Saltar al contenido

tutoriales · 4 min read

The EU AI Act's 4 Risk Levels: What Each One Requires

The EU AI Act sorts every AI system into one of 4 risk levels, each with very different obligations. A practical guide to finding out where yours lands.

Published on · Evicron

Regulation (EU) 2024/1689, known as the AI Act, doesn’t treat a customer-service chatbot the same as a system that decides who your company hires: it sorts every AI system into one of four risk levels, and each level carries very different obligations — from none at all to an outright ban. At Evicron, an AI and custom software studio based in Barcelona, this is the first question we answer when a company asks for help with compliance: not “am I compliant?”, but “which level does each system I use actually fall into?” Here’s what the four levels mean in practice, and how to classify your own.

Why this matters more than “complying with the law” in the abstract

Most SMEs treat the AI Act as one big block of rules to satisfy all at once. It doesn’t work that way: labeling, user disclosure, conformity assessment, or an outright ban all depend on which category each individual system falls into — not on the company as a whole. An accounting firm might run a chatbot that sits in the limited-risk tier (it just needs to disclose it’s an AI) while, at the same time, evaluating a scoring tool to pre-screen job candidates that lands squarely in high-risk. Getting the classification wrong — or skipping it — is the most common reason AESIA can already fine a company before anyone inside it saw it coming.

Unacceptable risk: what no company is allowed to use

This is the shortest, most clear-cut category: these practices have been banned outright, with no phase-in period, since February 2025. It covers subliminal manipulation that steers people toward harmful decisions, social scoring of individuals by public or private bodies, emotion recognition in the workplace or in schools (barring narrow medical or safety exceptions), and real-time remote biometric identification in public spaces for law-enforcement purposes, outside a short list of legally defined exceptions. If any tool your company uses does something in this list — sometimes dressed up as “team sentiment analysis” or “productivity monitoring” — better documentation won’t fix it. It has to be pulled.

High risk: the tier that comes with the most paperwork

This is where systems that can seriously affect someone’s rights live: hiring and personnel evaluation, credit scoring, admission to education, management of critical infrastructure, or biometric identification systems. These require a conformity assessment, detailed technical documentation, effective human oversight, and traceability of automated decisions. The good news for anyone already running one of these: the Digital Omnibus package pushed the full enforcement of Annex III systems back to December 2, 2027, so there’s real room to get it right instead of scrambling under deadline pressure.

Limited risk: the transparency duty that already applies today

This is the tier affecting the most SMEs right now, since it covers chatbots, voice assistants, image or text generators, and any synthetic content aimed at people. The obligation isn’t technically hard or expensive to meet: disclose that it’s an AI whenever that isn’t already obvious, and label generated content — image, audio, video, or text on matters of public interest — as synthetic. These Article 50 duties, which we covered in detail when they took effect, have applied since August 2, 2026 — and they’re by far the most common gap we find when auditing a client’s systems: a missing disclosure in the chatbot’s first message, or a marketing image generated without the required label.

Minimal risk: most of the AI you already use

Spam filters, grammar checkers, catalog recommendation engines, internal draft generation with no end recipient — the vast majority of AI tools an SME uses day to day fall here, with no specific obligations under the Regulation beyond ones that already existed (GDPR, intellectual property). The real risk at this level isn’t legal, it’s judgment: assuming “it’s just the harmless kind of AI” when the system actually influences a decision about a real person and should sit in a higher tier.

How to classify your own systems, in practice

  1. Build a real inventory, not one from memory: every chatbot, content generator, scoring tool, or screening system that touches a customer, employee, or candidate.
  2. Ask what it decides or influences, not what it technically does: a model that “just suggests” a shortlisted candidate is already influencing a hiring decision — and that alone can be enough to land it in high-risk.
  3. Check the vendor’s documentation: any serious AI tool built for business should state which risk tier it falls under according to the Regulation. If it doesn’t, that’s a warning sign, not a minor detail.
  4. Prioritize by exposure, not by fear: limited-risk systems talking to customers today are the immediate priority; high-risk ones have room until 2027, but it’s worth starting to document them now.

How we handle this at Evicron

We’re not a substitute for a law firm — the fine-grained legal reading is a job for your lawyers — but we’re the ones who audit which AI systems a company actually runs, which tier each one falls into, and what’s technically missing for the disclosure, labeling, or traceability to actually work in production, not just on paper. In our AI consulting service we always start with that inventory, in a free discovery session, before recommending any change.

Not sure which risk tier one of your AI systems falls into? Get in touch: you’ll leave the first session with a concrete classification, not a generic checklist.

Let's talk.

Tell us about your project, challenge or opportunity. We reply within 24 hours with a concrete action plan and indicative budget.