Call · 15 min
AI ActMattia Esposito9 September 20269 min read

The AI Act risk levels. And the point where an SME ends up inside without noticing.

Almost every explanation starts from a coloured pyramid. The pyramid isn't in the regulation, and the question that really matters isn't what level artificial intelligence sits at, but what level your use of it sits at.

In short

The tiers are counted as four: prohibited practices, high risk, transparency obligations, minimal risk. The regulation doesn't use the word levels and draws no pyramid.

Classification follows the use, not the tool. The same generative model sits in minimal risk if it writes product descriptions, and in high risk if it filters job applications.

Point 4 of Annex III is the one that affects ordinary businesses. Recruitment, selection, CV screening, performance evaluation: all high risk.

Two prohibitions also concern a normal company: inferring emotions in the workplace, and building face databases by collecting images from the web without a target.

This piece sits within the guide to the AI Act obligations for companies and SMEs and isolates its classification. It is written for whoever runs a business, and it ends where a lawyer's work begins.

Four tiers, and the pyramid nobody wrote

Regulation (EU) 2024/1689 builds four different treatments, but doesn't call them levels and doesn't draw them. The pyramid circulating everywhere is a popular representation, handy for explaining and absent from the text. It is worth saying, because whoever looks for the pyramid inside the rule doesn't find it and thinks they have misread.

TierWhat it entailsFrom when
Prohibited practicesArticle 5

Ten practices that can't be placed on the market, put into service or used. No compliance makes them admissible.

2 February 2025 for the original eight, 2 December 2026 for the two added in 2026

High riskArticle 6 and Annex III

The bulk of the regulation: risk management, data quality, documentation, human oversight, specific obligations for the deployer.

2 December 2027 for Annex III systems, 2 August 2028 for Annex I systems, after the 2026 postponement

Transparency obligationsArticle 50

Saying there is an artificial intelligence involved, marking generated or manipulated content, disclosing synthetic voices and faces.

2 August 2026

Minimal riskeverything else

No specific obligation beyond the general ones, including the staff literacy of Article 4. Most ordinary uses sit here.

Article 4 applies from 2 February 2025

The useful thing to take away is that the tiers don't describe technologies, they describe uses. No tool is high-risk in itself, and the same software licence can sit in two different tiers depending on what you do with it.

The prohibited practices, and the two that affect an ordinary company

Article 5 listed eight prohibited practices, in force from 2 February 2025, and the 2026 digital omnibus added two, applicable from 2 December 2026: the non-consensual generation or manipulation of intimate images of identifiable people, and the material covered by Directive 2011/93/EU. Of the original eight, six concern scenarios far from a private business: social scoring, predictive policing based on personality traits, real-time biometric identification for law enforcement, biometric categorisation to infer protected characteristics.

Two, on the other hand, can happen to anyone. The first is inferring emotions in the workplace and in education institutions, prohibited save for exceptions: software that analyses employees' tone of voice in calls or facial expressions on video calls to measure engagement falls within it.

The second is creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage. It concerns whoever thinks of building an archive of faces by collecting photos from the web.

Breach of the prohibition sits in the regulation's highest penalty band, in Article 99: up to €35 million or 7% of total worldwide annual turnover, whichever is higher.

The two doors into high risk

Article 6 provides two distinct entrances, and confusing them is the most common mistake. The first goes through products: the system is a safety component of a product, or is itself a product, covered by the harmonisation legislation listed in Annex I, and that product is subject to third-party conformity assessment.

The second goes through use cases: the system falls within one of the eight areas of Annex III. It is the door that concerns services, retail and light manufacturing businesses, because it doesn't depend on how the tool is made but on what you make it do.

The two doors also have different calendars, and in 2026 both were moved. Regulation (EU) 2026/1744 rewrote Article 113: the obligations of Chapter III, sections 1, 2 and 3, apply from 2 December 2027 for the high-risk systems of Annex III, and from 2 August 2028 for those of Annex I. The original date was 2 August 2026 for both.

