LinkedIn analytics tracking pixel for AIDOLS AI consulting website performance measurement
Governance & Risk

EU AI Act Risk Tier

EU AI Act risk tiers are the four-level classification — unacceptable, high, limited, and minimal/no risk — that determines which obligations apply to an AI system placed on the EU market under Regulation (EU) 2024/1689.

Full definition

Unacceptable-risk systems (Article 5: social scoring, manipulative subliminal techniques, real-time biometric ID in public spaces with narrow exceptions) are banned. High-risk systems (Annex III: critical infrastructure, education, employment, essential services, law enforcement, migration, justice) face the heaviest obligations — risk management, data governance, technical documentation, human oversight, accuracy, robustness, cybersecurity, and conformity assessment. Limited-risk systems require transparency (e.g., chatbot disclosure, deepfake labeling). Minimal-risk systems have no obligations.

Why it matters

Tier classification drives the entire compliance budget. Misclassifying a system as limited when it is actually high-risk exposes the provider to fines up to 7% of global turnover. Every EU AI deployment needs a documented tier rationale.

Example

An HR resume-screening tool is high-risk under Annex III §4(a); its provider must complete a conformity assessment, register in the EU database, run a Fundamental Rights Impact Assessment, and ensure human oversight before deploying in any EU market.

Frequently asked questions

Which AI systems are banned outright under the EU AI Act?

Article 5 prohibits four categories: real-time biometric identification in public spaces (with narrow law-enforcement exceptions), social scoring by public authorities, manipulative subliminal techniques that exploit psychological vulnerabilities, and AI that targets children or vulnerable groups. These are unacceptable-risk systems — deploying them in the EU carries fines up to €35 million or 7% of global annual revenue.

What makes an AI system high-risk under the EU AI Act?

High-risk systems are those listed in Annex III: critical infrastructure (energy, water, transport), education, employment decisions (CV screening, performance scoring, hiring and firing), access to essential services (credit scoring, insurance, social benefits), law enforcement, migration, and administration of justice. If your AI system directly influences decisions in any of these categories, it is high-risk regardless of how the vendor markets the product.

How do you classify an AI system's risk tier under the EU AI Act?

Three-step test: (1) Is the system in Article 5's prohibited list? → Unacceptable risk, banned. (2) Does it match an Annex III use case? → High-risk, requiring conformity assessment, EU-database registration, technical documentation, and human-oversight mechanisms. (3) Does it interact with users without disclosing it is AI? → Limited risk, transparency obligations only. Everything else is minimal risk with no mandatory obligations. The common mistake is relying on product marketing — an HR analytics tool that ranks job candidates is high-risk under Annex III §4(a) regardless of what the vendor calls it.

What are the fines for misclassifying an AI system under the EU AI Act?

Deploying a prohibited system: up to €35 million or 7% of global annual revenue (whichever is higher). Failing to meet high-risk obligations — missing conformity assessment, incomplete documentation, no human-oversight mechanism: up to €15 million or 3% of global revenue. Providing inaccurate information to notified bodies: up to €7.5 million or 1% of revenue. Enforcement is delegated to national market surveillance authorities; Germany, France, and the Netherlands are expected to be among the most active.

Source & further reading

Primary source: European Union — Regulation (EU) 2024/1689 on Artificial Intelligence (2024).

Citation policy: this entry is part of the AIDOLS AI Implementation Glossary and may be quoted for research, journalism, and education with attribution to aidolsgroup.com/es/glossary/eu-ai-act-risk-tier/.