The EU AI Act (Regulation (EU) 2024/1689) sorts AI systems into a four-tier risk pyramid instead of regulating all AI the same way. Where a system lands depends on how autonomously it decides, how severely a wrong decision could affect people's rights, safety or livelihood, and whether it operates in a sensitive sector listed in Annex III (biometric ID, critical infrastructure, education, employment, essential services, law enforcement, migration, justice).
RiskScore = 0.5Β·Autonomy + 0.4Β·Impact + SectorBonus(sector)
Tiers (illustrative thresholds):
score < 25 β Minimal risk β voluntary codes of conduct only
25 β 54 β Limited risk β transparency duties (e.g. disclose it's AI)
55 β 84 β High-risk β Title III: risk mgmt, data governance,
logging, human oversight, CE marking
score β₯ 85 β Unacceptable β banned under Article 5 (e.g. social
scoring, manipulative/subliminal systems)
- Autonomy β how much a human reviews or can override each decision; fully autonomous, unreviewed decisions push the score up.
- Potential impact β the severity of harm a wrong or biased decision could cause to health, safety or fundamental rights.
- Sector β Annex III use-cases (healthcare, law enforcement, employment, β¦) each carry a fixed risk bonus on top of Autonomy/Impact.
- Sandbox β Articles 57β58 let providers trial a high-risk system under a supervised regulatory sandbox before full Title III conformity is required; it never lifts an Article 5 ban.
The small cubes floating around the tower are a fixed sample of other hypothetical AI systems, coloured by their own tier, so the pyramid never looks empty at any setting.