Risk Tier Classification
The EU AI Act assigns applications to three broad risk categories, determining the regulatory burden.
Fines are severe
Non-compliance with prohibited AI practices can result in fines up to €35 million or 7% of global annual turnover, whichever is higher.
| Risk Tier | Examples | Obligations |
|---|---|---|
| Unacceptable Risk | Social scoring, subliminal manipulation, real-time biometric identification (exceptions apply). | Banned entirely within the EU. |
| High Risk | CV scanning tools, credit scoring, medical device AI. | Strict conformity assessments, logging, human oversight, and registration in an EU database. |
| Minimal/Limited Risk | Spam filters, basic chatbots (must declare they are AI). | Transparency obligations (e.g., users must know they are interacting with an AI). |
Timeline to Enforcement
- May 2024: Official adoption.
- November 2024: Prohibitions on unacceptable risk systems take effect (6 months post-entry).
- May 2025: General purpose AI (GPAI) rules apply.
- May 2026: High-risk system obligations fully enforceable.
Common Mistakes in Implementation
Firms frequently underestimate the scope of "AI". Even traditional statistical models embedded in HR software may qualify as high-risk systems under Annex III.