The 4 Risk Levels of AI Act, Explained with Examples

Edited by Solucom · June 1, 2026

The word «risk,» when paired with «artificial intelligence,» can be unsettling. But the AI Act uses that word in a very specific way, and understanding that takes away half your worries. The regulation does not treat all uses of AI the same way: it categorizes them into four levels of risk, like a pyramid. The higher you go, the more rules; but the base of the pyramid—where the vast majority of businesses are—is almost free. Let's look at the four levels with concrete examples, so you understand where you really stand. (As always: this is information, not legal advice for your specific situation.)

1. Unacceptable risk: prohibited uses

At the top of the pyramid are uses considered so dangerous that they forbidden in the European Union (the ban has been in effect since February 2025). This is not about obligations to be met: these things are simply not allowed.

Some examples: the social score of citizens in mass surveillance style, the systems that manipulate people exploiting vulnerabilities (age, disability), emotion recognition in the workplace or school, indiscriminate collection of faces to build facial recognition databases. For a normal SME, this is good news: these are practices far removed from everyday use. They are unlikely to concern you, unless you are evaluating something very extreme.

2. High Risk: delicate uses, serious obligations

The second level is the one that requires the most attention. They are uses Permissible but delicate, as they impact people's rights or safety. This triggers significant obligations: documentation, human oversight, data quality management, and traceability. (Remember: the deadlines for these obligations have been postponed to 2027-2028, as I explain in Dates that count.)

Examples that can also affect an SME: AI used for select personnel (automatic resume screening), for assess creditworthiness from a client, to decide access to essential services, or AI integrated in Regulated products as medical devices. The point to remember: if you use AI to make—or even just automatically influence—important decisions about people, you're probably here.

3. Limited risk: transparency is enough

Going down, we find the uses at limited risk. You don't need complex procedures here: what's needed is to be transparent. The bottom line is that people must know when they are interacting with an AI or viewing AI-generated content.

Concrete examples for a company: a chatbot On the site, you need to make it clear that users are speaking with an AI, not a person. images, texts, or videos generated from AI and published must be indicated as such in the cases provided (the full transparency obligation applies from August 2026). This is the level where a good part of the «visible» uses of AI in SMEs fall: nothing dramatic, just declared honesty.

4. Minimal risk: the vast majority

At the base of the pyramid is everything else: the customs minimum risk, which do not entail any specific obligations under AI Act. This is where most of what companies do with AI on a daily basis falls.

Examples: Use AI to write text drafts, summarize documents, organize notes, translate, conduct internal research, filter spam, suggest products. All activities with low impact on people's rights. Good sense and attention to data are needed, but not a dedicated compliance apparatus.

The point that almost everyone gets wrong: what matters is how you use it, not the tool itself.

Here is the key to not getting confused. The level of risk doesn't depend on the tool, but on how you use it. The same generic AI model can be at minimal or high risk depending on the task.

Clear example: using an AI assistant to write a draft of a commercial offer is a minimal risk. Using the same An assistant for automatically deciding which candidates to reject in a hiring process is high risk. The same tool, two different regulatory worlds. This is why it doesn't make sense to ask «Is ChatGPT high risk?»: the right question is «What am I using it for?». The same applies to a AI agentIt's the use that determines its level.

Supplier or user? The role also matters

There is a second element, besides the risk level, that decides how many obligations you have: the role in terms of how it interacts with the AI system. AI Act primarily distinguishes between two types, and the difference is substantial.

  • The supplier is whoever develops an AI system and brings it to market, or puts it into use under their own name. They bear the heaviest obligations, especially if the system is high-risk.
  • The professional user (The «deployer») is the one who uses an AI system in their business. Here, the obligations are generally lighter: use the system as intended, ensure human supervision where required, and do not alter its purpose.

For almost all SMEs, the position is the second one: USA tools made by others, you don't build them. Great news, because it keeps you away from the most burdensome obligations. But there's an exception to know: if deeply personalize a high-risk system, the remarks with your name or ne change the intended use, in the eyes of the regulation, you yourself can become a «supplier,» with all that entails. It doesn't happen often, but it's worth knowing before you put your logo on a third-party solution and resell it as your own.

Common errors

  • «AI equals high risk. False: most uses are at the bottom of the pyramid, with minimal or limited risk.
  • Not realizing high-risk use. AI for personnel selection or credit assessment is easy to implement «without thinking,» but it changes everything. This is the case to watch.
  • Ignore transparency. The limited risk seems like «nothing,» but disclosing a chatbot or generated content is a concrete obligation, as well as a matter of trust.
  • Look at the tool instead of its use. It's the fundamental error from which all others arise.

The first, concrete step

Resume the list of AI uses in your company (if you don't have one, it only takes ten minutes to write it). Next to each, try to assign a level: forbidden, high, limited, or minimum. For the most part, you'll end up with «minimal» or «limited,» and that's perfectly fine. What you're really looking for is the single use that, perhaps secretly, falls into «high risk»: that's where it's worth pausing and getting follow-up. In a spreadsheet, you have your risk map, and it's the quickest way to sleep soundly.

The rule to keep in mind

The four levels of the AI Act form a pyramid: a few prohibited uses at the top, some sensitive, high-risk uses, a ’transparency” zone for visible uses, and a very broad base with minimal risk where almost everything falls. There is only one golden rule: The risk lies in its use, not in the tool itself.. Keep that in mind, and AI Act will no longer be a mystery.

Frequently Asked Questions

Does using ChatGPT put my company at high risk?

Rarely. Using an AI assistant for drafts, summaries, or research carries minimal risk. The same tool only becomes high risk if you use it for delicate decisions about people, such as personnel selection or credit evaluation. It's the use that matters, not the tool.

Does the risk depend on the instrument or the usage?

From use. The same AI model can fall into the low-risk or high-risk category depending on the task you assign it to. This is why classification must be done on the concrete activity, not on the software itself.

What should I do if my use is at limited risk?

Be transparent. In practice: make it clear to people when they are interacting with an AI (for example, a chatbot) and label AI-generated content where required. Full transparency obligations will apply from August 2026.

Is there an AI use case in your company that you don't know where to place? Send me your main uses and I'll help you put them at the right level, pointing out the ones that are really worth exploring further. Find out how we handle AI Act o Write us your uses.