AI Act Hub · risk framework
The four risk tiers of the EU AI Act, with everyday SME examples
The Act uses a risk-based framework. The category a system falls into affects the obligations around it. That makes inventory and classification the sensible starting point.
Here is the framework in business terms.
Tier 1: Unacceptable risk (prohibited practices)
Some AI practices are prohibited because they can threaten people’s safety, livelihoods or rights. The Commission’s list includes harmful manipulation, exploitation of vulnerabilities, social scoring, certain criminal-offence predictions, untargeted scraping to build facial-recognition databases, emotion recognition in workplaces and education, certain biometric categorisation and certain real-time remote biometric identification.
The prohibitions began to apply in February 2025.
SME reality: most SMEs will not run these systems. Be cautious of any product pitched as a way to score a person’s trustworthiness or infer protected characteristics.
Tier 2: High risk (the heaviest obligations)
High-risk uses include certain systems in critical infrastructure, education, healthcare, law enforcement, migration, justice, employment and access to essential services.
For an SME, that can include:
- A recruitment platform that screens or ranks CVs
- A tool that evaluates staff performance
- An automated credit or payment-terms decision about a customer
- AI used to determine access to education or training
These are ordinary business use cases, not science fiction. The requirements can include risk management, data quality, technical documentation, logging, information for deployers, human oversight, accuracy, robustness and cybersecurity.
The main high-risk obligations are scheduled to apply from 2 December 2027, following a change to the timetable. Check the current official guidance for the final position.
Tier 3: Limited risk (transparency duties)
This category is mainly about telling people when AI is involved and helping them identify certain AI-generated content.
Examples include:
- Telling users when they are interacting with a chatbot
- Making AI-generated content identifiable
- Clearly labelling deepfakes and certain AI-generated text intended to inform the public
The European Commission says these transparency rules come into effect in August 2026. (More in our chatbot transparency guide.)
Tier 4: Minimal or no risk
The Act does not introduce additional rules for many low-risk uses, such as spam filters, game AI and some inventory forecasting. Other laws still apply, including data-protection law where personal data is involved.
The special case: general-purpose AI
Large language models and other general-purpose AI models have their own provider obligations. If your business builds on top of one, your responsibilities still depend largely on how you deploy it and which people or decisions are affected.
Why classification comes first
A sensible process is:
- Inventory: list the AI systems and automated tools you use.
- Classify: assess each system against the relevant tier.
- Find the gaps: compare the requirements with what you have.
- Fix the important gaps: start with prohibited, high-risk and transparency issues.
- Keep the list current: review new tools and changes in use.
This guide is a readiness overview, not legal advice. Where formal legal sign-off is needed, we work with partner law firms in the UK and Germany.