Tiers + obligations
Four tiers
| Tier | Examples | Obligation summary |
|---|---|---|
| Unacceptable risk | Social scoring by governments, real-time biometric ID in public spaces. | Banned. |
| High risk | Credit, hiring, medical, education, critical infra, law enforcement. | Risk mgmt, data governance, technical docs, transparency, human oversight, accuracy & robustness, conformity assessment, registration. |
| Limited risk | Chatbots, deepfakes. | Disclosure that user is interacting with AI / content is AI-generated. |
| Minimal risk | Spam filters, recommender systems (most). | Voluntary codes of conduct. |
Practical implications
- Know your tier before you build.
- For high-risk systems, the technical-documentation requirement is essentially: tracking + registry + model card + monitoring + audit log. (Sound familiar?)
- Penalties scale up to 7% of global turnover for the worst breaches.