The Four Risk Tiers Explained
The EU AI Act organises AI systems into four tiers based on the potential harm they could cause. Unacceptable risk covers AI uses that are banned outright: social scoring by governments, real-time remote biometric surveillance in public spaces, systems that exploit psychological vulnerabilities to manipulate behaviour. No commercial AI product should sit here. High risk covers AI systems in eight regulated domains including critical infrastructure, education, employment and HR tools, essential private and public services, law enforcement, migration, administration of justice, and democratic processes. If your product automates a credit decision, screens job candidates, allocates NHS resources, or assists in legal judgements, you are in this tier. Limited risk applies to systems with specific transparency obligations only, chiefly chatbots and AI-generated content. Users must be told they are interacting with an AI. Minimal risk covers everything else, including most business productivity tools, recommendation engines for entertainment, and general-purpose AI assistants where no high-risk use case is in scope. Most early-stage AI MVPs fall here or in limited risk.
High-Risk AI: What Compliance Actually Requires
If your system qualifies as high risk, the compliance burden is substantial. You need a risk management system documented and maintained across the product lifecycle. Your training data must be assessed for quality, relevance, and potential bias. Technical documentation must be produced before the system is placed on the market. Automatic logging must capture enough data for post-market monitoring and incident investigation. Human oversight must be built into the system design, not bolted on. For providers established outside the EU, you must appoint an EU-based authorised representative. For UK companies like those working with SpeedMVPs, this means the EU market requires either an in-EU legal entity or a designated representative before a high-risk system can be sold to EU customers. The obligations sound heavy because they are. Most founders discover they are not in this tier once they examine their use case carefully.
How to Determine Your Classification
The first question is whether your AI system is listed in Annex III of the EU AI Act, which defines the high-risk use cases. Read the annex literally. Courts and regulators interpret legal text narrowly, not by analogy. If your HR tool screens CVs before a human reviews them, that is Annex III. If your tool helps HR professionals draft job descriptions, it is not. The second question is whether your product is a general-purpose AI model, which carries its own obligations under the Act regardless of risk tier. The third question is what the actual deployment context is. An AI used by a medical professional to inform a clinical decision is assessed differently from one that makes the decision autonomously. Document your classification decision and the reasoning behind it. If regulators later challenge your categorisation, documented reasoning is your strongest defence.
GDPR Intersection and DPIA Triggers
AI risk classification under the EU AI Act does not replace your GDPR obligations, it adds to them. A system that qualifies as high risk under the EU AI Act will almost certainly also trigger a Data Protection Impact Assessment under GDPR Article 35, particularly if it involves systematic profiling, processing of special category data such as health or biometric data, or automated decision-making with legal or similarly significant effects. The ICO in the UK has published guidance on AI and data protection that maps closely to the EU AI Act framework. If you are building for both UK and EU markets, your DPIA should address both UK GDPR and EU AI Act obligations together rather than treating them as separate documents. SpeedMVPs builds GDPR-aware architecture from sprint one, which gives projects a foundation that simplifies both DPIA completion and EU AI Act technical documentation.
Limited Risk: Chatbot Transparency Requirements
Most consumer-facing AI products land in the limited risk tier, where the primary obligation is transparency. If your product includes a chatbot or AI-generated conversational interface, users must be told they are talking to an AI system. This disclosure must happen at the start of interaction, not buried in terms of service. Similarly, AI-generated text, images, audio, or video that could be mistaken for human-created content must carry a machine-readable label. For deepfake-style content the labelling obligation is stricter. These requirements sound simple, and technically they are. The implementation challenge is doing the disclosure in a way that does not damage user experience or conversion rates. The solution is usually a brief, plain-language notice at conversation start that most users accept naturally because they expect AI interaction in modern products.
Practical Steps for UK AI Product Teams
Start classification during scoping, not after build. The earlier you know which tier applies, the more your architecture can accommodate compliance requirements without expensive rework. Document your classification decision with reference to the specific Annex III use cases you considered and ruled out. Build your transparency disclosures into the product design from the beginning rather than retrofitting them. If you are selling to enterprise customers in the EU, expect them to ask for your EU AI Act documentation as part of procurement due diligence by 2026 and beyond. If your system is high risk, begin your conformity assessment process six to twelve months before market entry, not in the final weeks before launch. The transition periods in the EU AI Act are tightening, with prohibitions already in force and high-risk obligations applying from August 2026.