AI Risk Classification 101: The Four Tiers of the EU AI Act in Plain English
The EU AI Act drops every AI system into one of four risk tiers, and your obligations depend entirely on which one you land in. Here is each tier in plain English, with examples.
The EU AI Act sorts every AI system into four risk tiers: unacceptable (prohibited), high (heavily regulated), limited (transparency only), and minimal (essentially unregulated). The higher the risk to people, the heavier your obligations. Get the classification right and everything else falls into place — and the fastest test is to ask what happens to a person if the system gets it wrong.
| Tier | Plain-English test | Obligations |
|---|---|---|
| Unacceptable | Threatens rights or safety (social scoring, manipulation) | Banned outright |
| High | A wrong decision seriously affects a person (hiring, credit, biometrics) | Risk management, documentation, human oversight, conformity assessment |
| Limited | People could be deceived by a machine (chatbots, deepfakes) | Transparency and disclosure |
| Minimal | Low stakes for anyone (spam filters, forecasting) | None specific |
How does the EU AI Act classify risk?
The EU AI Act — Regulation (EU) 2024/1689 — rests on a single organizing idea that makes the whole thing far less intimidating than it first looks: the higher the risk an AI system poses to people, the heavier the obligations. A system that could wreck someone's life if it goes wrong is regulated tightly. A system that just filters spam is left alone.
This is the risk-based approach, and it drops every AI system into one of four tiers. Learning the tiers is the single most useful thing a business can do here, because your entire compliance burden flows from which one your system lands in. Get the classification right and everything else follows. Get it wrong and you either waste effort you didn't need to spend or, worse, miss obligations you did.
Even though this is a European law, the four-tier logic is worth learning for any business, because Canada's proposed AIDA and most emerging AI frameworks think the same way: find the high-stakes uses, regulate those, and leave the rest largely alone.
Tier One: Unacceptable Risk (Prohibited)
At the top sits a small set of AI practices considered so harmful they're banned outright. Not "regulated carefully" — not allowed at all.
The prohibited category targets uses that fundamentally threaten people's rights and safety. Examples the Act addresses include social scoring by public authorities that judges people's trustworthiness across unrelated contexts, AI that manipulates people through subliminal or deceptive techniques to their detriment, systems that exploit the vulnerabilities of specific groups such as children or people in economic hardship, and the untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases. Certain uses of real-time remote biometric identification in public spaces are heavily restricted too.
In plain terms: if an AI use feels like something out of a dystopian film — mass surveillance scoring, psychological manipulation of vulnerable people — it probably lives here. The vast majority of businesses never come close, but it's worth knowing the line exists.
Tier Two: High Risk (Heavily Regulated)
This is the tier that matters most for legitimate businesses, because it's where real, everyday, well-intentioned AI uses can land — and where the obligations get serious.
An AI system is generally high-risk when it's used in a context where a wrong or biased decision can significantly affect a person's rights, safety, or life opportunities. The Act points to areas including:
- Employment — screening job applicants, evaluating candidates, making promotion or termination decisions
- Access to essential services — credit scoring, eligibility for benefits, insurance decisions
- Education — scoring exams, determining admissions
- Biometric identification and categorization of people
- Critical infrastructure safety
- Law enforcement, migration, and administration of justice
- Safety components of regulated products
Build or deploy a high-risk system and the Act expects real work: a risk-management system, strong data governance to reduce bias, detailed technical documentation, record-keeping, transparency to users, meaningful human oversight, and appropriate accuracy and security — plus a conformity assessment before the system goes to market. This is exactly the kind of evidence an AI governance platform is built to assemble and keep current.
In plain terms: if your AI helps decide who gets hired, who gets a loan, who gets into a program, or who gets a public service, assume you're looking at high-risk obligations. This is the tier businesses most often underestimate.
Tier Three: Limited Risk (Transparency Obligations)
Most everyday commercial AI lives comfortably here. The concern at this tier isn't that the system makes life-altering decisions — it's that people shouldn't be deceived about interacting with a machine or consuming machine-made content.
