Obligations

EU AI Act risk classification, explained.

The Act sorts systems by what they do and the context they do it in, and the tier determines nearly everything that follows. Getting the tier wrong does not produce slightly wrong obligations — it produces the wrong set entirely.

The tiers, and what changes at each

Four bands, and a set of transparency duties that cut across them.

The bands are about use and context rather than about model capability, which is the point most technical teams find counter-intuitive.

01

Prohibited practices

A small set of uses the Act does not permit at all. The relevant question is not whether your system is sophisticated but whether its use falls inside one of the described practices.

02

High-risk

The band that carries the substantial duties, including the deployer obligations and, for certain deployers, the fundamental rights assessment. Reached through the Act’s own criteria and annexes rather than through a general sense of seriousness.

03

Transparency-obliged uses

Interactive systems, and generated or manipulated content, attract disclosure duties that apply irrespective of whether the system is high-risk. A chatbot can be outside the high-risk band and still owe a transparency duty.

04

Minimal risk

Everything else. Still worth a dated record establishing that the classification was considered — because the classification is the fact everything else rests on.

This page cannot answer the question for you. It sets out the questions that decide it. Whether a duty attaches to a particular deployment depends on facts specific to your organisation, and whether your position is adequate is a judgement for your counsel. Nothing here is legal advice. Classification depends on the specific system, its intended purpose and the context of use. This page describes the structure, not your system’s tier.

How we classify

Deterministically, and conservatively where the Act is ambiguous.

Classification is decided by code reading declared facts against the Act’s criteria. It is never a model’s impression of how risky something sounds.

01

From declared facts

Intended purpose, context of use, the decision the system informs, and the sector. Facts you declare, not inferences drawn from a product description.

02

Conservative where ambiguous

Where the Act genuinely admits two readings, the classification errs toward the higher tier. That is a deliberate policy: the cost of over-classifying is work, and the cost of under-classifying is a missing obligation set.

03

Recorded either way

The classification and the basis for it are part of the document, so a reviewer can disagree with the conclusion on the reasoning rather than on the outcome.

The tier drives the rest

Classify before you assess.

Every other EU AI Act question — FRIA, deployer duties, transparency — is downstream of the tier. It is the first thing a determination establishes.