Step by Step
U
Unacceptable risk — banned entirely
Certain AI applications are banned entirely: social scoring by governments, real-time facial recognition in public spaces, and subliminal manipulation techniques.
Example: a government deploying a citizen social credit scoring system being explicitly and entirely banned under this tier.
H
High risk — strict requirements
AI systems used in domains including medical devices, hiring, credit, education, law enforcement, and critical infrastructure face strict regulatory requirements.
Example: an AI system used to help make hiring decisions being subject to strict documentation, testing, and oversight requirements under this tier.
L
Limited risk — transparency obligations
Lower-risk applications face transparency obligations: chatbots must disclose they are AI, and deepfakes must be labeled as such.
Example: a synthetic video clearly labeled as an AI-generated deepfake, complying with this tier's transparency requirement.
M
Minimal risk — no regulation
The lowest-risk category, including things like spam filters and AI-powered games, faces no specific regulation under the Act at all.
Example: a simple AI-powered video game character behavior system falling into the minimal-risk, unregulated category.
Applied Walkthrough
1
A company needs to classify four different AI products they're deploying in the EU: a government social-scoring tool, a hiring-assistance AI, a customer service chatbot, and a simple spam filter.
2
The government social-scoring tool falls into the unacceptable risk tier and is banned entirely — it cannot legally be deployed regardless of any other considerations.
3
The hiring-assistance AI falls into the high-risk tier, requiring strict compliance measures, while the customer service chatbot falls into the limited-risk tier, only requiring disclosure that users are interacting with AI.
4
The simple spam filter falls into the minimal-risk tier, facing no specific regulation under the Act at all — illustrating how the same overall law applies dramatically different requirements based purely on each application's assessed risk level.
Exam Application
Exams test whether you can correctly classify a described AI application into all four EU AI Act risk tiers (unacceptable, high, limited, minimal) and whether you know the Act applies to any AI used in the EU regardless of where it was built — a frequently tested jurisdictional point.
⚠ Common Trap
The most common trap is forgetting the minimal-risk tier exists, treating the Act as having only three tiers (unacceptable, high, limited). The minimal-risk tier specifically covers low-stakes applications like spam filters and games, which face no regulation under the Act at all.
✓ Quick Self-Check
1. Name one AI application banned entirely under the unacceptable risk tier.
Government social scoring, real-time public facial recognition, or subliminal manipulation (any one).
Tap to reveal / hide
2. Name one domain falling under the high-risk tier.
Medical devices, hiring, credit, education, law enforcement, or critical infrastructure (any one).
Tap to reveal / hide
3. What transparency obligation applies to chatbots under the limited-risk tier?
They must disclose that they are AI.
Tap to reveal / hide
4. What level of regulation applies to minimal-risk applications like spam filters?
No specific regulation at all.
Tap to reveal / hide
5. Does the EU AI Act apply only to AI built within the EU?
No — it applies to any AI used in the EU, regardless of where it was built.
Tap to reveal / hide