The postponement concerns the requirements for high-risk systems, not the whole regulation. The prohibitions of Article 5, the literacy of Article 4 and the transparency obligations of Article 50 stay at their dates, so a business gains no time on the things that really concern it today.

The eight areas of Annex III, and which one concerns you

Annex III lists eight areas. Five concern almost only the public sector or regulated activities, and for an ordinary private business they can be read in thirty seconds. The three really worth looking at are 4, 5 and in part 1.

PointWhat it coversDoes it concern an SME?
1 · Biometrics

Remote biometric identification, biometric categorisation on sensitive attributes, emotion recognition. Simple verification that a person is who they claim to be is left out.

Rarely, and only if you use systems of this kind. Emotion recognition at work is prohibited by Article 5 anyway.

4 · Employment and work

Recruitment and selection, in particular targeted advertisements, analysing and filtering applications, evaluating candidates. And decisions on promotion, termination, task allocation, monitoring and evaluating performance.

Yes, and it is the most frequent case. A tool that screens CVs is enough.

5 · Essential services

Eligibility for public benefits, creditworthiness or credit scoring, pricing and risk in life and health insurance, emergency call handling.

Only if you operate in credit or insurance. Detecting financial fraud is excluded.

2, 3, 6, 7, 8

Critical infrastructure, education and vocational training, law enforcement, migration and borders, justice and democratic processes.

No, unless the business operates in those sectors or on behalf of public authorities.

Point 4 is the one that surprises, because it requires nothing exotic. A company of twenty people that buys a tool to sort incoming CVs is using a system the regulation classifies as high-risk, with the deployer obligations that follow.

The derogation that lightens, and the limit that closes it

Article 6(3) provides a way out. A system listed in Annex III is not considered high-risk if it doesn't pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision-making.

At least one of four conditions is needed: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations without replacing or influencing the previous human assessment without proper review; or it performs a preparatory task for an Annex III assessment.

«Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.»
Regulation (EU) 2024/1689, Article 6(3)

That line closes the door in the most interesting case. A tool that sorts CVs by learning from candidates' profiles performs profiling, and the derogation doesn't save it. Paragraph 4 adds that the provider convinced it falls within the derogation must document the assessment before placing the system on the market.

The tier where almost everything you use sits

An assistant that replies to customers, a model that writes product descriptions, a system that transcribes calls or translates technical sheets aren't high-risk merely by existing. They sit in the band of transparency obligations of Article 50, applicable from 2 August 2026, or directly in minimal risk.

The obligations of that band are information obligations: saying there is an artificial intelligence when a person interacts with it, marking generated or manipulated content in the cases provided, disclosing synthetic voices and faces. The full detail, with the division between provider and deployer, is in the guide to the obligations for SMEs.

In minimal risk there are no specific obligations, but it isn't a void. The literacy obligation of Article 4 still applies, from 2 February 2025, and all the rules on personal data described on the page about AI Act and GDPR apply too.

How to classify your own case in half an hour

Classification is done by use, so the work starts from the list of uses and not from the list of providers. For each system in the company you answer four questions, in order, and stop at the first that answers yes.

One, does it fall within one of the practices of Article 5? If so, switch it off, and no organisational measure makes it admissible. Two, does the use fall within one of the eight areas of Annex III? What counts here is the concrete purpose, not the tool's trade name.

Three, does the system talk to a person or produce published content? Then you need the disclosures of Article 50. Four, none of this? Minimal risk, and the training of the people who use it remains.

The answers should be written down, because classification is an assessment and an undocumented assessment doesn't exist. The sheet that comes out of it is the same one needed for the other obligations, so it is filled in once and used three times.

The human step, which shifts the tier

There is a practical aspect the regulation rewards and almost nobody exploits: where the decision sits. A system that prepares and flags, leaving the choice to a person who really examines it, is in a different position from one that decides on its own, and the derogation of Article 6(3) moves exactly along that line.

