The risk-based approach: four risk tiers
The EU AI Act requires organizations to classify every AI system they develop or deploy into one of four risk tiers: Unacceptable, High, Limited, or Minimal/No Risk. This classification dictates the level of regulatory oversight and the specific legal obligations the organization must satisfy.
What it means
The intent is a proportionate regulatory framework where the burden of compliance increases with the potential for harm to health, safety, and fundamental rights. Rather than regulating the technology itself, the Act regulates the *application* of that technology in specific contexts.
In practice, this means an organization cannot simply label its AI as "safe." It must evaluate the intended purpose of the system against the criteria defined in the Regulation. For example, a system used for credit scoring or recruitment is generally categorized as High Risk, regardless of how the developer perceives the risk level.
The four tiers create distinct legal paths: Unacceptable risk systems are banned; High-risk systems must meet strict requirements regarding data governance and human oversight; Limited-risk systems face basic transparency obligations; and Minimal-risk systems remain largely unregulated.
How to meet it
- Maintain a comprehensive inventory of all AI systems currently in use or under development within the organization.
- Conduct a formal risk classification exercise for each system, mapping its intended purpose against the prohibited practices and high-risk categories listed in the Act.
- Document the rationale used to assign a risk tier to each system, specifically noting why it does or does not fall into a higher category.
- Implement transparency disclosures (e.g., "You are interacting with an AI") for all systems classified as Limited Risk, such as chatbots or image generators.
- Establish a governance process to re-evaluate the risk tier if the system's intended purpose, target audience, or functionality changes.
- For systems identified as High Risk, initiate the required conformity assessments and quality management system (QMS) protocols.
Evidence an auditor asks for
- An AI Asset Register that explicitly lists every AI tool and its assigned risk tier.
- A Risk Classification Report providing a reasoned justification for each categorization based on the EU AI Act's criteria.
- Screenshots or technical specifications proving that transparency notices are visible to end-users for Limited Risk systems.
- Internal policy documents outlining the process used to identify and categorize AI risks across the organization.
Common pitfalls
- Confusing "technical risk" (e.g., probability of a bug) with "regulatory risk" (the potential impact on fundamental rights).
- Assuming that using a third-party AI provider exempts the organization from classifying the system's use case within their own business context.
- Treating classification as a one-time project rather than an ongoing lifecycle requirement, leading to outdated and non-compliant risk labels.