Introduction
Summaries of the EU's AI Act usually say it has "four risk tiers" and stop there. The tiers are easier to understand, and to argue about, once you've read how the European Commission describes each one and noticed what kind of thing is being sorted.
This reading walks through the Commission's description of the four levels, one at a time, and then places three everyday uses of AI into them.
Locating the Passage
The passage is on the European Commission's policy page titled "AI Act," which is free and listed in the References. The Commission is the EU's executive body, and this page is its plain-language summary of the law. The version read here was last updated on August 3, 2026.
The page has a section on the law's risk-based approach. It says that "the AI Act defines 4 levels of risk for AI systems" and then describes them from the top down: unacceptable risk, high risk, transparency risk, and minimal or no risk. All quotations are from this page (European Commission 2026a). The law itself is Regulation (EU) 2024/1689, and its articles and annexes hold the binding definitions (European Union 2024).
Walking Through the Passage
Step 1: Read the unacceptable-risk level and find its test
The page says that AI systems considered "a clear threat to the safety, livelihoods and rights of people" are banned. That phrase is the test for the top level. It names three things that could be threatened, and it asks for a threat that is "clear."
A list of banned practices follows. It includes "social scoring," "harmful AI-based manipulation and deception," "emotion recognition in workplaces and education institutions," and "untargeted scraping of the internet or CCTV material to create or expand facial recognition databases."
Every item on the list is a use. The list doesn't ban a kind of software, such as face recognition in general. It bans doing particular things with it, such as building a face database by collecting images indiscriminately.
The list has also grown. As the page stood in August 2026 it had nine items, the ninth being AI systems that generate sexual images without consent or child sexual abuse material. The page notes that the first eight applied from February 2025 and the ninth applies from December 2026.
Step 2: Read the high-risk level and list the kinds of use
The page gives the test: "AI use cases that can pose serious risks to health, safety or fundamental rights are classified as high-risk." Compare the wording with the top level. A "clear threat" has become "can pose serious risks." These uses are permitted, and the law's concern is that they might go wrong.
The page then lists areas. Among them are "AI safety components in critical infrastructures (e.g. transport)," tools used in schools "that may determine the access to education and course of someone's professional life," "AI tools for employment, management of workers and access to self-employment," uses that "give access to essential private and public services," and uses in law enforcement, migration and border control, and the administration of justice.
These areas have something in common. In each, a system's output can change what happens to a person: whether they get a job, a loan, a school place, or a visa.
The duties come next. Providers need "adequate risk assessment and mitigation systems," "logging of activity to ensure traceability of results," and "appropriate human oversight measures," among other things. The page gives December 2, 2027 as the date these duties begin to apply.
Step 3: Read the transparency level and say what it requires
The page describes this level as covering "the risks associated with a need for transparency around the use of AI." The law responds with "specific disclosure obligations to ensure that humans are informed when necessary to preserve trust."
Three duties are named. When people use "AI systems such as chatbots," they "should be made aware that they are interacting with a machine." Providers of generative AI "have to ensure that AI-generated content is identifiable." And deepfakes, along with AI-written text published to inform the public on matters of public interest, "should be clearly and visibly labelled."
This level doesn't restrict what a system does. A chatbot may say what it likes, within other laws. The duty is to tell you what you're dealing with.
Step 4: Read the minimal-risk level and note how much falls here
The fourth description is the shortest: "The AI Act does not introduce rules for AI that is deemed minimal or no risk." The page adds that "the vast majority of AI systems currently used in the EU fall into this category," and gives as examples "AI-enabled video games or spam filters."
This sentence is easy to pass over, and it changes the picture. By the Commission's own account, the law leaves most AI in use alone. The Commission has an interest in presenting its law as measured, so treat "vast majority" as its claim. The claim is consistent with the structure of the law, since the first three levels are defined by lists and the fourth is everything not on them.
Step 5: Place three everyday uses and ask what would move each one up
Take three uses you might meet in a week.
- A spam filter in your email. The page names spam filters as minimal risk, so no duties apply. The filter itself wouldn't move up. A similar sorting system would, if an employer used it to rank job applications, because employment is a listed high-risk area.
- A customer-service chatbot on a shop's website. This falls in the transparency level. The shop must make sure you know you're talking to a machine. It would move to high risk if the same chatbot decided whether you qualify for an essential service, such as credit or a public benefit.
- Software that screens job applications. This is high risk, since the page lists tools for employment and names "CV-sorting software for recruitment" as an example. It would move to the banned level if it tried to read applicants' emotions from their faces or voices in an interview, because "emotion recognition in workplaces" is on the prohibited list.
In each case the software barely changes. The level changes because the use does.
Key Considerations
The page is a summary. It's the Commission's account of the law, written for the public, and it leaves out the conditions and exceptions that the regulation contains. The binding categories are in the regulation itself: the prohibited practices in Article 5 and the high-risk areas in Annex III (European Union 2024). A real system's classification depends on that text, and on guidance and court decisions still to come.
A common mistake is to assume that the Act regulates AI as a technology. For the most part it regulates uses. The same model can power a minimal-risk game and a high-risk hiring tool. The main exception is the Act's separate set of rules for general-purpose models, which apply to a model's provider whatever the model is used for.
A second mistake is to read "high-risk" as "discouraged." High-risk uses are legal. The label triggers duties, and the page presents those duties as what allows such systems to be trusted.
Summary
The Commission describes four levels, each with a test, and the tests concern what a system is used for. The result of the reading is this table.
| Level | Test | Example | Duty |
|---|
| Unacceptable risk | "A clear threat to the safety, livelihoods and rights of people" | Social scoring | The use is banned |
| High risk | "Can pose serious risks to health, safety or fundamental rights" | Software that sorts job applications | Risk assessment, record-keeping, human oversight, and other duties, from December 2027 |
| Transparency risk | People need to know AI is involved | A chatbot; a deepfake | Tell people; make AI-generated content identifiable |
| Minimal or no risk | Everything not listed above | A spam filter | No new rules |
References
- European Commission. 2026a. "AI Act." Policy page. Last updated August 3, 2026.
- European Union. 2024. Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union, July 12, 2024.