Glossary · AI Act
Risk-Based Approach
The AI Act's structure of four risk tiers — unacceptable, high, limited, and minimal — with obligations scaled to each.
Explained in depth: AI Act overview
The AI Act regulates AI according to its potential for harm. Unacceptable-risk practices, such as social scoring by public authorities and manipulative techniques that cause significant harm, are prohibited outright under Article 5. High-risk systems, listed mainly in Annex III and in EU product safety legislation, are permitted but subject to the act's full compliance regime. Limited-risk systems face transparency obligations, such as disclosing that a user is interacting with a chatbot or that content is AI-generated. Minimal-risk AI, the vast majority of systems, carries no new obligations. General-purpose AI models sit somewhat outside this pyramid with their own obligations, heavier for models designated as posing systemic risk.
Why it matters
Risk classification is the first and most consequential step of AI Act compliance: everything an organisation must do follows from which tier each of its AI systems lands in. An inventory of AI systems with a documented classification per system is the foundational deliverable.
