
Risk Classification
Risk classification sorts artificial intelligence applications according to how much harm they can cause. The higher the tier, the stricter the rules a provider must comply with – ranging from no requirements at all to a complete ban.
Not every computer program that independently proposes decisions is equally dangerous. A filter that sorts out spam emails can cause little harm. A program that helps decide on loans or job applications, by contrast, intervenes deeply in a person’s life. Risk classification is the attempt to capture this difference in rules. It sorts applications into tiers, and specific obligations for the provider are attached to each tier. The basic idea: it is not the technology itself that is assessed, but the purpose for which it is used.
Four tiers under the European AI Act
In 2024, the European Union passed a law on artificial intelligence, known as the AI Act. It is the world’s first comprehensive set of rules of this kind. Its core is precisely this division into risk classes. Comparable approaches have long existed in other fields: medicines and food additives are likewise regulated according to their potential for harm, not across the board.
The AI Act distinguishes four tiers. At the very bottom is minimal risk, such as a spam filter or an opponent in a video game. Here, practically nothing special applies. Above that lies limited risk, subject to transparency obligations: anyone talking to a chatbot must be informed of this, and artificially generated images are supposed to be labeled. The third tier, high risk, covers applications in medicine, human resources, lending, schools, or policing. At the very top are prohibited practices, for example a state-run assessment of citizens' social behavior.
For companies, the classification determines a great deal of money. A high-risk system requires a documented risk analysis, vetted training data, human oversight, and registration in an EU database. Violations can trigger fines running into the millions. This is why the boundaries between the classes are fiercely contested – a shift in tier can render a product unprofitable.
How a classification comes about
The first question is what the system is specifically used for. The same image recognition technology can be harmless or high-risk. If it sorts vacation photos, it is uncritical. If it recognizes faces in a crowd for the police, it is deemed high-risk or is even banned. The purpose decides, not the program code.
To this end, the AI Act works with lists. An annex enumerates the fields of application considered high-risk. Anyone developing a system checks it against this list. There are also exceptions: if an application in a listed field performs only a minor auxiliary task, it can fall outside the classification. The provider must document this self-assessment and produce it upon request.
A common misconception is that large language models are automatically high-risk. A separate set of rules applies to them, with obligations for the developers. Only once someone integrates such a model into a critical field does the high-risk classification take effect. Responsibility then usually lies with the operator of the application, not solely with the model’s manufacturer.
What users and investors notice about it
In everyday life, risk classification shows up in small cues. A chat window that discloses that a machine is answering here. A note under an image stating that it was artificially generated. Such labels are not a courtesy on the part of providers, but a consequence of the transparency obligations in the second tier.
The term surfaces in business news when companies complain about regulatory costs, or when a provider launches a feature in Europe later than elsewhere or not at all. For investors, the classification is a risk metric: a business model built entirely on high-risk applications carries permanently higher compliance and liability costs. Investors, too, have therefore begun asking about a product’s classification.
The rules take effect at staggered times. The bans have applied since early 2025, while the obligations for high-risk systems follow in stages through 2027. Anyone reading reports about the AI Act today should therefore always note which tier is being referred to and from when it takes effect.