Four tiers, and most business AI features land in the middle two

The AI Act sorts systems into unacceptable risk (banned outright - manipulative or social-scoring systems), high risk (subject to the heaviest obligations - things like AI used in hiring decisions, credit scoring, or safety-critical infrastructure), limited risk (mainly transparency obligations - users need to know they're talking to an AI), and minimal risk (few or no specific obligations).

A customer-support chatbot, an internal knowledge assistant, or a content-drafting tool typically falls into limited or minimal risk - the obligations there are mostly about disclosure and basic transparency, not the extensive conformity assessments high-risk systems require.

Don't assume your AI feature is high-risk just because it makes decisions that matter to a business. The high-risk category is defined by specific listed use cases - primarily around employment, credit, law enforcement, and safety-critical systems - not by general business importance.

Where founders get this wrong in both directions

Some startups panic and assume every AI feature triggers the heaviest compliance burden, which leads to over-engineering compliance processes for a simple limited-risk chatbot. Others assume a customer-facing AI feature has no specific obligations at all, missing the transparency requirement that users be told they're interacting with an AI system, which is a real EU AI Act requirement for many limited-risk applications.

Getting the tier right the first time - grounded in the Act's actual listed high-risk use cases, not a general sense of how important the feature feels - avoids both mistakes.

Limited risk: disclose it's AI

Most customer-facing chatbots need clear disclosure that the user is interacting with an AI system - a real, often-missed obligation.

High risk: specific listed uses only

Employment decisions, credit scoring, and safety-critical systems trigger the heaviest tier - not general business importance.

Build the tier assessment into the project scope, not after launch

Determining the risk tier is a design-time decision, not a legal afterthought - it shapes what disclosure language needs to be in the product, what documentation needs to exist, and whether a conformity assessment is required before the feature can launch in the EU market at all.

Not sure which tier your planned AI feature falls into? Talk to us before you scope the build.

Key takeaways

  • The EU AI Act has four risk tiers - unacceptable, high, limited, and minimal - and most everyday business AI features fall into the limited or minimal tiers, not high-risk.
  • High-risk status is defined by specific listed use cases like employment decisions, credit scoring, and safety-critical systems - not by how important the feature feels to the business.
  • Limited-risk systems, including most customer-facing chatbots, still carry a real transparency obligation: users must be told they're interacting with an AI system.
  • Determine the risk tier at design time, not after launch - it shapes required disclosures, documentation, and whether a conformity assessment is needed before EU market entry.
This is general information, not legal advice. The EU AI Act's risk-tier classification depends on your specific use case and deployment context - consult qualified EU regulatory counsel before launch.