The EU AI Act: risk classification framework, all four tiers
The EU AI Act sorts AI use cases into four risk tiers, and everything else in the Act follows from that classification. It is the most heavily tested law on the AIGP exam.
Why this matters for the AIGP exam
Classification questions appear in many forms: a described use case, four candidate tiers, one right answer. The tier decides which obligations apply, so misclassifying at the top means every downstream answer is wrong too.
The essentials
- Prohibited practices. Uses judged incompatible with fundamental rights: social scoring by or for public authorities, manipulation that exploits vulnerability, untargeted scraping of facial images, emotion recognition in workplaces and schools, and real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions).
- High-risk systems. Two routes in: safety components of products already covered by EU product legislation, or use cases listed in Annex III — biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and justice. High-risk is where the Act's detailed obligations live.
- Limited risk. Transparency duties: people must be told they are interacting with an AI system, and AI-generated or manipulated content (deepfakes) must be disclosed.
- Minimal risk. Everything else — most AI systems in use — with no new obligations beyond existing law.
- Classification is per use case, not per technology. The same model can be minimal risk in one deployment and high-risk in another. This is the point exam distractors most often exploit.
What the exam asks
Sort a described system into its tier, spot the prohibited practice hidden in a business plan, and recognise when a general-purpose tool has been put to an Annex III use.
Going deeper
This page is the condensed version. The full topic — with the detail above expanded and practice questions attached — is in the app, inside Domain II. Domain I, a quarter of the course, is free to try first.
Back to the AIGP study guide.
AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.