EU AI Act: the four risk categories

How the EU AI Act classifies artificial intelligence systems into four risk levels and what that means for your company.

The EU AI Act does not treat all artificial intelligence the same way. Obligations depend on the risk a system poses to people. So the first step for any company is to know which category its systems fall into.

The four levels

  • Unacceptable risk: practices that are prohibited, such as harmful manipulation of behavior or social scoring of people.
  • High risk: systems used in sensitive areas such as employment, education, credit or essential services. Detailed requirements apply to them.
  • Limited risk: systems with transparency obligations, for example chatbots, where people must know they are talking to a machine.
  • Minimal risk: most applications, for which there are no specific obligations.

What high-risk systems require

  • Risk management throughout the system's life.
  • Quality and governance of the data used for training.
  • Technical documentation and event logging.
  • Human oversight.
  • Accuracy, robustness and cybersecurity.

Who it applies to

The regulation places obligations both on those who develop systems and on those who use them in their work. It also applies to companies outside the EU when their systems are offered on the EU market or their output is used there.

Where to start

Make an inventory of the AI systems you use or develop, including the off-the-shelf tools staff use every day. Classify each one by risk and focus first on those that affect decisions about people.

Related serviceAI Compliance and SecurityEU AI Act, ISO/IEC 42001, risk assessment and governance frameworks for AI systems.Learn more

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573