Is Your AI a Ticking Compliance Time Bomb? Find Out in 4 Steps
AI Governance

Is Your AI a Ticking Compliance Time Bomb? Find Out in 4 Steps

The EU AI Act sorts every AI system into 4 risk tiers, and your duties depend entirely on which one. Most are low-risk, but one wrong call can cost millions. Here's how to check.

AI Compliance, One Rule at a Time, Part 3 of the series This is the third in our weekly series taking one rule of AI regulation at a time and explaining, in plain language, what it means and how to comply. So far we have covered specific duties: chatbot disclosure and content labelling. This week we step back to the foundation that decides which rules apply to you at all: your risk tier. This is an explainer, not legal advice, and the law is still evolving, so confirm specifics with a qualified professional before acting.
The rule this week

The EU AI Act sorts every AI system into one of four risk tiers, unacceptable, high, limited, or minimal, and your obligations flow almost entirely from which tier applies. Most ordinary business AI lands in the lowest tier with no mandatory duties, but classifying wrongly, especially treating a high-risk system as low-risk, is the most expensive mistake you can make. Working out your tier is the first real step in compliance, because it tells you which of the rules in this series you actually need to follow.

In the last two episodes we looked at specific transparency duties. But before any of those rules matter to you, there is a prior question: what kind of AI are you actually running? The entire AI Act is built on a single idea, that obligations should scale with risk, and it puts that idea into practice by sorting every system into one of four tiers. Get your tier right and the rest of compliance becomes a clear, manageable roadmap. Get it wrong and you either waste money over-complying or expose yourself to serious penalties. Here is how the tiers work and how to place your own systems.

The four tiers, from most to least regulated

The first tier is unacceptable risk. A narrow set of AI uses is simply banned in the EU as a clear threat to people's rights and safety, things like social scoring and certain manipulative systems. There is no compliance pathway here; these uses are prohibited outright, and have been since February 2025. We will cover exactly what is banned in a later episode.

The second tier is high risk. These are systems used in sensitive areas, hiring and employment, credit scoring, education, healthcare, law enforcement, biometric identification, critical infrastructure, where a bad decision can seriously affect someone's life. High-risk systems are permitted, but only with heavy obligations: documented risk management, human oversight, record-keeping, and in some cases independent assessment before they go to market. This is the demanding tier, and correctly identifying whether you are in it matters more than anything else in classification.

The third tier is limited risk, also called transparency risk. This is where chatbots and generative AI content live, and it is the tier behind the first two episodes of this series. The duty here is disclosure: tell people they are dealing with an AI, and label AI-generated content. That is the whole obligation for this tier, no conformity assessments, just transparency.

The fourth tier is minimal risk, and this is where most AI actually sits. Spam filters, recommendation systems, AI in video games, the vast majority of everyday business tools fall here, and they carry no mandatory obligations under the Act at all. For a great many businesses, this is the reassuring reality: most of what you use is minimal risk.

The deadline detail that changed recently:

An update matters here. The Digital Omnibus, a set of amendments in force since July 2026, pushed back the deadlines for the high-risk tier. The heavy high-risk obligations now apply from December 2027 for most such systems, and from August 2028 for a narrower category, rather than in 2026. Two new prohibited uses were also added, taking effect December 2026. But note what did not move: the limited-risk transparency duties, chatbot disclosure and content labelling, took effect on schedule in August 2026. So if you are high-risk you have more time to prepare, but if you are limited-risk your duties are already live.

How to classify your own system

Work through it top down, in order, because the tiers are a hierarchy. First, ask whether your use is one of the banned practices; if so, stop, it cannot be used. Next, and most important, check whether it falls into a high-risk area: is it making or heavily influencing consequential decisions about people in areas like employment, credit, education, health, or law enforcement? If yes, treat it as high-risk and prepare for the heavier obligations. If not, ask whether it interacts with people or generates content, a chatbot, a virtual assistant, AI-generated media; if so, it is limited risk and owes the transparency duties from earlier in this series. If none of these apply, it is almost certainly minimal risk, with no mandatory obligations. Whatever tier you land on, write down your reasoning: regulators expect you to be able to show how you reached your classification.

