Tiers follow use, not sophistication
The Act's central design choice is that risk is a property of what a system is used for, not of how it was built. A large model writing marketing copy sits in the lightest tier. A far simpler statistical model deciding who gets shortlisted for a job sits in the heavy one.
This is unintuitive to technical teams, who tend to rank systems by capability, and it is the single most useful thing to internalise. Asking how advanced is this model tells you nothing about your obligations. Asking what decision does this influence, and about whom tells you almost everything.
Four tiers, in descending weight. Prohibited practices, which may not be placed on the market or used at all. High-risk systems, permitted subject to substantial requirements. Systems with transparency obligations, permitted subject to telling people what is going on. And everything else, which the Act calls minimal risk and leaves essentially unregulated.
Most systems in most organisations land in that last group.

