Key takeaways:
- The AI Act classifies AI systems into 4 risk levels according to their purpose and impact on people, not according to the technology used.
- Unacceptable risk (prohibited practices): deceptive manipulation, social scoring, certain uses of biometrics: penalties of up to €35 million or 7% of global turnover.
- High risk: systems used in employment, education, justice, critical infrastructure, etc. Strict requirements for documentation, risk management and conformity assessment.
- Limited risk: transparency requirements (chatbots, deepfakes) to inform users that they are interacting with AI or AI-generated content.
- Minimal risk: the majority of common uses (spam filters, recommendations), subject to limited regulation but still covered by the GDPR and other existing rights.
- Starting point for a company: inventory its AI uses, classify them, document them and adapt governance to the identified level of risk.
With the AI Act, not all uses of artificial intelligence are treated in the same way. A system used to write marketing copy does not require the same precautions as a tool used to pre-screen candidates. The entire logic of the regulation is based on this distinction.
For a company, the first step is therefore to identify its uses of AI, measure their effects and determine their level of risk.
What is the European AI Act risk pyramid?
The AI Act, a pioneering European regulation on artificial intelligence
The AI Act, or European Regulation 2024/1689, establishes a legal framework dedicated to artificial intelligence in the European Union. Its distinctive feature is its risk-based approach. The obligations vary depending on the system’s use and the consequences it may have on people. For an overview of the regulation, Eterra provides a presentation of the European Artificial Intelligence Act.
The logic of risk-level classification
The technology used alone is not enough to determine the level of risk. What matters most is the purpose of the system, its context of use and its impact on people’s rights . For example, a conversational assistant designed to answer customer questions is not assessed in the same way as a system that plays a role in a recruitment decision.
The four categories of the risk pyramid
The AI Act distinguishes four main levels.
- At the top are unacceptable risk practices, which are prohibited.
- Next come high-risk systems, subject to the strictest rules.
- Limited-risk systems must primarily comply with transparency requirements.
- Minimal-risk uses, on the other hand, are much less regulated by the regulation.
Once this logic is understood, it becomes easier to examine what each level of the pyramid encompasses.
Unacceptable risk: AI practices prohibited by the AI Act
Definition and scope of unacceptable risk
This category covers practices deemed incompatible with safety, dignity or fundamental rights. Eight prohibitions are already applicable. A ninth, concerning certain sexually explicit content and child sexual abuse material, is due to enter into force in December 2026.
Does your company use an AI system involving unacceptable risk without knowing it?
Examples of unacceptable-risk AI systems
Among the prohibited practices are subliminal or deceptive manipulation likely to cause harm, exploitation of vulnerabilities related to age, disability or social situation, as well as social scoring based on behaviour or certain personal characteristics.
The AI Act also prohibits certain uses of biometrics and emotion recognition, particularly in professional or educational settings.
Penalties for non-compliance with the prohibition
Prohibited practices are subject to the heaviest penalties provided for by the regulation. They can reach €35 million or 7% of annual worldwide turnover, depending on the applicable ceiling. An AI Act expert consultancy can help assess these practices in advance and secure uses before any risk of sanctions.
Just below prohibited practices is the category of high-risk systems.
High risk: AI systems subject to the strictest requirements
What is a high-risk AI system?
A system may be classified as high risk when it is integrated into a product already subject to sector-specific regulation or when it falls within one of the uses listed in Annex III of the AI Act.
List of high-risk application areas
Annex III covers several sensitive sectors, including:
- biometrics
- critical infrastructure
- education
- employment
- essential services
- law enforcement
- migration
- justice
- certain democratic processes
Compliance obligations for providers and deployers
The provider must organise risk management throughout the system’s entire lifecycle. In particular, it documents the training, validation and testing data, their representativeness, identified biases, model accuracy, robustness and cybersecurity.
The deployer also has responsibilities. They follow the instructions provided, organise human oversight, retain the necessary logs and report incidents.
Conformity assessment and certification
Before placing the system on the market or putting it into service, the provider carries out the conformity assessment required for the system concerned.
When a use mentioned in Annex III is ultimately considered not to qualify as high risk, this decision must be justified and documented.
Other systems require lighter monitoring. This is particularly the case for those classified as limited risk.
Does your AI system fall within the scope of high-risk obligations?
Limited risk: transparency obligations for AI
Characteristics of limited-risk systems
Limited risk concerns, in particular, systems capable of creating confusion about the nature of the interaction or content provided without falling into the high-risk category.
Transparency and user information requirements
When a person interacts with an AI system, they must be informed of this situation when it is not already obvious from the context.
The regulation also provides information requirements for certain artificially generated or manipulated content.
Practical cases: chatbots, deepfakes and AI-generated content
A support chatbot must therefore indicate its automated nature. Deepfakes, whether images, videos or audio content created or modified by AI, must also be identified in the situations provided for by the regulation.
A large proportion of common uses of artificial intelligence nevertheless remain classified at the lower level of the pyramid.
Minimal risk: the least restrictive category of the AI Act
AI literacy requires organisations to train employees and service providers to understand the limitations of AI, verify its results, protect data and raise concerns. The AI Act requires measures proportionate to the uses and risks. Strong governance relies on mapping tools, internal rules, responsibilities, documented training and regular reviews.
