The Four-Tier Risk Framework
The EU AI Act is built around a risk-proportionate architecture. Every AI system is classified into one of four tiers, and compliance obligations flow from that classification. The framework is hierarchical: test for Prohibited first, then High-Risk, then Limited-Risk. Everything else is Minimal-Risk.
| Tier | Classification | Legal Basis | Max Penalty | Deadline |
|---|---|---|---|---|
| Tier 1 | Prohibited, absolute ban | Art. 5 | €35M / 7% | 2 Feb 2025 |
| Tier 2 | High-Risk, full compliance burden | Annex III + I | €15M / 3% | 2 Dec 2027 |
| Tier 3 | Limited-Risk, transparency only | Art. 50, 52 | €15M / 3% | 2 Aug 2026Art. 50(2) watermarking: 2 Dec 2026 |
| Tier 4 | Minimal-Risk, voluntary only | General | None | No deadline |
Tier 1: Prohibited AI Practices (Article 5), Active Since 2 Feb 2025
These are absolute prohibitions, not compliance challenges. No risk management system or technical documentation can make a prohibited AI practice lawful. The nine prohibited categories under Article 5(1)(a)-(h) are: subliminal manipulation AI; exploitation of vulnerability-based manipulation; government social scoring systems; criminal prediction based solely on profiling; untargeted facial image scraping for biometric databases; emotion inference in workplaces and education; biometric categorisation for sensitive attributes; and real-time remote biometric identification in public spaces (with narrow law enforcement exceptions). Post-hoc remote biometric identification is high-risk under Annex III, not prohibited.
Tier 2: High-Risk AI Systems, Annex III Domains
High-risk classification triggers the full compliance burden under Chapter III: risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11 + Annex IV), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), and accuracy/robustness (Art. 15). Under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), full compliance is required by 2 December 2027 for Annex III standalone high-risk systems (moved from 2 August 2026, a 16-month deferral).
The eight Annex III high-risk domains:
- Biometric identification and categorisation, post-prohibition biometric systems, emotion recognition, biometric categorisation on sensitive attributes
- Critical infrastructure, AI safety components for utilities, transport, and digital infrastructure
- Education and vocational training, access determination, student assessment, examination monitoring AI
- Employment and workforce management, recruitment, selection, monitoring, performance evaluation, termination AI
- Essential private and public services, credit scoring, insurance risk, public benefit eligibility, emergency dispatch AI
- Law enforcement, individual risk assessment, polygraphs, evidence reliability, predictive policing
- Migration, asylum, and border management, risk assessment, document verification, asylum application AI
- Administration of justice and democratic processes, judicial assistance, electoral influence, political advertising AI
Important nuance: Article 6(3) permits providers to declare a system not high-risk even if in an Annex III domain, if it does not pose a significant risk of harm. This requires documented justification and a provider declaration, and regulators can challenge it.
Tier 3: Limited-Risk AI, Transparency Obligations
Limited-risk AI faces targeted transparency requirements rather than the full compliance burden. Key obligations:
- Conversational AI (chatbots): Must inform users they are interacting with an AI, unless obvious from context
- Deepfakes and synthetic content: Must be labelled as AI-generated or AI-manipulated
- Emotion recognition systems: Must inform exposed persons the system is inferring their emotional state
- Biometric categorisation: Must inform exposed persons about the categorisation
Tier 4: Minimal-Risk AI, No Mandatory Requirements
The vast majority of AI systems, spam filters, recommendation engines, AI video games, inventory optimisation, most creative AI tools, productivity AI, face no mandatory requirements under the Act. Voluntary codes of conduct are encouraged but not obligatory.
Special Category: GPAI (General-Purpose AI)
GPAI models (LLMs, foundation models, multimodal AI) face a distinct compliance framework under Articles 51–56, active since 2 August 2025. GPAI obligations apply in addition to risk-tier obligations for GPAI models that are also high-risk systems. Models above 10²⁵ FLOPs training compute face additional systemic risk obligations.
Classification Decision Framework
Apply this seven-step framework to every AI system in your organisation:
- Article 5 check: Does the system fall within any prohibited practice? → If yes: cease immediately.
- Annex I check: Is the system a safety component of a regulated product (medical devices, machinery, vehicles)? → If yes: high-risk.
- Annex III domain check: Does the system operate in any of the eight high-risk domains? → If yes: provisionally high-risk.
- Article 6(3) exception: Even if in an Annex III domain, does the system pose significant risk of harm? → If not: may be excluded with documented justification.
- Transparency check: Is the system a chatbot, deepfake generator, or emotion recognition tool? → If yes: limited-risk transparency obligations.
- GPAI check: Is the system a general-purpose AI model? → If yes: Chapter V GPAI obligations apply.
- Default: If none of the above apply: minimal-risk, no mandatory requirements.
Yes. If the intended purpose, capabilities, or deployment context of an AI system changes materially, its risk classification must be reassessed. A general analytics tool subsequently deployed for credit scoring decisions would move from minimal-risk to high-risk classification and trigger full compliance obligations. Classification decisions should be formally reviewed whenever the system or its context changes significantly.
Primary classification responsibility sits with the provider. However, deployers who substantially modify a system or use a general-purpose system in a high-risk context take on provider-equivalent obligations. Where a deployer uses a third-party AI system in a high-risk domain without the provider having classified it as high-risk, the deployer bears responsibility for that deployment's compliance.