The AI Act’s four-tier risk structure is clearly defined on paper. How national market surveillance authorities will apply it in the first years of enforcement is a different and still open question.
The AI Act places systems into four categories: unacceptable risk (prohibited), high risk (conformity requirements), limited risk (transparency obligations), and minimal risk (no specific obligations). The prohibited and high-risk categories are defined by Annexes specifying the use cases and sectors that trigger each classification.
Many real systems do not map neatly onto these categories. A system performing multiple functions may fall into different risk classes depending on deployment context. The provider-deployer distinction adds further complexity when systems are adapted after sale.
The AI Act’s risk tiers are defined primarily by use, not by technical capability. The same underlying model can produce different regulatory classifications depending on how and where it is deployed.
National enforcement is assigned to market surveillance authorities that already hold mandates in product safety, financial services, or sectoral regulation. Assessing AI systems within their sectors requires technical and regulatory capacity that is still being developed across member states. Early enforcement decisions will show how the classification thresholds are interpreted in practice, and that interpretation will vary.