{"id":176,"date":"2026-06-01T12:39:58","date_gmt":"2026-06-01T12:39:58","guid":{"rendered":"https:\/\/solucom.si\/?p=176"},"modified":"2026-06-05T00:33:28","modified_gmt":"2026-06-04T22:33:28","slug":"ais-four-levels-of-risk","status":"publish","type":"post","link":"https:\/\/solucom.si\/en\/ai-act-quattro-livelli-di-rischio\/","title":{"rendered":"The 4 Risk Levels of AI Act, Explained with Examples"},"content":{"rendered":"<p>The word \u00abrisk,\u00bb when paired with \u00abartificial intelligence,\u00bb can be unsettling. But the AI Act uses that word in a very specific way, and understanding that takes away half your worries. The regulation does not treat all uses of AI the same way: it categorizes them into <strong>four levels of risk<\/strong>, like a pyramid. The higher you go, the more rules; but the base of the pyramid\u2014where the vast majority of businesses are\u2014is almost free. Let's look at the four levels with concrete examples, so you understand where you really stand. (As always: this is information, not legal advice for your specific situation.)<\/p>\n\n<h2>1. Unacceptable risk: prohibited uses<\/h2>\n<p>At the top of the pyramid are uses considered so dangerous that they <strong>forbidden<\/strong> in the European Union (the ban has been in effect since February 2025). This is not about obligations to be met: these things are simply not allowed.<\/p>\n<p>Some examples: the <em>social score<\/em> of citizens in mass surveillance style, the systems that <em>manipulate<\/em> people exploiting vulnerabilities (age, disability), emotion recognition in the workplace or school, indiscriminate collection of faces to build facial recognition databases. For a normal SME, this is good news: these are practices far removed from everyday use. They are unlikely to concern you, unless you are evaluating something very extreme.<\/p>\n\n<h2>2. High Risk: delicate uses, serious obligations<\/h2>\n<p>The second level is the one that requires the most attention. They are uses <strong>Permissible but delicate<\/strong>, as they impact people's rights or safety. This triggers significant obligations: documentation, human oversight, data quality management, and traceability. (Remember: the deadlines for these obligations have been postponed to 2027-2028, as I explain in <a href=\"\/en\/ai-acts-that-matter\/\">Dates that count<\/a>.)<\/p>\n<p>Examples that can also affect an SME: AI used for <strong>select personnel<\/strong> (automatic resume screening), for <strong>assess creditworthiness<\/strong> from a client, to decide access to essential services, or AI integrated in <strong>Regulated products<\/strong> as medical devices. The point to remember: if you use AI to make\u2014or even just automatically influence\u2014important decisions about people, you're probably here.<\/p>\n\n<h2>3. Limited risk: transparency is enough<\/h2>\n<p>Going down, we find the uses at <strong>limited risk<\/strong>. You don't need complex procedures here: what's needed is <strong>to be transparent<\/strong>. The bottom line is that people must know when they are interacting with an AI or viewing AI-generated content.<\/p>\n<p>Concrete examples for a company: a <strong>chatbot<\/strong> On the site, you need to make it clear that users are speaking with an AI, not a person. <strong>images, texts, or videos generated<\/strong> from AI and published must be indicated as such in the cases provided (the full transparency obligation applies from August 2026). This is the level where a good part of the \u00abvisible\u00bb uses of AI in SMEs fall: nothing dramatic, just declared honesty.<\/p>\n\n<h2>4. Minimal risk: the vast majority<\/h2>\n<p>At the base of the pyramid is everything else: the customs <strong>minimum risk<\/strong>, which do not entail any specific obligations under AI Act. This is where most of what companies do with AI on a daily basis falls.<\/p>\n<p>Examples: Use AI to write text drafts, summarize documents, organize notes, translate, conduct internal research, filter spam, suggest products. All activities with low impact on people's rights. Good sense and attention to data are needed, but not a dedicated compliance apparatus.<\/p>\n\n<h2>The point that almost everyone gets wrong: what matters is how you use it, not the tool itself.<\/h2>\n<p>Here is the key to not getting confused. <strong>The level of risk doesn't depend on the tool, but on how you use it.<\/strong> The same generic AI model can be at minimal or high risk depending on the task.<\/p>\n<p>Clear example: using an AI assistant to write a draft of a commercial offer is a minimal risk. Using the <em>same<\/em> An assistant for automatically deciding which candidates to reject in a hiring process is high risk. The same tool, two different regulatory worlds. This is why it doesn't make sense to ask \u00abIs ChatGPT high risk?\u00bb: the right question is \u00abWhat am I using it for?\u00bb. The same applies to a <a href=\"\/en\/what-is-an-ai-agent\/\">AI agent<\/a>It's the use that determines its level.