The AI Act's risk levels. And the point where an SME ends up inside one without noticing.
Almost every explanation starts with a colourful pyramid. The pyramid isn't in the regulation, and the question that really matters isn't which level AI sits at, but which level your use of it sits at.
There are four tiers: prohibited practices, high-risk, transparency obligations, minimal risk. The regulation doesn't use the word levels and doesn't draw any pyramid.
Classification follows the use, not the tool. The same generative model is minimal risk when it writes product descriptions, and high-risk when it filters job applications.
Point 4 of Annex III is the one that reaches ordinary businesses. Recruitment, selection, CV screening, performance evaluation: all high-risk.
Two prohibitions apply to ordinary companies too: inferring emotions in the workplace, and building face databases by scraping images from the web without a target.
This piece belongs to the guide on AI Act obligations for businesses and SMEs and looks at classification on its own. It's written for people running a business, and it stops where a lawyer's work begins.
Four tiers, and the pyramid nobody wrote
Regulation (EU) 2024/1689 sets up four different treatments, but doesn't call them levels or draw them. The pyramid you see everywhere is a popular illustration, handy for explaining and absent from the text. It's worth saying, because people who look for the pyramid in the law don't find it and assume they've misread.
| Tier | What it means | From when |
|---|---|---|
| Prohibited practicesArticle 5 | Ten practices that can't be placed on the market, put into service or used. No amount of compliance makes them acceptable. |
2 February 2025 for the original eight, 2 December 2026 for the two added in 2026 |
| High-riskArticle 6 and Annex III | The bulk of the regulation: risk management, data quality, documentation, human oversight, specific obligations for the deployer. |
2 December 2027 for Annex III systems, 2 August 2028 for Annex I systems, after the 2026 postponement |
| Transparency obligationsArticle 50 | Say when there's an AI involved, mark generated or manipulated content, disclose synthetic voices and faces. |
2 August 2026 |
| Minimal riskeverything else | No specific obligations beyond the general ones, including staff AI literacy under Article 4. Most everyday uses sit here. |
Article 4 has applied since 2 February 2025 |
The useful takeaway is that the tiers describe uses, not technologies. No tool is high-risk in itself, and the same software licence can sit in two different tiers depending on what you do with it.
The prohibited practices, and the two that reach ordinary companies
Article 5 listed eight prohibited practices, in force since 2 February 2025, and the 2026 digital omnibus added two more, applicable from 2 December 2026: the non-consensual generation or manipulation of intimate images of identifiable people, and the material covered by Directive 2011/93/EU. Of the original eight, six concern scenarios far removed from a private business: social scoring, predictive policing based on personality traits, real-time biometric identification for law enforcement, and biometric categorisation to infer protected characteristics.
Two, on the other hand, can happen to anyone. The first is inferring emotions in the workplace and in education, prohibited with some exceptions: this catches software that analyses employees' tone of voice on calls, or facial expressions on video calls, to measure engagement.
The second is creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage. It applies to anyone thinking of building an archive of faces by collecting photos from the web.
Breaching a prohibition falls in the regulation's highest penalty band, in Article 99: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
The two routes into high-risk
Article 6 sets out two separate routes, and mixing them up is the most common mistake. The first goes through products: the system is a safety component of a product, or is itself a product, covered by the harmonisation legislation listed in Annex I, and that product is subject to third-party conformity assessment.
The second goes through use cases: the system falls under one of the eight areas in Annex III. This is the route that concerns service businesses, retail and light manufacturing, because it doesn't depend on how the tool is built but on what you have it do.
The two routes also run on different timelines, and both were moved in 2026. Regulation (EU) 2026/1744 rewrote Article 113: the obligations in Chapter III, Sections 1, 2 and 3, apply from 2 December 2027 for high-risk systems in Annex III, and from 2 August 2028 for those in Annex I. The original date was 2 August 2026 for both.
The postponement covers the requirements for high-risk systems, not the whole regulation. The prohibitions in Article 5, AI literacy under Article 4 and the transparency obligations in Article 50 keep their dates, so a business gains no time on the things that actually concern it today.
The eight areas in Annex III, and which one concerns you
Annex III lists eight areas. Five concern almost exclusively the public sector or regulated activities, and for an ordinary private business they take thirty seconds to read. The three worth a proper look are 4, 5 and, in part, 1.
| Point | What it covers | Does it concern an SME? |
|---|---|---|
| 1 · Biometrics | Remote biometric identification, biometric categorisation based on sensitive attributes, emotion recognition. Simply verifying that a person is who they claim to be is left out. |
Rarely, and only if you use systems of this kind. Emotion recognition at work is prohibited by Article 5 in any case. |
| 4 · Employment and work | Recruitment and selection, in particular targeted adverts, analysing and filtering applications, evaluating candidates. And decisions on promotion, termination, task allocation, and monitoring and evaluating performance. |
Yes, and it's the most common case. A tool that screens CVs is enough. |
| 5 · Essential services | Eligibility for public benefits, creditworthiness assessment or credit scoring, pricing and risk assessment in life and health insurance, handling emergency calls. |
Only if you work in credit or insurance. Detecting financial fraud is excluded. |
| 2, 3, 6, 7, 8 | Critical infrastructure, education and vocational training, law enforcement, migration and border control, justice and democratic processes. |
No, unless the business works in those sectors or on behalf of public authorities. |
Point 4 is the surprise, because it doesn't take anything exotic. A twenty-person company that buys a tool to sort incoming CVs is using a system the regulation classifies as high-risk, with the deployer obligations that follow.
The exemption that lightens the load, and the limit that closes it
Article 6(3) provides a way out. A system listed in Annex III is not considered high-risk if it doesn't pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making.
