The EU AI Act explained — risk tiers and what they mean for you
TL;DR — The AI Act is the EU's regulation for artificial intelligence. It classifies AI systems by risk — unacceptable, high, limited, and minimal — and scales obligations accordingly. High-risk systems carry the heaviest duties: risk management, data governance, technical documentation, human oversight, and conformity assessment. If your product embeds AI, your first job is to determine which risk tier applies.
What is the AI Act?
The AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal law governing artificial intelligence. It applies to providers and deployers of AI systems placed on the EU market or whose output is used in the EU — regardless of where the provider is established.
Its central mechanism is a risk-based approach: the higher the risk an AI system poses to health, safety, and fundamental rights, the stricter the obligations.
The four risk tiers
1. Unacceptable risk — prohibited. Certain practices are banned outright, such as social scoring by public authorities and manipulative or exploitative systems.
2. High risk — heavily regulated. AI used in critical areas (for example, safety components of products, biometric identification, critical infrastructure, employment, essential services, law enforcement) must meet strict requirements before and during market placement.
3. Limited risk — transparency obligations. Systems like chatbots or AI-generated content must disclose that users are interacting with, or seeing output from, AI.
4. Minimal risk — largely unregulated. The majority of AI systems fall here, with no specific obligations under the Act.
There is also a distinct regime for general-purpose AI (GPAI) models, with obligations that scale further for models presenting systemic risk.
What do high-risk obligations look like?
Providers of high-risk AI systems must, among other things:
- Establish a risk-management system across the lifecycle
- Apply data governance to training, validation, and testing data
- Maintain technical documentation and automatic logging
- Ensure appropriate human oversight
- Achieve suitable levels of accuracy, robustness, and cybersecurity
- Undergo conformity assessment and register the system
Deployers of high-risk systems carry their own obligations around use, monitoring, and human oversight.
Why classification is the hard part
The most consequential — and often most difficult — step is determining which tier your system falls into. Misclassifying a high-risk system as limited risk exposes you to significant non-compliance. The classification depends on the system's intended purpose and its area of use, and it interacts with existing product-safety legislation.
This is why a structured scoping step matters before you invest in controls.
How the AI Act overlaps with the CRA
If your AI system is embedded in a product with digital elements, both the AI Act and the CRA can apply. The cybersecurity obligations of the AI Act (robustness, security of high-risk systems) align closely with CRA product-security requirements — shared evidence such as risk assessments and security testing serves both.
Timeline
The AI Act applies in phases:
- Prohibitions on unacceptable-risk practices apply first
- GPAI obligations follow
- High-risk obligations phase in through 2026-2027
Exact dates depend on the system category; confirm against current official sources.
The risk pyramid at a glance
▲ UNACCEPTABLE
╱ ╲ → prohibited outright
╱ ╲
╱ HIGH ╲ → strict obligations,
╱ RISK ╲ conformity assessment
╱─────────╲
╱ LIMITED ╲ → transparency duties
╱ RISK ╲ (disclose AI use)
╱───────────────╲
╱ MINIMAL ╲ → no specific
╱ RISK ╲ obligations
╱─────────────────────╲
(most AI systems live here)
The higher up the pyramid, the heavier the obligations — and the fewer systems occupy each level. Most AI is minimal-risk; the regulatory weight concentrates at the top.
Provider vs deployer
The AI Act distinguishes two main roles, and you may be both:
| Provider | Deployer | |
|---|---|---|
| ▸ Who | Develops/places the AI system on the market | Uses an AI system under its authority |
| ▸ Core duty | Build compliant systems, run conformity assessment | Use as intended, ensure oversight, monitor |
| ▸ Typical example | An AI vendor | A company using a vendor's AI tool |
Getting the role right matters, because the obligations differ. A company that fine-tunes or substantially modifies a system can shift from deployer to provider.
Frequently asked questions
Does the AI Act apply to us if we're outside the EU? Yes, if your AI system is placed on the EU market or its output is used in the EU. Location of the provider does not exempt you.
We only use third-party AI — are we covered? Potentially, as a deployer — especially for high-risk uses, where deployers carry monitoring and oversight duties. And if you modify a system substantially, you may become a provider.
What about general-purpose AI models? GPAI models have their own obligations, which scale further for models presenting systemic risk. If you build on or provide such models, this regime is relevant to you.
How do we know if we're high-risk? Classification depends on the system's intended purpose and area of use, and interacts with existing product-safety law. It is the decisive first step — scope it before investing in controls.
What to do now
- Inventory your AI — every model and system, and its intended purpose.
- Classify by risk tier — this drives everything downstream.
- For high-risk systems, begin building the risk-management, data-governance, and documentation foundations early.
- Add transparency notices where limited-risk obligations apply.
A free scope review helps you determine how the AI Act applies across your product portfolio.
→ Related: How EU compliance works
Where do most teams get AI Act classification wrong? The most common error is treating a system as limited-risk when its intended use places it in a high-risk category. Because classification drives the entire obligation load, confirming it early — before investing in controls — is the single highest-value step.
NexCyber provides a readiness analysis, not legal advice. AI Act classification and conformity assessment for high-risk systems may require legal review and accredited notified bodies.
Last reviewed 2026-07-10.