The risk pyramid — and the GPAI track beside it

Lesson 2 of 5 in The EU AI Act at a Glance: Purpose, Scope, and the Risk Pyramid.

The Act’s central design decision is proportionality: regulate the use, not the technology, and scale the burden to the risk. The same computer-vision model faces no obligations counting shoppers, heavy obligations screening job applicants, and an outright ban identifying protesters in real time. What changes is not the mathematics — it is what the system is for.

That decision produces the famous four-tier risk pyramid. Click each tier — every one maps to a chapter of this domain.

The four risk tiers (with the GPAI track alongside)

  1. Unacceptable risk — Prohibited — Art 5

    Eight practices the EU judged incompatible with fundamental rights at any price: social scoring, harmful manipulation, exploitation of vulnerable people, untargeted face-scraping, emotion recognition at work and school, and more. No conformity assessment can legalise them. Banned since 2 February 2025, at the top penalty tier: €35M or 7% of worldwide turnover.

  2. High risk — Regulated — Arts 6–49

    Permitted, but only inside a full product-safety regime: risk management, data governance, technical documentation, logging, human oversight, conformity assessment, CE marking, registration. Two routes in: AI as a safety component of regulated products (Annex I) or use in one of eight sensitive areas (Annex III) — employment, education, credit, essential services, law enforcement, migration, justice, biometrics.

  3. Limited risk — Transparency — Art 50

    Systems whose main danger is deception about what you are dealing with. The cure is disclosure, not certification: chatbots must reveal they are machines, synthetic content must be machine-readably marked, deepfakes must be labelled, emotion-recognition deployers must inform the people exposed.

  4. Minimal risk — No new obligations

    Everything else — the overwhelming majority of AI in the economy. Spam filters, recommendation engines, inventory forecasting, AI in video games. The Act adds no new obligations; voluntary codes of conduct are encouraged (Art 95), and existing law (GDPR, consumer protection) still applies as always.

Now the part every simplified diagram gets wrong. The pyramid classifies AI systems by use. But since the 2023 redesign, a second regime runs alongside the pyramid, not inside it: the general-purpose AI track (Arts 51–56). A GPAI model — the foundation model underneath — carries its own obligations (technical documentation, a copyright policy, a training-content summary; plus safety duties above the 10²⁵-FLOP systemic risk (GPAI) threshold) regardless of tier. The two regimes stack: a chatbot built on a GPAI model can simultaneously trigger the model provider’s Art 53 duties and Art 50 transparency and, if deployed for hiring, the full high-risk regime.

One more misconception to kill early: the tiers are not a maturity ladder. A system does not "graduate" between tiers as it improves. Tier is a function of use case and context — change the use, and the tier changes with it.

What each tier costs you — a first orientation (depth comes in later modules)
TierCore obligationWho carries itWhere you will study it

Unacceptable (Art 5)

Do not build, sell, or use — full stop

Everyone in the chain

Prohibited Practices module

High risk (Arts 6–49)

Full lifecycle regime: risk management → data governance → documentation → oversight → conformity assessment → CE mark → registration → monitoring

Provider primarily; deployer, importer, distributor each hold duties

Classification, Requirements, and Value-Chain modules

Limited risk (Art 50)

Disclose: "this is AI", mark synthetic content, label deepfakes

Provider or deployer, by paragraph

Transparency & GPAI module

Minimal risk

Nothing new; voluntary codes encouraged (Art 95)

Background throughout

GPAI track (Arts 51–56)

Model documentation, copyright policy, training-data summary; + evaluations, incident reporting, cybersecurity at systemic-risk scale

The model provider — a different actor from the system provider

Transparency & GPAI module

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.