Auditen
Home / Frameworks / EU AI Act / The risk-based approach: four risk tiers

The risk-based approach: four risk tiers

The EU AI Act requires organizations to classify every AI system they develop or deploy into one of four risk tiers: Unacceptable, High, Limited, or Minimal/No Risk. This classification dictates the level of regulatory oversight and the specific legal obligations the organization must satisfy.

What it means

The intent is a proportionate regulatory framework where the burden of compliance increases with the potential for harm to health, safety, and fundamental rights. Rather than regulating the technology itself, the Act regulates the *application* of that technology in specific contexts.

In practice, this means an organization cannot simply label its AI as "safe." It must evaluate the intended purpose of the system against the criteria defined in the Regulation. For example, a system used for credit scoring or recruitment is generally categorized as High Risk, regardless of how the developer perceives the risk level.

The four tiers create distinct legal paths: Unacceptable risk systems are banned; High-risk systems must meet strict requirements regarding data governance and human oversight; Limited-risk systems face basic transparency obligations; and Minimal-risk systems remain largely unregulated.

How to meet it

Evidence an auditor asks for

  • An AI Asset Register that explicitly lists every AI tool and its assigned risk tier.
  • A Risk Classification Report providing a reasoned justification for each categorization based on the EU AI Act's criteria.
  • Screenshots or technical specifications proving that transparency notices are visible to end-users for Limited Risk systems.
  • Internal policy documents outlining the process used to identify and categorize AI risks across the organization.

Common pitfalls

  • Confusing "technical risk" (e.g., probability of a bug) with "regulatory risk" (the potential impact on fundamental rights).
  • Assuming that using a third-party AI provider exempts the organization from classifying the system's use case within their own business context.
  • Treating classification as a one-time project rather than an ongoing lifecycle requirement, leading to outdated and non-compliant risk labels.