EU AI Act Risk Tier Tracker
A comprehensive guide to understanding and mapping the EU AI Act risk tiers for enterprise compliance.
The Framework of the AI Act
The European Union's Artificial Intelligence Act categorizes AI systems based on the risk they pose to citizens' rights and safety. This tiered approach means that the regulatory burden is directly proportional to the potential harm. Enterprises must accurately classify their systems to avoid significant penalties.
Risk Tiers Breakdown
| Tier | Definition | Example | Compliance Burden |
|---|---|---|---|
| Unacceptable | Clear threat to safety, livelihoods, or rights | Social scoring by governments | Banned |
| High-Risk | Negatively affect safety or fundamental rights | CV scanning in employment | Strict obligations before market entry (CE marking, data governance) |
| Limited Risk | Systems interacting with humans (e.g., chatbots) | Customer service chatbots | Transparency obligations (users must know they interact with AI) |
| Minimal Risk | All other AI systems | Spam filters, AI-enabled video games | No strict legal obligations, voluntary codes of conduct |
Financial Implications (Figures as of Q1 2024)
Non-compliance carries severe financial penalties. For prohibited AI practices, fines can reach up to €35 million or 7% of total worldwide annual turnover, whichever is higher. For high-risk violations, the cap is €15 million or 3%. Our estimates suggest a mid-sized enterprise deploying a high-risk system will incur an initial compliance setup cost of €200,000 to €350,000, primarily in data governance auditing and human oversight implementation.
Common Mistakes
- Under-classifying General Purpose AI (GPAI): Assuming a foundational model is 'limited risk' without assessing if it has systemic risk capabilities (currently defined as trained using >10^25 FLOPs).
- Ignoring the Supply Chain: Deployers are liable even if the core model was built by a third party. You must secure compliance documentation from your vendors.
- Waiting for Enforcement: The phased rollout means some bans apply within 6 months of entry into force, not the full 24-month grace period.
FAQ
- Does this apply to non-EU companies?
- Yes, the AI Act has extraterritorial reach. If the output of the AI system is used within the EU, the provider/deployer is subject to the Act, regardless of where they are headquartered.
- Are open-source models exempt?
- Partially. Free and open-source models are exempt from some obligations unless they are classified as high-risk, prohibited, or GPAI with systemic risk.
Authoritative Data
This brief is maintained by the Institute's quantitative research desk. Data points are aggregated from public filings, primary vendor pricing, and regulatory disclosures.