The obligations are mostly about transparency and disclosure:
- Chatbots and virtual assistants must make clear that a person is interacting with an AI, not a human
- AI-generated or manipulated content — synthetic images, audio, and video, including deepfakes — generally must be disclosed as artificially generated
- AI-generated text published to inform the public on matters of public interest carries disclosure expectations in defined situations
- Emotion-recognition and biometric-categorization systems must inform the people exposed to them
In plain terms: your customer-service chatbot needs to say it's a bot, and content your business generates with AI should be labelled as such. The effort is modest, and much of it is simply good, trust-building practice you'd want to follow anyway.
Tier Four: Minimal Risk (Essentially Unregulated)
The overwhelming majority of AI systems fall into this bottom tier and carry no specific obligations under the Act. Spam filters, AI in video games, inventory-forecasting tools, recommendation engines for your own product catalogue, grammar checkers — none of these pose much risk to anyone's rights, and the Act largely leaves them alone.
Businesses are encouraged to follow voluntary codes of conduct and good practice for these systems, but there's no mandatory compliance regime. If your AI use is genuinely low-stakes and steers clear of the sensitive contexts above, this is almost certainly where you sit.
In plain terms: most of the AI a typical Canadian business uses day to day is minimal risk, and you can use it freely — while still applying good judgment about privacy and accuracy.
A Word on General-Purpose AI
Sitting a bit across these tiers is a separate set of rules for general-purpose AI models — the large foundation models that power many downstream tools. Providers of these models face their own transparency and documentation duties, with extra obligations for the most capable models that could pose systemic risk. If you use rather than build these models, the practical takeaway is simpler: how you deploy the model still gets classified by the four-tier logic above.
How to Use This
Take your AI inventory and run each system through one question: what happens to a person if this gets it wrong? If the answer is "a life-altering decision goes against them," you're likely in high-risk territory and should treat it seriously. If the answer is "they get a slightly worse product recommendation," you're in minimal-risk territory. That single question resolves most classifications, and doing it deliberately — with the result written down in your governance records — is the foundation of any credible AI compliance posture. Pair it with a PIPEDA assessment and you've covered the privacy side that rides alongside every AI system.
This article is general information, not legal advice — classifying a specific system can get nuanced, so confirm high-stakes cases with a qualified professional.
Running your systems through this four-tier logic, recording the result, and keeping it current as your tools change is exactly the workflow a platform like Valdra is built to make routine — so your classification is always ready when a customer, partner, or regulator asks to see it.
Frequently asked questions
What are the four risk levels in the EU AI Act?+
They are unacceptable risk (prohibited practices like social scoring), high risk (heavily regulated systems such as hiring, credit, and biometrics), limited risk (transparency obligations for chatbots and AI-generated content), and minimal risk (essentially unregulated tools like spam filters and forecasting). Obligations scale directly with the tier.
What counts as a high-risk AI system?+
A system is generally high-risk when a wrong or biased decision can significantly affect a person’s rights, safety, or life opportunities — think AI used in employment, credit scoring, access to essential services, education admissions, biometric identification, law enforcement, or as a safety component of a regulated product.
What are the obligations for limited-risk AI?+
Limited-risk systems mainly carry transparency duties: chatbots must disclose that users are dealing with AI, AI-generated or manipulated images, audio, and video generally must be labelled as artificial, and emotion-recognition or biometric-categorization systems must tell the people exposed to them. The effort is modest and it builds trust.
Is most business AI high-risk under the EU AI Act?+
No. The overwhelming majority of everyday business AI — spam filters, inventory forecasting, product recommendations, grammar checkers — is minimal or limited risk and carries few or no specific obligations. High-risk classification is reserved for sensitive contexts like hiring, credit, and biometrics.
How do I classify my own AI system?+
Ask one question of each system: what happens to a person if it gets this wrong? A life-altering decision points to high risk; a slightly worse recommendation points to minimal risk; deceiving someone about a machine points to limited risk. Write the result down — deliberate, documented classification is the foundation of AI compliance.
AI governance and privacy compliance, simplified.
Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.
Explore Valdra