Skip to main content
Deliberate AcademyProfessional AI Education
~15 min left
Lesson 5 of 9
15 min read10 XP

EU AI Act Risk Tiers: A First Orientation

Deliberate Academy Editorial Team

Reviewed for accuracy and professional relevance

You're 5 lessons in — don't lose your progress.

Sign up free
What you'll learn
  • Name the EU AI Act's four risk tiers and describe what generally determines which tier a system falls into
  • Explain why classification is driven by use-case domain, not by how advanced or impressive the underlying AI technology is
  • Apply an orientation-level decision tree to place a described AI system into its most likely tier
  • Recognize the boundary between this lesson's orientation-level classification and the formal conformity-obligation depth a dedicated governance course covers

A newcomer to AI compliance work is asked whether a company's new AI writing assistant is "high-risk" under the EU AI Act. The instinctive answer is often based on how powerful or sophisticated the tool seems — and that instinct is exactly backwards. The Act's tier structure is built around what the system is used for, not how advanced its underlying technology is. This lesson gives you the orientation-level version of that classification logic.

The Four Tiers

Unacceptable risk (prohibited). A defined list of AI practices considered to carry risks too severe to permit, regardless of sector or claimed benefit — banned outright.

High-risk. Systems used in specified sensitive domains — among others, employment and worker management, access to essential public and private services (including credit and insurance), biometric identification, education and vocational training, law enforcement, and migration — or systems that serve as a safety component of a product already regulated under existing EU product-safety law. High-risk systems are not banned, but they carry the Act's most extensive conformity obligations.

Limited risk (transparency obligations). Systems with specific disclosure duties short of the full high-risk regime — most notably, systems that interact directly with people, such as chatbots, generally must make clear that a person is interacting with an AI system, and systems generating synthetic "deepfake" content generally carry labeling obligations.

Minimal risk. The large majority of AI systems in typical enterprise use — internal productivity tools, most recommendation engines, and similar applications — fall here, with no mandatory obligations under the Act.

Note

Treat these tier descriptions as an orientation map, not verbatim legal text. The Act's phased implementation means specific obligations become enforceable on different timelines, and official guidance from EU institutions continues to refine definitional boundaries. Verify a specific classification decision against current official guidance or legal counsel before relying on it in a real case — this lesson builds the orientation that makes that later verification faster and more accurate, not a substitute for it.

Knowledge check

A company deploys a highly sophisticated, cutting-edge AI model purely for internal engineering productivity — summarizing technical documentation for its own developers, with no external users and no bearing on any decision about an individual. What does the domain-based classification logic in this lesson suggest about its likely tier?

Select one answer.

A First-Pass Orientation Question Set

At an orientation level — well short of the formal classification methodology a dedicated governance course teaches — ask, in order: does this system's function resemble anything on the prohibited-practices list? Does it operate in an enumerated high-risk domain such as employment, credit, or biometric identification, or serve as a safety component of an already-regulated product? Does it interact directly with people or generate synthetic media? If none of the above apply, it is very likely minimal-risk. This sequence gives you a defensible first impression to bring into a conversation with a colleague or a dedicated governance specialist — not a final, audit-ready classification.

Correcting a Sophistication-Based Misclassification — Software Company

Compliance Analyst, enterprise software company

Context

A compliance analyst new to AI governance was asked to give a first-pass view on two AI features the company was launching: an advanced, technically impressive AI-powered code-review assistant for internal engineering use, and a simpler AI-powered chatbot answering basic customer billing questions on the company's public website.

Action

Her initial instinct was to flag the code-review assistant as higher risk because it was the more sophisticated and expensive system. Applying the orientation question set from this lesson instead, she recognized that the code-review tool served internal engineers only, with no external interaction and no bearing on decisions about individuals — very likely minimal-risk — while the simpler customer-facing chatbot, precisely because it interacts directly with the public, likely triggers the Act's limited-risk transparency obligations regardless of its comparative simplicity.

Outcome

Her corrected first-pass assessment properly directed the compliance team's limited review time toward the customer-facing chatbot's disclosure requirements, rather than the more impressive-seeming but lower-risk internal tool. Her manager used the example in onboarding training for new compliance staff as a clear illustration of why classification instinct must follow domain, not technical sophistication.

Quick check

Why does this lesson emphasize that EU AI Act risk classification is driven by use-case domain rather than technical sophistication?

Select one answer.

Exercise

~12 min

Your Task

List three AI systems from your organization or a plausible one. For each, apply the orientation question sequence from this lesson: prohibited-practices resemblance, high-risk domain or regulated-product safety component, direct interaction or synthetic media, or default minimal-risk. Write your first-pass tier for each system and one sentence justifying it based on domain and use case, not on how advanced the underlying technology seems.

Success looks like

  • Each system's classification is justified by domain and use case, not by a subjective sense of how impressive or advanced the technology is

Watch out for

  • Classifying a system as higher-risk simply because it uses a more advanced or well-known underlying AI model

Hint

Systems touching employment, credit, insurance, benefits eligibility, or biometric identification are the strongest high-risk domain candidates to check first.

Note

This lesson gives you a first-pass orientation, not a formal classification methodology. Producing an audit-ready classification record — with documented reasoning, conformity gap analysis, and evidence a regulator or auditor would actually ask to see — is the depth a dedicated AI governance and compliance course teaches. Treat this lesson as what makes that deeper material land correctly on first read.

Key takeaways
  • The EU AI Act organizes systems into four tiers — unacceptable/prohibited, high-risk, limited-risk (transparency), and minimal-risk — with obligations scaling to the tier.
  • Classification follows use-case domain and decision impact, not the sophistication of the underlying technology — a simple tool in a high-risk domain can outrank an advanced tool used for low-stakes internal purposes.
  • An orientation-level question sequence — prohibited practices, high-risk domain, direct interaction or synthetic media, default minimal-risk — gives you a defensible first impression to bring into a deeper review.
  • Treat any specific implementation deadline or definitional boundary as something to verify against current official guidance, given the Act's phased rollout and ongoing regulatory clarification.
  • This lesson is an orientation, not a formal classification methodology — that operational depth belongs to a dedicated AI governance and compliance course.