At least one of four conditions must be met: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations without replacing or influencing the previous human assessment without proper review; or it performs a preparatory task for an assessment covered by Annex III.
“Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.”
Regulation (EU) 2024/1689, Article 6(3)
That line shuts the door on the most interesting case. A tool that ranks CVs by learning from applicants' profiles is profiling, and the exemption doesn't save it. Paragraph 4 adds that a provider who believes the exemption applies must document the assessment before placing the system on the market.
The tier where almost everything you use sits
An assistant answering customers, a model writing product descriptions, a system transcribing calls or translating spec sheets isn't high-risk just by existing. It sits in the transparency obligations band of Article 50, which applies from 2 August 2026, or straight in minimal risk.
The obligations in that band are about informing people: say there's an AI involved when a person interacts with it, mark generated or manipulated content where required, disclose synthetic voices and faces. The full detail, split between provider and user, is in the guide to SME obligations.
Minimal risk carries no specific obligations, but it isn't a blank. The AI literacy obligation in Article 4 still applies, from 2 February 2025, and so do all the personal data rules described on the page about the AI Act and the GDPR.
How to classify your own case in half an hour
Classification works by use, so the job starts from the list of uses, not the list of suppliers. For each system in the business, answer four questions in order, and stop at the first yes.
One: does it fall under one of the practices in Article 5? If so, switch it off; no organisational measure makes it acceptable. Two: does the use fall into one of the eight areas in Annex III? What counts here is the actual purpose, not the tool's brand name.
Three: does the system talk to people or produce published content? Then you need the disclosures in Article 50. Four: none of the above? Minimal risk, and training for the people who use it still applies.
Write the answers down, because classification is an assessment, and an undocumented assessment doesn't exist. The sheet you end up with is the same one you need for the other obligations, so you fill it in once and use it three times.
The human checkpoint, which moves the tier
There's a practical point the regulation rewards and almost nobody makes use of: where the decision sits. A system that prepares and flags, leaving the choice to a person who genuinely reviews it, is in a different position from one that decides on its own, and the exemption in Article 6(3) turns on exactly that line.
In the systems we build, the rule is written before the code: any message that commits the business, such as offers, quotes, prices and confirmations, goes out only after a person has read and approved it. Replies drawing on information the owner has already approved can go out on their own, the owner switches that on and off channel by channel, and the reply says it comes from a system, as Article 50 requires.
The full scope, including what we never do, is in our AI principles, and the list of systems we actually use is on the AI transparency page.
Questions and answers
How many risk levels does the AI Act have?
In practice there are four tiers: prohibited practices (Article 5), high-risk (Article 6 and Annex III), transparency obligations (Article 50), and minimal risk, which is everything else.
The regulation never uses the word levels and contains no pyramid: the one you see everywhere is a popular illustration, handy for explaining but absent from the text.
Which practices are prohibited?
Article 5 listed eight, in force since 2 February 2025, including subliminal or manipulative techniques causing significant harm, exploiting vulnerabilities due to age or disability, social scoring, untargeted scraping of facial images to build face databases, and inferring emotions at work and in education, with some exceptions. The 2026 omnibus added two more, applicable from 2 December 2026, on the non-consensual generation of sexually explicit material.
A breach falls in the highest band of Article 99: up to €35 million or 7% of worldwide annual turnover.
When is a system considered high-risk?
There are two routes. The first: the system is a safety component of a product, or is itself a product, covered by the legislation in Annex I and subject to third-party conformity assessment. The second: the use falls into one of the eight areas in Annex III.
Paragraph 3 provides an exemption for Annex III systems that perform narrow procedural or preparatory tasks and pose no significant risk. That exemption never applies if the system performs profiling of natural persons.
Can an SME use a high-risk system without knowing it?
Yes, and the common case is point 4 of Annex III, on employment and workers management: recruitment and selection, targeted adverts, analysing and filtering applications, evaluating candidates, decisions on promotion and termination, performance monitoring.
A twenty-person company that buys a tool to screen CVs is using a high-risk system, with the deployer obligations that follow.
Where does a chatbot or text generator fit?
Outside high-risk, in the transparency obligations band of Article 50, which applies from 2 August 2026. An assistant talking to customers and a model writing text aren't high-risk just by existing.
The classification changes if the same tool is used for an Annex III purpose, for example to assess job applicants. What counts is the use, not the product.
Notes on sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 5 for prohibited practices, Article 6 for the classification rules and the exemption in paragraph 3, Annex III for the eight areas, Article 50 for transparency obligations, Article 99 for the penalty bands, Article 113 for the dates of application.
- Regulation (EU) 2026/1744, the digital omnibus on AI, published on 24 July 2026: the two new points in Article 5(1), applicable from 2 December 2026, and the rewrite of Article 113 moving Chapter III, Sections 1, 2 and 3, to 2 December 2027 and 2 August 2028. The out-of-date high-risk dates are still everywhere, and this is where it pays to check the source.
- The pyramid picture of risk levels doesn't appear in the text of the regulation. It's a popular summary common in institutional communications and commentary, and this page names it as such rather than attributing it to the law.
- The Annex III entries are summarised. For a classification with legal effect, read the full text of the relevant point, because each item contains exclusions this page doesn't cover in full.
- This page doesn't list the obligations on providers and deployers of high-risk systems, because they are covered in Chapter III and need a dedicated reading, usually with a professional.
This article is a practical overview, not legal advice. On classifying a specific system, which has real consequences, the answer has to come from a professional who looks at your business.
Classification is done by use. So it's done by looking at your processes.
Working out which tier each of your systems falls into takes the list of uses, not the list of suppliers, and you can write it yourself in a morning. The human checkpoint moves the tier a system falls into, and only if it's part of the design: bolted on later, it means redoing the classification from scratch. It's fifteen minutes on a call, with the Cruscotto open.