<\/p>\n\n<h2>Supplier or user? The role also matters<\/h2>\n<p>There is a second element, besides the risk level, that decides how many obligations you have: the <strong>role<\/strong> in terms of how it interacts with the AI system. AI Act primarily distinguishes between two types, and the difference is substantial.<\/p>\n<ul>\n<li><strong>The supplier<\/strong> is whoever develops an AI system and brings it to market, or puts it into use under their own name. They bear the heaviest obligations, especially if the system is high-risk.<\/li>\n<li><strong>The professional user<\/strong> (The \u00abdeployer\u00bb) is the one who uses an AI system in their business. Here, the obligations are generally lighter: use the system as intended, ensure human supervision where required, and do not alter its purpose.<\/li>\n<\/ul>\n<p>For almost all SMEs, the position is the second one: <strong>USA<\/strong> tools made by others, you don't build them. Great news, because it keeps you away from the most burdensome obligations. But there's an exception to know: if <em>deeply personalize<\/em> a high-risk system, the <em>remarks<\/em> with your name or ne <em>change the intended use<\/em>, in the eyes of the regulation, you yourself can become a \u00absupplier,\u00bb with all that entails. It doesn't happen often, but it's worth knowing before you put your logo on a third-party solution and resell it as your own.<\/p>\n<h2>Common errors<\/h2>\n<ul>\n<li><strong>\u00abAI equals high risk.<\/strong> False: most uses are at the bottom of the pyramid, with minimal or limited risk.<\/li>\n<li><strong>Not realizing high-risk use.<\/strong> AI for personnel selection or credit assessment is easy to implement \u00abwithout thinking,\u00bb but it changes everything. This is the case to watch.<\/li>\n<li><strong>Ignore transparency.<\/strong> The limited risk seems like \u00abnothing,\u00bb but disclosing a chatbot or generated content is a concrete obligation, as well as a matter of trust.<\/li>\n<li><strong>Look at the tool instead of its use.<\/strong> It's the fundamental error from which all others arise.<\/li>\n<\/ul>\n\n<h2>The first, concrete step<\/h2>\n<p>Resume the list of AI uses in your company (if you don't have one, it only takes ten minutes to write it). Next to each, try to assign a level: <strong>forbidden, high, limited, or minimum<\/strong>. For the most part, you'll end up with \u00abminimal\u00bb or \u00ablimited,\u00bb and that's perfectly fine. What you're really looking for is the single use that, perhaps secretly, falls into \u00abhigh risk\u00bb: that's where it's worth pausing and getting follow-up. In a spreadsheet, you have your risk map, and it's the quickest way to sleep soundly.<\/p>\n\n<h2>The rule to keep in mind<\/h2>\n<p>The four levels of the AI Act form a pyramid: a few prohibited uses at the top, some sensitive, high-risk uses, a \u2019transparency\u201d zone for visible uses, and a very broad base with minimal risk where almost everything falls. There is only one golden rule: <strong>The risk lies in its use, not in the tool itself.<\/strong>. Keep that in mind, and AI Act will no longer be a mystery.<\/p>\n\n\n<h2>Frequently Asked Questions<\/h2>\n\n\n<p><strong>Is there an AI use case in your company that you don't know where to place?<\/strong> Send me your main uses and I'll help you put them at the right level, pointing out the ones that are really worth exploring further. <a href=\"\/en\/ai-act\/\">Find out how we handle AI Act<\/a> o <a href=\"\/en\/#contatti\">Write us your uses<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>The AI Act Risk Pyramid Explained with Examples: Prohibited Uses, High Risk, Limited Risk, and Minimal Risk. And the rule that almost everyone gets wrong: it\u2019s the use that matters, not the tool.<\/p>","protected":false},"author":1,"featured_media":209,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"I 4 livelli di rischio dell'AI Act con esempi | Solucom","_seopress_titles_desc":"L'AI Act classifica l'AI in quattro livelli di rischio. Ti spiego ognuno con esempi concreti, per capire in quale fascia ricade cio che usi.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"livelli di rischio AI Act","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"footnotes":""},"categories":[15],"tags":[],"class_list":["post-176","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contenuti-ai-act-compliance"],"_links":{"self":[{"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/posts\/176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/comments?post=176"}],"version-history":[{"count":5,"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/posts\/176\/revisions"}],"predecessor-version":[{"id":271,"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/posts\/176\/revisions\/271"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/media\/209"}],"wp:attachment":[{"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/media?parent=176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/categories?post=176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solucom.si\/en\/wp-json\/wp\/v2\/tags?post=176"}],"curies":[{"name":"WP","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}