How do the EU AI Act risk tiers decide what applies to us?
The EU AI Act categorises AI systems into four risk tiers: unacceptable, high, limited, and minimal/no risk. These tiers directly dictate the applicable legal obligations, ranging from outright prohibition for unacceptable risks to stringent compliance requirements for high-risk systems, and lighter transparency duties or voluntary codes for lower-risk categories. Applicability is determined by the AI system's intended purpose and potential impact on fundamental rights and safety, rather than the technology itself.
The EU AI Act establishes a tiered risk approach to regulate AI systems, directly influencing the compliance burden for organisations. Systems deemed an "unacceptable risk," such as those enabling social scoring or manipulative techniques, are prohibited outright. "High-risk" AI systems, identified by their potential to harm health, safety, or fundamental rights (e.g., in critical infrastructure, employment, law enforcement), face the most rigorous requirements. These include robust risk management systems, data governance, technical documentation, human oversight, cybersecurity, and conformity assessments. "Limited risk" AI systems, like chatbots, primarily require transparency obligations, ensuring users are aware they are interacting with AI. Finally, "minimal or no risk" AI systems are subject to voluntary codes of conduct, encouraging best practices without mandatory legal obligations.
Practitioners must understand that the risk classification is not inherent to the technology itself but is determined by the AI system's specific intended purpose and use case. An AI system might be high-risk in one context (e.g., medical diagnosis) but minimal-risk in another (e.g., content recommendation). Organisations must conduct thorough assessments to accurately classify their AI systems, as misclassification can lead to non-compliance or unnecessary overhead. Frameworks like ISO/IEC 42001, while not explicitly mandated by the AI Act, provide a robust management system for AI. Implementing ISO/IEC 42001 can significantly aid organisations in meeting the stringent requirements for high-risk AI systems, particularly concerning risk management, data quality, transparency, and human oversight, thereby streamlining compliance efforts and demonstrating due diligence.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Chapter II (Prohibited AI practices), Chapter III (High-risk AI systems), Chapter IV (Transparency obligations for certain AI systems)
- Regulation (EU) 2024/1689, Annex III (High-risk AI systems)