Back to Knowledge Base
Knowledge Base · fundamentals

AI Act risk tiers: how a system is classified, and why the model is not the answer

15 April 2026 7 min read AI Act

The AI Act sets four tiers. The tier attaches to the system in its context of use, not to the underlying model.

The short answer

The AI Act sets four tiers. **The tier attaches to the system in its context of use, not to the underlying model.**

``` unacceptable prohibited outright Article 5 high permitted with substantial obligations Article 6 + Annex I / Annex III limited transparency duties only Article 50 minimal no obligations ```

**The same model can sit in three different tiers inside the same company.** A language model summarising internal documents is minimal risk. The same model screening job applications is high risk. The same model inferring the emotional state of employees is prohibited.

This is the single most useful thing to understand about the AI Act, because it means **classification is an exercise you run per use case**, and an inventory of models tells you almost nothing about your exposure.

Tier 1 — Unacceptable risk, Article 5

Eight practices are banned outright. They have been enforceable since **2 February 2025** and they carry the regulation's highest penalty: up to **EUR 35 000 000 or 7 % of total worldwide annual turnover**.

Among them:

likely to cause significant harm;

or disproportionate to the behaviour;

recognition databases;

reasons;

trade union membership, religious beliefs or sexual orientation.

**A prohibited practice cannot be remediated by documentation.** Every other tier is a matter of doing the work properly. This one is a matter of stopping.

**And it is most often reached by purchase, not by design.** An interview-analysis tool that scores candidate enthusiasm, a call-centre feature that reports agent sentiment, a productivity monitor that flags disengagement — these arrive as product features, not as AI projects, which is exactly why they escape review.

  • manipulative or deceptive techniques that materially distort behaviour and cause or are
  • exploitation of vulnerabilities due to age, disability, or social or economic situation;
  • social scoring leading to detrimental treatment in contexts unrelated to the data's origin,
  • untargeted scraping of facial images from the internet or CCTV to build or expand facial
  • **inference of emotions in the workplace and in education**, except for medical or safety
  • biometric categorisation to infer sensitive attributes such as race, political opinions,

Tier 2 — High risk

Two independent routes in. **Either one is sufficient.**

**Route A — Annex I: the AI system is a product or a safety component**

Where the AI system is itself a product covered by EU sectoral legislation listed in Annex I, or is a safety component of such a product, **and** that product is required to undergo a third-party conformity assessment under that legislation.

**These obligations apply from 2 August 2027**, later than the rest.

**Route B — Annex III: the use case is listed**

Regardless of what the product is, the system is high risk if it falls within a listed area, including: biometrics; critical infrastructure; education and vocational training; employment, worker management and access to self-employment; access to essential private and public services; law enforcement; migration, asylum and border control; and the administration of justice and democratic processes.

**These apply from 2 August 2026.**

**There is a narrow derogation:** a system in an Annex III area is not high risk where it does not pose a significant risk of harm — for instance where it performs a narrow procedural task, improves the result of a previously completed human activity, or performs a preparatory task. **But the derogation must be documented and, in defined cases, registered before placing on the market.** It is an assessment you record, not a conclusion you assume.

**What high risk actually requires**

For **providers**: a risk management system, data governance, technical documentation, automatic record-keeping, information and instructions for deployers, human oversight by design, and appropriate accuracy, robustness and cybersecurity — plus a quality management system, conformity assessment, EU declaration of conformity and CE marking.

For **deployers** — and this is where most organisations sit: use in accordance with the instructions, assign human oversight to people with the competence and authority to exercise it, ensure input data is relevant and sufficiently representative, monitor operation, keep logs, and inform workers' representatives and affected workers before putting a high-risk system into use in the workplace. Certain deployers — including bodies governed by public law and entities providing certain essential services — must also carry out a **fundamental rights impact assessment** before first use.

Tier 3 — Limited risk: transparency, Article 50

No approval, no conformity assessment. **Disclosure.**

artificially generated or manipulated.

disclosed, subject to defined exceptions.

**The machine-readable marking requirement is a technical obligation on the generator**, not a labelling policy on the publisher. It applies from **2 August 2026**.

  • People must be informed they are interacting with an AI system, unless it is obvious.
  • Synthetic audio, image, video and text must be **marked in a machine-readable format** as
  • Deep fakes must be disclosed as such.
  • AI-generated text published to inform the public on matters of public interest must be

Tier 4 — Minimal risk

Everything else, and **that is most AI in commercial use**: spam filtering, recommendation of non-critical content, forecasting, code assistance, document search.

No obligations follow. **But the conclusion has to be reached, not assumed** — and the record of having reached it is what makes the difference between a defensible position and an opinion.

How to classify without over- or under-shooting

1. **List use cases, not models.** One line per "system X, used to decide Y, about Z". 2. **Screen every line against Article 5 first.** It is in force, it is the most expensive tier, and it cannot be fixed later. 3. **Then test against Annex III by function**, not by department name. "HR analytics" is not a classification; "ranks candidates for interview" is. 4. **Record the minimal-risk conclusions too.** An unrecorded decision is indistinguishable from no decision. 5. **Re-run classification when the use changes.** A system repurposed into a new decision can change tier without a single line of code changing.

Tools available on NexCyber

Further reading

What is the EU AI ActArticle 5 prohibited practices in force since February 2025AI Act × CRA — what overlaps for AI products with digital elementsOne evidence set across five EU regulationsAI Act regulation overview

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. The AI Act applies in phases, and guidelines, harmonised standards and codes of practice supporting classification continue to be adopted — verify against the current text of Regulation (EU) 2024/1689 and the Official Journal. Consult your competent authority or a qualified adviser.*

This is an educational explainer. For the canonical regulation reference, see the dedicated AI Act page — or run an assessment to see how it applies to your product.