The four risk tiers, explained with everyday tools
18 June 2026 · 6 min read

The EU AI Act sorts every AI system into one of four risk tiers, and the tier decides what you have to do. That sounds abstract until you realise the tools in question are the ones already open in your browser tabs. A chatbot on your website, a CV screener your recruiter tried last month, the image generator your designer uses, the ChatGPT window drafting your emails. Each one sits in a tier, and each tier carries a different set of duties, from none at all to a full compliance programme.
This guide walks through the four tiers using tools a small team actually recognises. For each one you get the plain meaning, a concrete everyday example, and what the Act asks of you. By the end you should be able to look at your own stack and place each tool with reasonable confidence.
At the top sits the banned list. Article 5 of the Act names practices that are considered an unacceptable risk to people's rights, so they are not allowed on the EU market at all. There is no paperwork that makes them fine. You either avoid them or you break the law.
For a small team the relevant bans are narrower than the headlines suggest, but two are worth knowing well:
The prohibited practices have applied since 2 February 2025, earlier than most of the Act. They also carry the heaviest penalty: up to 35 million euro or 7% of worldwide annual turnover, whichever is lower for a smaller company. What you must do here is simple to state and important to follow. Do not buy, build or switch on anything on this list, and if a supplier's demo edges into it, walk away.
The second tier is where a small business is most likely to trip without noticing. High-risk systems are listed in Annex III of the Act. They are allowed, but only if a serious set of obligations is met, because they make or shape decisions that affect people's lives.
The category most relevant to small teams is employment and worker management. That covers AI used for recruitment, for filtering or ranking job applicants, for allocating tasks, and for evaluating performance or deciding who to promote or let go.
The everyday example is a CV screener or automated hiring tool. Say your recruiter starts using a system that ranks applicants and surfaces the top ten. The moment that tool influences who gets an interview, you are using a high-risk system, and as the deployer you inherit real duties:
Other Annex III areas include education, access to essential private and public services such as credit or insurance decisions, certain uses of biometrics, and critical infrastructure. Most small studios and agencies will only meet this tier through hiring or evaluation software. The heavier high-risk obligations for Annex III systems, for both deployers and providers, were moved by the 2026 Digital Omnibus from 2 August 2026 to 2 December 2027, so that is now the date to plan around. Note that 2 August 2026 is when the transparency duties apply, not the high-risk duties. Getting the wrong answer here is still expensive, with penalties of up to 15 million euro or 3% of worldwide annual turnover.
The trap with high-risk tools. You do not have to build a hiring algorithm to be on the hook. Simply using one, under your own authority, makes you the deployer with oversight, record-keeping and transparency duties. If your team is testing anything that screens, ranks or evaluates people, treat it as high-risk until you have confirmed otherwise.
The third tier is lighter. These systems are not dangerous, but they can mislead people about what they are dealing with, so Article 50 asks for one thing: transparency. Tell people when they are interacting with AI or looking at AI-generated content. That is essentially the whole duty.
Two everyday examples cover most small teams:
None of this stops you using these tools. It just asks you to be upfront. The cost of compliance is a sentence, a label or a small notice. The transparency obligations become fully relevant from 2 August 2026, and they sit under the same penalty ceiling as other obligations, up to 15 million euro or 3% of turnover, though in practice a missing disclosure is far easier to fix than a banned practice.
The last tier is where most of your stack actually lives. Minimal risk covers everyday tools that do not make consequential decisions about people. The Act sets no specific legal obligations for these systems.
The everyday examples are the ones you use constantly:
There is no register to file, no oversight process to document, no disclosure required for the tool itself. That said, minimal risk is not the same as no responsibility. Two things still apply. First, if you use one of these tools to produce synthetic media, the transparency duty from tier three still bites on that output. Second, and this catches everyone, the AI literacy duty applies here too.
Article 4 of the Act, the AI literacy duty, does not care which tier your tools sit in or how small your company is. It has applied since 2 February 2025, and it asks providers and deployers to ensure a sufficient level of AI literacy among the staff and others who use AI on their behalf.
It is deliberately proportionate. It does not prescribe a particular course or certificate. It takes into account your people's technical knowledge, their experience, the context they use AI in, and who the AI is used on. The core idea is plain: the people using these tools should understand enough to use them responsibly and to spot the risks, and you should be able to show you made a reasonable, role-appropriate effort. So even a team whose entire stack is minimal risk still owes its people basic AI literacy.
You do not need a lawyer to make a first pass. Work through your tools one at a time and ask a short chain of questions:
How to classify yours, quickly. Open a simple list of every AI tool your team touches. Beside each one, write the tier and a one-line reason. Most rows will read "minimal, drafting only." The point is to surface the one or two that are not, usually a chatbot that needs a disclosure or a hiring tool that needs oversight, before anyone else does. That single sheet is the start of a risk-classified tool inventory, the first of the four artefacts that turn "we tried to comply" into "we can show it."
Classification is not a one-off. Tools change, features get added, and a minimal-risk app can grow an AI hiring feature overnight. Klaar keeps this inventory current for small teams and pairs it with the training, policy and dated compliance record that back it up, so when a client, insurer or regulator asks, the answer is a folder rather than a shrug. Start with the four questions above, and you will already know where you stand well before the transparency duties apply on 2 August 2026 and the heavier high-risk obligations follow on 2 December 2027.
Klaar walks you through inventory, training, policy and the dated evidence.