In the systems we build the rule is written before the code: every message that commits the company, that is, offers, quotes, prices and confirmations, goes out only after a person has read and approved it. Replies on information already approved by the owner can go out on their own, the owner switches channels on and off one by one, and the reply states that it is a system as Article 50 requires.

The extended scope, with what we never do, is in the AI principles, and the list of systems we actually use is on the AI transparency page.

Questions and answers

How many risk levels does the AI Act have?

In practice four tiers are counted: prohibited practices (Article 5), high risk (Article 6 and Annex III), transparency obligations (Article 50), and minimal risk, that is, everything else.

The regulation never uses the word levels and contains no pyramid: the one seen everywhere is a popular representation, useful for explaining but absent from the text.

Which practices are prohibited?

Article 5 listed eight, in force from 2 February 2025: among others, subliminal or manipulative techniques causing significant harm, exploiting vulnerabilities due to age or disability, social scoring, untargeted scraping of facial images to build face databases, and inferring emotions in the workplace and at school, save for exceptions. The 2026 omnibus added two, applicable from 2 December 2026, on the non-consensual generation of sexually explicit material.

Breach sits in the highest band of Article 99: up to €35 million or 7% of worldwide annual turnover.

When is a system considered high-risk?

There are two doors. First: the system is a safety component of a product, or is itself a product, covered by the legislation in Annex I and subject to third-party conformity assessment. Second: the use falls within one of the eight areas of Annex III.

Paragraph 3 provides a derogation for Annex III systems that perform narrow procedural or preparatory tasks and pose no significant risk. That derogation never applies if the system performs profiling of natural persons.

Can an SME use a high-risk system without knowing it?

Yes, and the frequent case is point 4 of Annex III, on employment and workers management: recruitment and selection, targeted advertisements, analysing and filtering applications, evaluating candidates, decisions on promotion and termination, performance monitoring.

A company of twenty people that buys a tool to screen CVs is using a high-risk system, with the deployer obligations that follow.

Where does a chatbot or a text generator end up?

Outside high risk, in the band of transparency obligations of Article 50, applicable from 2 August 2026. An assistant that talks to customers and a model that writes texts aren't high-risk merely by existing.

The classification changes if that same tool is used for an Annex III purpose, for example to evaluate candidates for a job. What counts is the use, not the product.

Notes on sources

  1. Regulation (EU) 2024/1689 (AI Act), EUR-Lex: Article 5 for the prohibited practices, Article 6 for the classification rules and the derogation in paragraph 3, Annex III for the eight areas, Article 50 for the transparency obligations, Article 99 for the penalty bands, Article 113 for the dates of application.
  2. Regulation (EU) 2026/1744, the digital omnibus on AI, published on 24 July 2026: the two new points in Article 5(1), applicable from 2 December 2026, and the rewriting of Article 113 that moves Chapter III, sections 1, 2 and 3, to 2 December 2027 and 2 August 2028. The high-risk dates still circulate everywhere in the outdated version, and it is the point where it pays to look at the source.
  3. The pyramid representation of the risk levels doesn't appear in the text of the regulation. It is a popular summary widespread in institutional communication and commentary, and this page names it as such instead of attributing it to the rule.
  4. The Annex III items are given in summary form. For a classification that has legal effects, the full text of the relevant point should be read, because each letter contains exclusions this page doesn't report in full.
  5. This page doesn't list the obligations on providers and deployers of high-risk systems, because they are the subject of Chapter III and require a dedicated reading, usually with a professional.

This article is an operational overview, not a legal opinion. On the classification of a specific system, which has concrete consequences, the answer comes from a professional who looks at your company.

·The next step

Classification is done on the use. So it is done by looking at your processes.

Establishing which tier each system you have in-house falls into requires the list of uses, not the list of providers, and you can write it yourselves in a morning. The human step shifts the tier a system falls into, and it only does so if it is in the design: added afterwards, it forces you to redo the classification from scratch. It is fifteen minutes on a call, with the Cruscotto open.