AnyLearn
All lessons
Businessintermediate

Risk Tiers and the Amended Compliance Timeline

The AI Act sorts systems into four tiers by what they are used for, not by how sophisticated they are. This lesson covers prohibited practices, the two routes into the high-risk tier, the derogation that lets a listed system out, the transparency duties, and the timeline as amended by the 2026 Digital Omnibus: which dates moved, which did not, and how grandfathering works.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 10

Tiers follow use, not sophistication

The Act's central design choice is that risk is a property of what a system is used for, not of how it was built. A large model writing marketing copy sits in the lightest tier. A far simpler statistical model deciding who gets shortlisted for a job sits in the heavy one.

This is unintuitive to technical teams, who tend to rank systems by capability, and it is the single most useful thing to internalise. Asking how advanced is this model tells you nothing about your obligations. Asking what decision does this influence, and about whom tells you almost everything.

Four tiers, in descending weight. Prohibited practices, which may not be placed on the market or used at all. High-risk systems, permitted subject to substantial requirements. Systems with transparency obligations, permitted subject to telling people what is going on. And everything else, which the Act calls minimal risk and leaves essentially unregulated.

Most systems in most organisations land in that last group.

Full lesson text

All 10 steps on one page, for reading, reference, and search.

Show

1. Tiers follow use, not sophistication

The Act's central design choice is that risk is a property of what a system is used for, not of how it was built. A large model writing marketing copy sits in the lightest tier. A far simpler statistical model deciding who gets shortlisted for a job sits in the heavy one.

This is unintuitive to technical teams, who tend to rank systems by capability, and it is the single most useful thing to internalise. Asking how advanced is this model tells you nothing about your obligations. Asking what decision does this influence, and about whom tells you almost everything.

Four tiers, in descending weight. Prohibited practices, which may not be placed on the market or used at all. High-risk systems, permitted subject to substantial requirements. Systems with transparency obligations, permitted subject to telling people what is going on. And everything else, which the Act calls minimal risk and leaves essentially unregulated.

Most systems in most organisations land in that last group.

2. Prohibited practices

Article 5 bans a defined set of practices outright. These have applied since 2 February 2025 and carry the highest penalty tier.

The list covers subliminal, manipulative or deceptive techniques that materially distort behaviour and cause significant harm; exploitation of vulnerabilities due to age, disability or a specific social or economic situation; social scoring by public or private actors leading to detrimental treatment in unrelated contexts or disproportionate to the behaviour; predicting criminal offending based solely on profiling or personality traits; untargeted scraping of facial images to build recognition databases; emotion inference in the workplace and in education, outside medical or safety purposes; biometric categorisation to infer sensitive attributes such as race, political opinions or sexual orientation; and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions.

The 2026 Digital Omnibus added a further prohibition covering AI-generated non-consensual intimate imagery and child sexual abuse material, with a transitional period running to 2 December 2026.

Two of these reach ordinary employers directly. Emotion inference in the workplace catches sentiment analysis applied to staff, and the education limb catches similar tools applied to students.

3. Two routes into the high-risk tier

A system becomes high-risk by one of two independent routes, and they behave differently.

The first is the product-safety route, in Annex I. If a system is a safety component of a product already covered by EU product legislation, or is itself such a product, and that product requires third-party conformity assessment, the AI system is high-risk. Machinery, medical devices, lifts, toys and vehicles are the sort of thing in scope. The 2026 Omnibus narrowed the definition of safety component and carved out products covered by the Machinery Regulation, removing a double-regulation overlap.

The second is the use-case route, in Annex III. Eight areas: biometrics; critical infrastructure; education and vocational training; employment and worker management; access to essential private and public services, including creditworthiness assessment; law enforcement; migration, asylum and border control; and administration of justice and democratic processes.

Annex III is where ordinary commercial organisations land. Recruitment screening, promotion and task-allocation tools, credit scoring, and admissions or grading systems are all inside it, and none of them require advanced technology to qualify.

4. The derogation that lets a system out

Being listed in Annex III creates a presumption, not a conclusion. Article 6(3) provides a derogation.

A system in an Annex III area is not high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision-making.

The Act gives conditions under which this applies, covering systems intended to perform a narrow procedural task, to improve the result of a previously completed human activity, to detect decision-making patterns or deviations from prior patterns without replacing or influencing the human assessment without proper review, or to perform a preparatory task to an assessment.

