Phase 5: AI Impact Assessment & Governance · 40 min · Python
EU AI Act Risk Classification — Unacceptable, High, Limited, Minimal
The EU AI Act doesn't ban AI. It classifies it. Your job is to know which tier you're in.
Hiring signal: Every RAI role in or serving the EU market requires understanding the AI Act's risk tiers. Being able to classify a system into the correct tier and identify the resulting obligations is a fundamental compliance skill.
What you will learn
- Describe the 4 EU AI Act risk tiers and their obligations
- Classify an AI system into the correct risk tier based on its use case
- Identify the specific compliance obligations for each tier
- Build a risk classification tool that maps use cases to obligations
The Problem
In Lesson 1, you conducted an algorithmic impact assessment and produced an internal score — High, Moderate, Low. That score tells your organization how much internal governance to apply. It does not tell you what the law requires. The EU AI Act has its own classification system, with its own four tiers and its own legally binding obligations attached to each one, and getting the tier wrong is not a paperwork error — it's the difference between "voluntary code of conduct" and "up to €15M or 3% of global revenue in fines."
The challenge engineers run into is that the Act's tiers are not intuitive from a technical description alone. A resume-screening tool sounds like a recommendation engine; legally, it's explicitly listed as high-risk in Annex III because it affects access to employment. A chatbot sounds high-stakes because it talks to customers directly; legally, it's limited-risk, with a single transparency obligation (tell the user they're talking to AI). You cannot guess your way through this — you need a repeatable classification process that maps a system's actual use case to the Act's actual categories.
The 4 Risk Tiers
| Tier | Examples | Obligations | Penalty for Non-Compliance |
|---|
| Unacceptable (banned) | Social scoring, manipulative AI, real-time biometric ID in public spaces | System is prohibited | Up to €35M or 7% of global revenue |
| High-risk (Annex III) | Employment screening, credit scoring, medical diagnosis, education, law enforcement, critical infrastructure | Risk assessment, data governance, transparency, human oversight, logging, conformity assessment | Up to €15M or 3% of global revenue |
| Limited-risk | Chatbots, emotion recognition, deepfakes, biometric categorization | Transparency obligations (users must know they're interacting with AI) | Up to €7.5M or 1.5% of global revenue |
| Minimal-risk | Spam filters, recommendation engines, inventory optimization | No specific obligations (voluntary codes of conduct) | N/A |
Unlock the full lesson
You've read the first 2 sections. The rest of this lesson covers Annex III High-Risk Categories, Building the Risk Classifier, What's Next — plus a hands-on lab, quiz, and project artifact.
Create a free account to unlock Phase 0 and Phase 1 of every course — no credit card.
Browse all courses · View pricing · DeVenture Academy