Skip to content

Courses

Learning streak: 6 days in a row

Reading · 9 min · Lesson 5 of 9

The four risk levels

From prohibited practices to systems with no specific obligations.

The Act sorts AI uses by risk. Unacceptable-risk practices are banned outright, including social scoring, manipulative techniques that exploit vulnerabilities and emotion recognition in workplaces and schools. High risk covers uses listed in the Act, such as recruitment and worker management, creditworthiness, education and access to essential services, as well as AI in regulated products like medical devices.

Limited risk carries transparency duties: people must know when they are talking to a chatbot, and synthetic images, audio or video must be recognisable as such. Minimal risk, such as spam filters or AI in video games, has no specific obligations under the Act, although GDPR and other laws still apply.

Classify by use, not by tool. The same general-purpose model is minimal risk when it drafts a newsletter and high risk when it ranks job applicants. Obligations phase in over several years: the bans and the AI literacy duty have applied since February 2025, rules for general-purpose AI models since August 2025, and transparency duties such as chatbot disclosure since August 2026. After the 2026 amendment, duties for stand-alone high-risk uses such as hiring and credit scoring apply from 2 December 2027, and for AI in regulated products from 2 August 2028.

Key takeaways

  1. The Act has four tiers: unacceptable, high, limited and minimal risk.
  2. Risk depends on the use, not on the tool.
  3. Obligations phase in until 2028, and high-risk duties start in December 2027 or August 2028.