Definition and examples of minimal-risk systems
A spam filter, a product recommendation engine, certain video games or a proofreader used internally generally fall under minimal risk.
Code of practice and voluntary compliance
Even when obligations are limited, keeping some basic information remains useful. The purpose of the system, its provider, the data used and the internal person responsible can be recorded in a simple register.
This record makes it easier to conduct reviews when a system evolves or begins to be used for a new function.
Why adopt a proactive approach even for minimal risks
Minimal risk does not mean the absence of applicable law. The GDPR, consumer law, copyright law, product safety requirements and contractual commitments may also continue to govern the use in question.
The next step is therefore to translate this pyramid into a working method for classifying the systems actually used within the company.
How do you classify your AI system in the risk pyramid?
Risk level assessment methodology
The starting point is a complete inventoryincluding SaaS solutions and external models already adopted by teams. To frame this step, Eterra’s guide to achieving compliance with the AI Act Act details the process to follow.
For each use case, it is necessary to describe the purpose of the system, the people who use it or are affected by it, the data processed, the sector concerned and the possible presence of a prohibited case or one mentioned in Annex III.
Classification criteria: use, sector and impact on fundamental rights
The analysis must cover the degree of autonomy given to the system, its role in human decision-making and the possible consequences for individuals, particularly in employment, healthcare, justice or access to essential services.
A change in the purpose, data, model or deployment context may be enough to change the classification.
Tools and resources for self-assessment
An AI systems register, a classification sheet and a risk matrix already provide a solid working basis.
General-purpose AI models, or GPAI, are also subject to a specific regime. Since July 2025, guidelines, a GPAI code of practice and a public template for summarising training data have complemented this framework. Eterra’s analysis of the Digital Omnibus examines these recent developments in detail.
Once the systems have been classified, the challenge is to turn this analysis into governance rules that are actually implemented.
Compliance with the AI Act: governance and risk management
Structuring AI governance proportionate to the level of risk
Governance begins with a clear allocation of responsibilities between business teams, IT, legal and management.. An AI officer can coordinate this work and monitor changes in usage.
Corporate governance experts can support this allocation of roles and the formalisation of procedures.
Documentation and traceability: requirements by risk category
The systems register, classification analysis, notices, logs, supplier contracts and incident management procedures form the documentary foundation.
For high-risk systems, this documentation covers the entire lifecycle. It must remain sufficiently precise to demonstrate the choices made without unnecessarily exposing information covered by trade secrets.
Team training and awareness of regulatory obligations
Employees who configure, use or validate the results of a system must understand its limitations, the rules relating to data and the situations requiring human intervention.
A written procedure does not protect the company if no one knows how to apply it. Training must therefore remain linked to the practical uses encountered by each team.
The role of compliance experts in securing your AI roadmap
Working with an AI Act expert consultancy helps qualify systems, review supplier contracts and prepare the evidence expected in the event of an inspection.
Eterra’s expertise combines governance, regulatory compliance and support for European projects. The objective is to build a framework proportionate to the uses actually present within the organisation, without unnecessarily adding to processes.
Pour approfondir le sujet, Eterra propose également un guide pour être en conformité avec l’IA Act, une présentation de la loi européenne sur l’intelligence artificielle ainsi qu’un décryptage du digital omnibus.
The key points to remember about AI-related risks
L’AI Act classe les usages d’intelligence artificielle selon leur finalité, leur contexte et leurs effets sur les droits. Il interdit huit pratiques, impose une conformité stricte aux systèmes à haut risque, puis des règles de transparence aux chatbots et deepfakes. Les entreprises doivent inventorier chaque outil, justifier son classement, former leurs équipes et actualiser l’analyse après toute évolution d’usage.
YOUR QUESTIONS
FAQ - Questions fréquentes sur la pyramide des risques de l’AI Act
Before contacting us, you may have these questions. Here are direct answers from our senior consultants.
—
When does the AI Act come into force in Europe?
The first prohibitions have been in force since February 2025, while the obligations concerning GPAI have applied since August 2025. The transparency rules are scheduled for August 2026, and the main obligations relating to high-risk systems are announced for 2 December 2027.
Can an AI system change risk category?
Yes. A change in its use, data, users or role in a decision may alter its classification. For example, an assistant initially used to draft internal documents may change status if it subsequently becomes involved in screening job applications.
What are the penalties for non-compliance with the AI Act?
Penalties vary depending on the nature of the breach and the role of the organisation concerned. Prohibited practices are associated with the highest ceiling, namely €35 million or 7% of annual worldwide turnover. Other infringements are subject to different thresholds.
Are SMEs concerned by the AI Act risk pyramid?
Yes. An SME that develops, purchases or uses an AI system in the European Union may be covered by the regulation. When it uses a solution developed by an external provider, it retains obligations linked to its own role as a deployer.
The risk pyramid is primarily used to put priorities in the right order. Companies should start by taking an inventory of their systems, assessing each use case and retaining the elements that justify their analysis. Prohibited practices and high-risk systems should naturally receive the greatest attention.
To organise this mapping and build appropriate governance, the Eterra team supports organisations from identifying use cases through to operational monitoring.


