The EU AI Act sorts systems into tiers — prohibited, high-risk, limited-risk, and minimal-risk — and your obligations follow from where you land. The mistake is guessing.
Start with use, not technology
The Act classifies by purpose and context, not by how clever your model is. A simple classifier used for hiring decisions can be high-risk; a sophisticated model used for spam filtering may not be.
Three questions to begin
Does the system fall into a listed high-risk use? Does it interact with people in a way that triggers transparency duties? Is any prohibited practice anywhere near your roadmap? Answering these honestly is the first hour of any review.
This article is general information, not legal advice. Your facts decide your tier.