The EU AI Act introduces a four-tier risk classification system that determines the compliance obligations applying to any AI system placed on the EU market or used within it. Understanding which tier your systems fall into is the starting point for any AI governance programme.

What are the four risk tiers under the EU AI Act?

The regulation organises AI systems into four categories based on the potential harm they present.

Unacceptable risk systems are prohibited outright. These include AI used for social scoring by governments, real-time biometric identification in public spaces (with narrow exceptions), systems that exploit cognitive vulnerabilities, and emotion recognition in workplaces and educational institutions. These prohibitions have applied since February 2025.

High-risk systems are subject to the most significant compliance obligations. These are defined in Annex III of the Act and cover eight categories: biometric identification and categorisation, critical infrastructure safety components, education and vocational training, employment and worker management, essential private and public services (including credit scoring and health insurance risk assessment), law enforcement, migration and border control, and administration of justice. High-risk system obligations apply from August 2026, subject to potential extension under the Digital Omnibus proposals currently in trilogue.

Limited risk systems face transparency obligations only. Providers of chatbots must disclose that users are interacting with AI. Providers of deepfakes and AI-generated content published for public information purposes must ensure that content is labelled accordingly.

Minimal risk systems – the vast majority of AI applications, including spam filters and recommendation algorithms – face no mandatory obligations, though voluntary codes of practice are available.

What obligations apply to high-risk AI systems?

Providers of high-risk systems must implement a documented risk management system covering the full AI lifecycle. They must establish data governance frameworks ensuring training data meets quality criteria. Technical documentation must be prepared in a form sufficient for regulatory assessment. Human oversight mechanisms must be built in by design. Conformity assessments must be completed and systems registered in the EU database before deployment.

Deployers of high-risk systems must ensure appropriate human oversight, monitor systems for risks in operation, and maintain logs where systems generate them.

What is GPAI and what are its obligations?

General-purpose AI models – foundation models such as large language models that underpin many downstream applications – face a separate set of obligations effective from August 2025. Providers must publish summaries of training data, maintain technical documentation, and establish copyright compliance policies. Models assessed as posing systemic risk (based on training compute exceeding 10^25 FLOPs or other criteria) face additional requirements including adversarial testing, incident reporting to the AI Office, and cybersecurity measures.

Does the EU AI Act apply to organisations outside the EU?

Yes. The Act has extraterritorial scope equivalent to the GDPR. Any provider whose AI system is placed on the EU market, or any deployer using an AI system within the EU, is within scope regardless of where they are established. A company headquartered in the United States using an AI-powered recruitment tool that processes applications from EU residents is subject to the Act's obligations.

What are the penalties for non-compliance?

Fines for violations of prohibited AI practices reach €35 million or 7% of global annual turnover, whichever is higher. Violations of other obligations attract fines of up to €15 million or 3% of turnover. Providing incorrect information to authorities is subject to fines of up to €7.5 million or 1.5% of turnover.

How does the EU AI Act interact with GDPR?

The two frameworks are additive. Any AI system processing personal data must comply with both. Key intersection points include: the legal basis requirement applies to AI training on personal data; DPIAs may be required where AI processing meets the high-risk threshold under GDPR; and technical documentation required under the AI Act overlaps with accountability records required under GDPR Article 5(2). Organisations with mature GDPR programmes have a material head start on AI Act compliance.

What this means for your organisation

  • If you develop, deploy, or procure AI systems used in the EU, you are likely within scope of the AI Act regardless of where you are based.
  • The August 2026 deadline for high-risk AI obligations is not a distant planning horizon. Conformity assessments, technical documentation, and human oversight mechanisms must be in place before deployment.
  • AI systems that also process personal data require compliance with both the AI Act and GDPR. These obligations are additive, not alternative.
  • Organisations with no current AI inventory have no way to know which obligations apply to them.

What you should do now

  1. Conduct an AI systems inventory identifying every AI system your organisation develops, deploys, or procures.
  2. Classify each system against the four-tier risk framework to determine applicable obligations.
  3. For each high-risk system, assess the gap between current practice and the requirements of Articles 9 to 15.
  4. Document the assessment before the August 2026 deadline – the AI Act requires providers to document why a system is or is not high-risk.
  5. Review data processing agreements and DPIAs for any AI system handling personal data.

How Priventia helps

Priventia's AI Systems Inventory module allows you to register, classify, and assess every AI system against EU AI Act and NIST AI RMF obligations. The Compliance Intelligence Assessment covers AI governance alongside privacy and due diligence, producing a single Compliance Intelligence Brief across all active regulatory domains.