
Two things did not move, and assuming otherwise is the expensive mistake here. The Article 50 transparency duties and the general-purpose AI regime applied from 2 August 2026 as originally scheduled. So the deferral buys time on the high-risk conformity work and none at all on disclosure. Check the current consolidated text before committing a budget, because this timetable has now changed once inside a fortnight of its own deadline.
Penalties are set as the higher of a fixed sum or a percentage of worldwide annual turnover, with the lower of the two applying to small and medium enterprises. Prohibited practices carry the top band at up to 35 million euro or 7 per cent. Most other breaches sit at up to 15 million euro or 3 per cent. Supplying incorrect, incomplete or misleading information to authorities sits at up to 7.5 million euro or 1 per cent.
The practical planning point is that the long lead item is not the paperwork, it is evidence. High-risk requirements ask for records of testing, data governance and post-market monitoring that can only be produced by having done those things over time. An organisation that starts generating that evidence a quarter before a deadline cannot retrofit it.
Common questions
- What are the risk categories in the EU AI Act?
- Four. Unacceptable risk is prohibited outright. High risk is allowed but carries substantial obligations before and after deployment. Limited or transparency risk requires only that people are told what they are interacting with. Minimal risk covers everything else and carries no obligations. General-purpose AI models are handled on a separate track with duties falling on whoever supplies the model.
- How do I know if my AI system is high risk under the EU AI Act?
- Check two routes. First, is it a safety component of a product covered by the EU product legislation in Annex I Section A that requires third-party conformity assessment, such as medical devices and lifts. Section B products, including motor vehicles and, since Regulation (EU) 2026/1744, machinery, are handled through their own product legislation rather than the AI Act's high-risk regime. Second, does its use fall within Annex III, which lists contexts including employment, creditworthiness and insurance, education, biometrics, critical infrastructure safety, law enforcement, migration and public benefits. Classification follows the intended purpose and context of use, not the technical sophistication of the model.
- Can a system in Annex III avoid being high risk?
- Yes, where it does not pose a significant risk to health, safety or fundamental rights, and it performs a narrow procedural task, improves the output of a completed human activity, detects decision patterns without replacing human assessment, or performs a preparatory task. The exemption never applies where the system profiles natural persons, and relying on it requires documenting the assessment before deployment and being able to produce it.
- What is the difference between a provider and a deployer under the EU AI Act?
- A provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses one under its own authority. Providers carry the heavier obligations covering risk management, technical documentation, conformity assessment and post-market monitoring. Deployers must use the system as instructed, assign competent human oversight, monitor it, keep logs and inform affected workers.
- Can a company using someone else's AI become a provider?
- Yes. Under Article 25, an organisation that puts its own name or trademark on a high-risk system, substantially modifies one, or changes the intended purpose so that a system becomes high risk, takes on the full provider obligations. Fine-tuning a supplier's model on internal data or wrapping a general model in a branded hiring tool can cross that line without any deliberate decision to do so.
- What are the fines under the EU AI Act?
- Penalties are set as the higher of a fixed amount or a share of worldwide annual turnover, with small and medium enterprises subject to the lower figure. Prohibited practices attract up to 35 million euro or 7 per cent. Most other breaches attract up to 15 million euro or 3 per cent. Supplying incorrect or misleading information to authorities attracts up to 7.5 million euro or 1 per cent.