Beginner

The Risk-Based Framework

The Act’s central idea is simple: the more a system can harm people, the more rules it carries. Everything else is detail hanging off four risk tiers. Get the tier right and the rest of your obligations fall into place.

✍️ AI School Editorial Team · Lilly Tech Systems 📅 Published Jun 13, 2026 · Reviewed Jun 13, 2026

The Four Tiers

The Act does not regulate all AI equally. It places each system on a ladder of risk and scales the obligations accordingly. There are four rungs:

TierWhat it meansWhat the Act does
Unacceptable riskUses considered a clear threat to safety, livelihoods, or rights.Banned outright (Lesson 3).
High riskSystems that can significantly affect health, safety, or fundamental rights.Permitted but heavily regulated - the full obligation stack (Lesson 4).
Limited riskSystems that interact with people or generate content, where the main danger is deception.Transparency duties - tell people it is AI (Lesson 6).
Minimal riskEverything else - spam filters, recommendation engines, AI in games.No mandatory obligations; voluntary codes encouraged.

The vast majority of AI in use today - by count of systems - sits in the minimal-risk tier and carries no new legal duties. The Act concentrates its weight on the small number of systems that can do real harm.

💡
Risk here means risk to people, not to your business. The Act’s notion of "high risk" is about potential harm to health, safety, and fundamental rights - not commercial or reputational risk to you. A system can be business-critical and still be minimal-risk under the Act, or low-revenue and still be high-risk.

Tier 1: Unacceptable Risk

At the top of the ladder are practices the EU has decided no amount of safeguards can justify. These are prohibited entirely - you cannot place them on the market, put them into service, or use them, full stop. They include things like government social scoring and certain manipulative or exploitative systems. The ban has applied since February 2025. Lesson 3 walks through all eight categories.

Tier 2: High Risk

This is where most of the Act’s text and most of the real compliance work lives. A system is high-risk by one of two routes:

  1. It is a safety component of a regulated product (or is itself such a product) covered by existing EU product-safety law - medical devices, machinery, toys, vehicles, lifts, and so on. If the product already needs third-party safety certification, AI inside it inherits high-risk status.
  2. It falls into one of the use-cases listed in Annex III - areas like biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice.

High-risk does not mean banned. These systems are allowed, but their providers must meet a substantial set of requirements - risk management, data governance, technical documentation, human oversight, accuracy and robustness - and pass a conformity assessment before going to market. Lesson 4 is dedicated to this tier.

There is a narrow off-ramp from Annex III. Even if a system matches an Annex III use-case, it may escape high-risk classification if it does not pose a significant risk to health, safety, or rights - for example, if it performs a narrow procedural task or only improves the result of a completed human activity. But you must document and justify that assessment; it is not automatic, and systems that profile people never qualify for the exemption.

Tier 3: Limited Risk

Some systems are not dangerous so much as potentially deceptive. A chatbot that a user might mistake for a human, a deepfake, or AI-generated text published to inform the public - the risk is that people are misled about what they are dealing with. The Act’s answer is transparency rather than heavy regulation: disclose that AI is involved, and label synthetic content. Lesson 6 covers exactly what must be disclosed and by whom.

Tier 4: Minimal Risk

Everything that is not prohibited, high-risk, or subject to transparency duties falls here. AI spam filters, inventory forecasting, product recommendations, and the AI in a video game carry no mandatory obligations under the Act. The EU encourages voluntary codes of conduct for this tier, but they are exactly that - voluntary.

How to Find Your Tier

For any system you build or use, work down this short decision path:

  1. Is it a prohibited practice? If yes, stop - you cannot offer it (Lesson 3).
  2. Is it a safety component of a regulated product, or listed in Annex III without qualifying for the narrow exemption? If yes, it is high-risk (Lesson 4).
  3. Does it interact with people or generate content in a way that could deceive? If yes, transparency duties apply (Lesson 6).
  4. Otherwise, it is minimal-risk - no mandatory obligations.

Run this per system and per role. And remember the general-purpose AI regime (Lesson 5) sits alongside these tiers: a foundation model carries its own obligations as a GPAI model, on top of any tier that applies when it is built into a specific application.

📝
Worked example: A résumé-screening tool that ranks job applicants is listed under Annex III (employment) - high-risk. The same company’s internal meeting-notes summariser is minimal-risk. Its customer-facing support chatbot is limited-risk (must disclose it is AI). One company, three systems, three different tiers.

Ready to Go Deeper?

Live instructor-led courses from our partners. Affiliate disclosure.