Back to glossaryLaw & regulation

AI Act risk tiers

Four-tier classification that drives every obligation in the European AI regulation, from outright prohibition to no obligation at all, with a separate regime for general-purpose models.

Definition

The European AI regulation does not regulate the technology, it regulates the use, and the classification of the use drives everything else. Four tiers follow one another. Unacceptable risk is prohibited, with no commercial derogation available. High risk is permitted under heavy conditions: risk management system, data governance, technical documentation, logging, transparency toward the deployer, human oversight, robustness, conformity assessment and registration in a European database. Limited risk calls only for transparency obligations: disclose that you are talking to a machine, label generated content. Minimal risk calls for nothing. A fifth, cross-cutting regime targets general-purpose models, with reinforced obligations above a compute threshold. For insurance the decisive point fits in one line: AI systems intended for risk assessment and pricing in life and health insurance are classified as high risk, which drops a pricing engine into the most demanding regime.

Example

Regulation (EU) 2024/1689, in force since August 1, 2024. Prohibitions and the AI literacy obligation have applied since February 2, 2025, general-purpose model obligations since August 2, 2025, and those on Annex III high-risk systems from August 2, 2026. A European health insurer running a pricing engine built on a learning model therefore enters the high-risk regime at that last date, and the compliance runway is measured in quarters, not weeks.

Related terms
Also known as

approche par les risques, risk-based approach, pyramide des risques IA, classification des systèmes d'IA