The mistake that costs the most

There is one error worth guarding against above all others: misclassifying a high-risk system as limited or minimal risk. It is an easy trap, a hiring tool or a credit-decision tool can feel like ordinary software, but if it makes consequential decisions about people in a sensitive area, it carries the full weight of high-risk obligations, and treating it as low-risk leaves you badly exposed. When a system sits near the boundary, or spans more than one category, that is exactly the moment to get professional advice rather than guess. The cost of over-preparing a limited-risk system is small; the cost of under-preparing a high-risk one is not.

Your action this week

Make a simple list of every AI system your business uses, then run each one through the top-down check above and write its tier next to it, with a sentence on why. Most will come out as minimal risk, which is fine and expected. Flag anything that touches hiring, credit, education, health, law enforcement, or biometrics as a candidate for high-risk and a priority for closer review. Note any chatbots or generative tools as limited-risk, and confirm they meet the disclosure duties from Episodes 1 and 2. This single inventory is the backbone of your whole compliance effort; everything else in this series becomes easier once you know which tier each system is in. Next week, we look at the banned practices, the uses that fall in that top tier and are prohibited outright.

Frequently asked questions

What are the four risk tiers of the EU AI Act?

Unacceptable risk (prohibited outright), high risk (permitted but heavily regulated), limited risk (transparency duties like disclosing AI and labelling content), and minimal risk (no mandatory obligations). Your obligations flow almost entirely from which tier your system falls into, so classification is the foundation of compliance.

What makes an AI system high-risk?

Broadly, being used in a sensitive area where decisions seriously affect people: employment and hiring, credit scoring, education, healthcare, law enforcement, biometric identification, and critical infrastructure, or being a safety component in a regulated product. High-risk systems carry heavy obligations like risk management, human oversight, and record-keeping. Misclassifying one as lower-risk is the most expensive mistake in compliance.

What tier is a chatbot?

A chatbot that interacts with people is generally limited risk, also called transparency risk. Its obligation is disclosure: tell users they are dealing with an AI. Generative AI that creates content sits in the same tier, with a duty to label that content. These are the duties covered in Episodes 1 and 2 of this series, and they took effect in August 2026.

Does most of my business AI have obligations?

Probably not heavy ones. Most everyday AI, spam filters, recommendation systems, general productivity tools, falls into minimal risk, which carries no mandatory obligations under the Act. The duties concentrate in the high-risk and limited-risk tiers. It is still worth documenting that you assessed each system and why it is minimal risk.

When do the high-risk rules take effect?

Later than originally planned. Under the Digital Omnibus amendments in force since July 2026, the heavy high-risk obligations apply from December 2027 for most such systems and August 2028 for a narrower category. The prohibited practices have applied since February 2025, and the limited-risk transparency duties took effect on schedule in August 2026. So high-risk operators have more lead time, but transparency duties are already live.

Follow the series, get compliant one rule at a time

This is Part 3 of our weekly guide to AI regulation, breaking down one rule at a time so compliance feels manageable instead of overwhelming. Explore more clear, honest guides on AISetApp and follow along each week.

Explore more on AISetApp
Sources and further reading
  1. EU AI Act (Regulation (EU) 2024/1689), risk-classification framework and Annex III high-risk areas
  2. Digital Omnibus on AI (Regulation (EU) 2026/1744), in force 27 July 2026, on revised high-risk deadlines and new prohibitions
  3. 2026 practitioner guides to EU AI Act risk tiers and top-down classification from Jaggaer, Airia, Snowflake, and Glocert International
  4. GDPR Local and trail-ml analyses of high-risk criteria and the four-tier structure, 2026

Reviewed August 2026. This is an explainer, not legal advice. The law is evolving; verify specifics with a qualified professional before acting.

Researched and drafted with AI assistance, reviewed and edited by Yasser El Hardouz, who takes editorial responsibility for this article.