The EU AI Act, Regulation (EU) 2024/1689, sorts AI systems into four tiers by the risk of their use rather than the sophistication of the model: prohibited (Article 5), high-risk (Annex III areas and safety components of regulated products, with narrow Article 6 derogations), limited-risk (transparency duties, such as disclosing that content is AI-generated), and minimal-risk (no specific obligations). What the system does and where it is used decides the tier — so classification follows from declared facts about purpose and deployment context, and can be computed rather than debated.
A regulation organised by risk
The EU AI Act — Regulation (EU) 2024/1689 — is the first comprehensive horizontal law for artificial intelligence. Its central idea is a risk-based pyramid: an AI system's obligations depend on the risk its use poses, sorted into four tiers. What the system does and where it's used determines the tier — not how advanced the underlying model is.
| Tier | What it means |
|---|---|
| Prohibited | Uses banned outright — for example social scoring or certain manipulative or exploitative systems (Article 5). |
| High-risk | Permitted but heavily regulated — the systems in the Annex III areas (and safety components), carrying the bulk of the Act's obligations. |
| Limited-risk | Permitted with transparency duties — for example telling people they're interacting with an AI or that content is AI-generated. |
| Minimal-risk | Everything else — the majority of AI uses, with no specific obligations under the Act. |
What makes a system "high-risk"
High-risk is the tier that matters most, because it's where the obligations concentrate. A system is high-risk broadly if it's used in one of the areas listed in Annex III — think biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and the administration of justice — or if it's a safety component of a regulated product.
Article 6 provides a narrow set of derogations: a system in an Annex III area may not be high-risk if it performs a narrow procedural task, doesn't materially influence a decision, and so on. But those derogations fall away if the system does profiling of individuals — profiling keeps a system high-risk regardless. Classification is therefore a chain of declared facts.
The risk category should follow from facts about the system — its use area, whether it profiles, whether a derogation genuinely applies — not from a box someone ticked. A hand-set category that disagrees with those facts is exactly the kind of thing that unravels under scrutiny.
What a high-risk system owes
For a high-risk system, a provider must maintain technical documentation (the Annex IV set — intended purpose, design, data governance, risk management, human oversight, accuracy and robustness), register the system in the EU database (the Annex VIII information), and operate a quality and risk-management system around it. There are also serious-incident obligations: reporting to the authorities on a clock measured from the moment you become aware — a discipline of days.
Building the register with Qgentic
Qgentic AI Act keeps your AI estate on the record: it takes the declared facts about each system, computes the risk category from the Article 5 / Article 6 / Annex III logic, and refuses a hand-set category that disagrees. It runs the Annex IV documentation completeness gates for high-risk systems, shapes the Annex VIII registration record, and tracks the incident clocks. It also computes the general-purpose AI model duties (Articles 51, 53 and 55) and whether an Article 27 fundamental-rights impact assessment is required. It is prepare-only, on the same approval gate and audit trail as every Qgentic platform. For UK organisations there's a separate rulebook — see UK AI governance.
This is engineering-and-compliance orientation, not legal advice, and the AI Act's obligations phase in over time. Article references are for orientation; confirm classification and duties for your specific systems with counsel.
Qgentic AI Act computes each system's risk category from declared facts, and refuses a hand-set category that disagrees.
See the AI Act platform Book a consultation