The derogation is not self-executing and it is not free. A provider relying on it must document the assessment before placing the system on the market, remains subject to registration obligations, and must produce the documentation to national authorities on request.

The distinction that decides most cases is whether the system materially influences the decision. A tool that reformats applications for a human to read is preparatory. A tool that ranks them so the human reads the top twenty is influencing the outcome, whatever the interface claims.

5. Working out the tier

The classification runs as a sequence of tests, in order, and stopping at the first that matches.

Start with the prohibited list. If the practice is on it, there is no compliance path; the use has to stop.

Then the two high-risk routes. Product-safety component under Annex I, or use case within Annex III. If Annex III matches, check whether the Article 6(3) derogation applies, and document that assessment if you rely on it.

Then the transparency tier: systems that interact with people, generate synthetic content, perform emotion recognition or biometric categorisation, or produce deepfakes.

What remains is minimal risk, where the Act imposes no product requirements. Note that the tiers are not exclusive at the bottom end: a high-risk system that also interacts with people carries the transparency duties too.

flowchart TD
A["Is the practice in the Article 5 prohibited list?"] --> B["Yes: not permitted at all"]
A --> C["No: check high-risk routes"]
C --> D["Annex I: safety component of a regulated product"]
C --> E["Annex III: listed use case"]
E --> F["Article 6(3) derogation applies? Document it"]
F --> G["Not high-risk, but registration still applies"]
D --> H["High-risk: full requirements"]
E --> H
C --> I["Transparency tier: interacts, generates, or recognises"]
I --> J["Article 50 duties"]
C --> K["Minimal risk: no product requirements"]

6. The transparency tier

Article 50 is the tier most organisations will actually meet first, because it applies to the generative tools already in use.

Providers must ensure systems intended to interact directly with people are designed so people are informed they are interacting with an AI system, unless it is obvious to a reasonably well-informed person.

Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format detectable as artificially generated or manipulated.

Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them.

Deployers generating or manipulating deepfake content must disclose that it is artificially generated or manipulated, with an adjustment where the content is part of an evidently artistic or satirical work. Deployers publishing text to inform the public on matters of public interest must disclose artificial generation, unless the content underwent human review with editorial responsibility.

These duties apply from 2 August 2026 and were not deferred by the Omnibus. The one concession: the machine-readable marking requirement does not bite until 2 December 2026 for systems already on the market before August.

7. The timeline as amended

The Act entered into force on 1 August 2024 and applies in staggered waves. The 2026 Digital Omnibus moved some of them and left others alone, so the table below is the operative one.

2 Feb 2025   Prohibited practices (Art 5); AI literacy (Art 4)
2 Aug 2025   GPAI model obligations; governance bodies
             (models already on market: full compliance by 2 Aug 2027)
2 Aug 2026   Article 50 transparency duties  [NOT deferred]
2 Dec 2026   Art 50(2) marking for systems already on market;
             new prohibition on AI-generated NCII and CSAM
2 Dec 2027   Annex III standalone high-risk   [was 2 Aug 2026]
2 Aug 2028   Annex I embedded high-risk       [was 2 Aug 2027]

The pattern is worth reading. What was deferred is the heavy high-risk machinery, by sixteen months and twelve months respectively. What was not deferred is the transparency layer, which is precisely the layer that touches the generative tools most organisations already run.

So an organisation that concluded from headlines about delay that nothing lands soon has drawn the wrong inference. The nearest deadline for most is 2 August 2026, and it is untouched.

8. Grandfathering

The Omnibus also settled what happens to systems already deployed when a deadline passes, and the answer changes the calculus for anyone mid-project.

AI systems placed on the EU market before the applicable high-risk date are not subject to the high-risk requirements, unless they undergo a substantial modification after that date.

The qualifier carries the weight. Substantial modification is a defined concept, covering changes not foreseen in the provider's initial conformity assessment that affect compliance with the requirements or alter the intended purpose. Ordinary maintenance does not trigger it. Retraining a model on materially different data, or extending it to a new decision, plausibly does.

Two consequences follow. A system frozen before the date inherits a lighter regime than an identical system launched after it, which is an odd incentive but a real one. And any organisation relying on grandfathering needs a record of what the system was at the cut-off, because the claim is only defensible against a documented baseline.

Relying on this without that record is the kind of position that looks fine until someone asks.

9. Penalties, accurately

Article 99 sets a tiered penalty structure, and the figures get quoted far more often than they get attributed to the right provisions.

Up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher, for breach of the Article 5 prohibited practices. This is the tier the headlines use, and it belongs to the banned list alone.

