Step by Step
U
Unacceptable risk — banned outright
Certain AI applications are banned outright under the EU AI Act, including social scoring systems, real-time public biometric surveillance, and subliminal manipulation techniques.
Example: a government-run social credit scoring system based on citizens' behavior being explicitly banned under this category.
H
High risk — strict requirements apply
AI systems used in domains like employment, education, criminal justice, healthcare, and credit decisions face strict regulatory requirements, though they aren't banned outright.
Example: an AI system used for hiring decisions being subject to strict documentation, testing, and oversight requirements under this high-risk category.
L
Limited risk — disclosure requirements
Lower-risk AI applications, like chatbots, face lighter-touch requirements — primarily needing to disclose to users that they are interacting with AI.
Example: a customer service chatbot being required to clearly disclose to users that they are talking to an AI system, not a human.
$
Enforcement — massive potential fines
Violations of the EU AI Act can result in fines up to 35 million euros or 7% of a company's global annual revenue, whichever is higher — among the most severe regulatory penalties globally.
Example: a large multinational company facing a fine calculated as 7% of its global annual revenue for a serious EU AI Act violation, potentially far exceeding the flat 35 million euro figure.
Applied Walkthrough
1
A company is deploying an AI system and needs to determine which EU AI Act risk category applies.
2
If the system performs real-time public biometric surveillance, it falls into the unacceptable risk category and is banned outright.
3
If instead the system is used for employment decisions (like screening job applicants), it falls into the high-risk category, requiring strict compliance measures rather than an outright ban.
4
If the system is simply a customer-facing chatbot, it falls into the limited-risk category, requiring only that it disclose to users that they're interacting with AI — illustrating how the Act's risk-based structure applies very different requirements depending on the application.
Exam Application
Exams test whether you can correctly categorize a described AI application into the EU AI Act's risk tiers (unacceptable, high, limited) and whether you know the significant financial penalties involved (up to 35 million euros or 7% of global revenue). Also expect a comparative question contrasting the EU's rules-based approach with the US's principles-based approach and China's national-strategy approach.
⚠ Common Trap
The most common trap is assuming all AI applications face the same level of regulatory scrutiny under the EU AI Act. The Act specifically uses a risk-based, tiered approach — banning only the most dangerous applications outright, while applying proportionally lighter requirements to lower-risk uses like basic chatbots.
✓ Quick Self-Check
1. Name one AI application banned outright under the EU AI Act's unacceptable risk category.
Social scoring, real-time public biometric surveillance, or subliminal manipulation (any one).
Tap to reveal / hide
2. Name one domain that falls under the EU AI Act's high-risk category.
Employment, education, criminal justice, healthcare, or credit (any one).
Tap to reveal / hide
3. What is required of limited-risk AI systems like chatbots?
They must disclose to users that they are interacting with AI.
Tap to reveal / hide
4. What are the potential fines for violating the EU AI Act?
Up to 35 million euros or 7% of global annual revenue, whichever is higher.
Tap to reveal / hide
5. How does the EU's regulatory approach compare to the US's, based on this lesson?
The EU leads with comprehensive rules, while the US leads with principles and frameworks (like NIST) rather than comprehensive federal law.
Tap to reveal / hide