The EU AI Act's central design principle is risk proportionality: the stricter the potential harm, the more demanding the obligations. The regulation establishes four risk tiers, each with a distinct obligation set. Understanding which tier applies to a given AI system is the first step in any compliance analysis.
The Four Risk Tiers
Tier 1 (Prohibited) covers ten AI practices that are unconditionally banned under Article 5. Tier 2 (High-Risk) covers AI systems listed in Annex I (product safety components) and Annex III (standalone high-risk applications) under Article 6. These systems must meet requirements in Articles 9-15 and undergo conformity assessment before market entry. Tier 3 (Limited Risk) covers AI systems with specific transparency obligations under Article 50, such as chatbots and emotion recognition systems. Tier 4 (Minimal Risk) covers all other AI systems, which are not subject to mandatory obligations under the regulation -- though voluntary codes of conduct are encouraged.
Article 6(3) Derogation
Article 6(3) introduces a derogation mechanism that allows an AI system listed in Annex III to be reclassified as non-high-risk if four cumulative conditions are met: it performs a narrow procedural task; it supports human review without replacing human decision-making; it detects patterns in pre-existing data; and it is not intended to profile natural persons. However, this derogation is overridden when the system performs profiling of natural persons, in which case it remains high-risk regardless.
Regulation (EU) 2024/1689 — Article 6(2)
“In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.”
| Risk Tier | Legal Basis | Core Obligation |
|---|---|---|
| Prohibited | Article 5 | Unconditional ban -- do not develop or deploy |
| High-Risk (Annex I) | Article 6(1) | Full compliance requirements Articles 9-15 + conformity assessment |
| High-Risk (Annex III) | Article 6(2) | Full compliance requirements Articles 9-15 + conformity assessment |
| Limited Risk | Article 50 | Transparency notifications to end users |
| Minimal Risk | N/A (no obligation) | Voluntary codes of conduct under Article 95 |