The Risk-Based Framework
The Act’s central idea is simple: the more a system can harm people, the more rules it carries. Everything else is detail hanging off four risk tiers. Get the tier right and the rest of your obligations fall into place.
The Four Tiers
The Act does not regulate all AI equally. It places each system on a ladder of risk and scales the obligations accordingly. There are four rungs:
| Tier | What it means | What the Act does |
|---|---|---|
| Unacceptable risk | Uses considered a clear threat to safety, livelihoods, or rights. | Banned outright (Lesson 3). |
| High risk | Systems that can significantly affect health, safety, or fundamental rights. | Permitted but heavily regulated - the full obligation stack (Lesson 4). |
| Limited risk | Systems that interact with people or generate content, where the main danger is deception. | Transparency duties - tell people it is AI (Lesson 6). |
| Minimal risk | Everything else - spam filters, recommendation engines, AI in games. | No mandatory obligations; voluntary codes encouraged. |
The vast majority of AI in use today - by count of systems - sits in the minimal-risk tier and carries no new legal duties. The Act concentrates its weight on the small number of systems that can do real harm.
Tier 1: Unacceptable Risk
At the top of the ladder are practices the EU has decided no amount of safeguards can justify. These are prohibited entirely - you cannot place them on the market, put them into service, or use them, full stop. They include things like government social scoring and certain manipulative or exploitative systems. The ban has applied since February 2025. Lesson 3 walks through all eight categories.
Tier 2: High Risk
This is where most of the Act’s text and most of the real compliance work lives. A system is high-risk by one of two routes:
- It is a safety component of a regulated product (or is itself such a product) covered by existing EU product-safety law - medical devices, machinery, toys, vehicles, lifts, and so on. If the product already needs third-party safety certification, AI inside it inherits high-risk status.
- It falls into one of the use-cases listed in Annex III - areas like biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice.
High-risk does not mean banned. These systems are allowed, but their providers must meet a substantial set of requirements - risk management, data governance, technical documentation, human oversight, accuracy and robustness - and pass a conformity assessment before going to market. Lesson 4 is dedicated to this tier.
Tier 3: Limited Risk
Some systems are not dangerous so much as potentially deceptive. A chatbot that a user might mistake for a human, a deepfake, or AI-generated text published to inform the public - the risk is that people are misled about what they are dealing with. The Act’s answer is transparency rather than heavy regulation: disclose that AI is involved, and label synthetic content. Lesson 6 covers exactly what must be disclosed and by whom.
Tier 4: Minimal Risk
Everything that is not prohibited, high-risk, or subject to transparency duties falls here. AI spam filters, inventory forecasting, product recommendations, and the AI in a video game carry no mandatory obligations under the Act. The EU encourages voluntary codes of conduct for this tier, but they are exactly that - voluntary.
How to Find Your Tier
For any system you build or use, work down this short decision path:
- Is it a prohibited practice? If yes, stop - you cannot offer it (Lesson 3).
- Is it a safety component of a regulated product, or listed in Annex III without qualifying for the narrow exemption? If yes, it is high-risk (Lesson 4).
- Does it interact with people or generate content in a way that could deceive? If yes, transparency duties apply (Lesson 6).
- Otherwise, it is minimal-risk - no mandatory obligations.
Run this per system and per role. And remember the general-purpose AI regime (Lesson 5) sits alongside these tiers: a foundation model carries its own obligations as a GPAI model, on top of any tier that applies when it is built into a specific application.
Ready to Go Deeper?
Live instructor-led courses from our partners. Affiliate disclosure.
AI & ML Courses - 30% Off
Live instructor-led AI, machine learning, data science, and cloud courses for working professionals. Use code Limited30 at checkout.
EdurekaDataCamp - AI & Data Science
Hands-on Python, machine learning, and AI courses with interactive exercises and real projects.
DataCampedX - Top AI Courses
University-level AI courses from MIT, Harvard, Stanford. Earn certificates that employers recognize.
edX