Up to 15 million euros or 3 percent, for non-compliance with most other obligations, including provider and deployer duties for high-risk systems and the Article 50 transparency duties.

Up to 7.5 million euros or 1.5 percent, for supplying incorrect, incomplete or misleading information to notified bodies or national authorities.

For SMEs including start-ups, the caps apply as the lower of the percentage or the fixed amount rather than the higher, which materially reduces exposure for smaller organisations.

Member States set their own penalty regimes within this framework, and supervision sits with national market surveillance authorities. Penalties must be effective, proportionate and dissuasive, with the authority taking into account the nature and gravity of the infringement and whether it was negligent or intentional.

10. What to do with the extra time

The deferral of the high-risk deadlines is real relief for organisations building or deploying Annex III systems. It is not a reason to stop, for three reasons worth being concrete about.

The near-term dates are unchanged. Article 50 transparency lands on 2 August 2026, and the prohibited practices have been in force since February 2025. An organisation running emotion inference on its workforce is not waiting for a deadline; it is already outside the law.

The work that the high-risk regime requires has long lead times. Data governance, technical documentation, a quality management system and a conformity assessment are not tasks that compress into a final quarter, which is precisely why the deadline moved.

And classification takes longer than expected. Most of the elapsed time in these projects goes into establishing what systems exist and which ones are in Annex III areas, not into the compliance work itself.

The defensible use of the extra sixteen months is to complete the inventory and classification now, then sequence the heavy work against the new dates. That is the subject of the third lesson, which turns this into a proportionate plan for an organisation without a legal department.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. What determines which risk tier an AI system falls into?
    • The size of the model and its technical capability
    • What the system is used for and who it affects
    • Whether the provider is established in the EU
    • The volume of personal data the system processes
  2. Which date was NOT deferred by the 2026 Digital Omnibus?
    • Annex III standalone high-risk obligations
    • Annex I embedded high-risk obligations
    • The Article 50 transparency duties on 2 August 2026
    • Both high-risk deadlines were left unchanged
  3. A recruitment tool ranks applicants so a human reviews only the top twenty. Can the provider rely on the Article 6(3) derogation?
    • Yes, because a human still makes the final decision
    • Yes, because ranking is a preparatory task
    • Only if the tool is used by an SME
    • No, because ranking materially influences the outcome of the decision
  4. Under the grandfathering rule, what causes an already-deployed system to lose its exemption from the high-risk requirements?
    • A substantial modification after the applicable date
    • Any software update, including routine maintenance
    • A change of deployer
    • The passage of the deadline itself
  5. How does the penalty cap work differently for SMEs and start-ups?
    • SMEs are exempt from penalties entirely
    • The cap is the lower of the fixed amount or the percentage, rather than the higher
    • Penalties are capped at 1.5 percent regardless of the breach
    • SMEs receive an automatic reduction of fifty percent

Related lessons

Law & Compliance
advanced

Proof: Disclosure, Presumptions, and the Complexity Rule

Strict liability is worthless if the claimant cannot prove a defect they never saw. Articles 9 and 10 answer that with a disclosure order, three presumptions of defectiveness, a presumption of causation, and a rule turning complexity into the claimant's ally. This lesson works through the cascade, the three-year and ten-year clocks, and what a defendant should be able to produce.

10 steps·~15 min
Law & Compliance
advanced

Who Pays, and For What Damage

The Directive builds a chain of liable operators so an injured person in the EU always has someone to sue. This lesson covers the manufacturer and component manufacturer, the importer and fulfilment service provider route, the distributor's one-month rule, online platforms, how a modification makes you a manufacturer, the heads of damage including data loss, and the exemptions.

10 steps·~15 min
Law & Compliance
advanced

Defectiveness: The Safety a Person Is Entitled to Expect

A product is defective when it lacks the safety a person is entitled to expect. Article 7 turns that into circumstances a court weighs, several written for software: the ability to learn after release, interconnection, cybersecurity requirements, and recalls. This lesson works through the list, the rule that a later improvement is not an admission, and why compliance is not a defence.

10 steps·~15 min
Law & Compliance
advanced

Software as a Product: What the New Liability Directive Changed

Directive (EU) 2024/2853 replaces the 1985 regime and settles a forty-year argument by naming software a product. This lesson covers the new definition and why delivery method is irrelevant, why information is not a product, how components and related services extend the net, where open source sits, and why liability cannot be disclaimed by contract.

10 steps·~15 min