Phase 7 · AI Security Landscape + Governance Frameworks · Lesson 4 of 4
Exercise
·
20 min
·
+20 pts
This is the judgement call at the heart of an EU AI Act assessment, and it is squarely a GRC engineer's job: take an AI system, decide its risk tier, and thereby decide how heavy its controls have to be. The rule from the video holds — classify by use and impact, not by technology. Ask who the system affects and how reversibly, and the tier usually follows. A handful are genuinely borderline; for those, the reasoning you write matters more than the label.
Below are eight AI use cases a company might be running. For each, pick the tier and note the one-line reason. Then check your reasoning against the reference.
Exercise
~20 min
Place eight AI systems in their EU AI Act risk tier
Read each use case for what it is used for and who it affects. Choose its EU AI Act tier and write the one-line reason a regulator would read.
The four tiers
Banned
Unacceptable risk. Prohibited outright (Art. 5) — e.g. social scoring, manipulative or exploitative systems, most real-time biometric ID in public.
High
High risk. Allowed but heavily regulated (Annex III) — risk management, data governance, logging, human oversight, conformity assessment, registration.
Limited
Limited risk. Transparency obligations (Art. 50) — users must be told they are interacting with AI / seeing AI-generated or manipulated content.
Minimal
Minimal risk. No specific obligations under the Act; voluntary codes of conduct.
For each use case, choose the EU AI Act risk tier and note the one-line reason. There is a defensible answer for each; the reasoning matters as much as the label.
Use case 1
Government citizen social-scoring system
A public agency scores residents on trustworthiness using behavioral and financial data, and uses the score to grant or deny access to public services.
Risk tier
Reason (optional)
Use case 2
Real-time public facial recognition for law enforcement
Police run live facial recognition across cameras in public squares to identify people in the crowd in real time.
Risk tier
Reason (optional)
Use case 3
AI resume screening for hiring
An applicant-tracking tool ranks and filters job candidates, deciding who advances to a human recruiter.
Risk tier
Reason (optional)
Use case 4
AI creditworthiness scoring for loans
A model decides whether individuals qualify for a consumer loan and on what terms.
Risk tier
Reason (optional)
Use case 5
Emergency-room AI triage assistant
A clinical tool prioritizes incoming patients by predicted severity, influencing who is seen first.
Risk tier
Reason (optional)
Use case 6
Customer-support chatbot (product FAQs)
A website chatbot answers questions about product features, shipping, and returns. It takes no consequential action on the user.
Risk tier
Reason (optional)
Use case 7
AI deepfake / synthetic image generator for marketing
A tool generates photorealistic synthetic images and video of people for ad campaigns, published to the public.
Risk tier
Reason (optional)
Use case 8
Email spam filter
A model classifies inbound email as spam or not and moves spam to a junk folder.
Risk tier
Reason (optional)
Classification so far
0/8 classified
Banned
0
none yet
High
0
none yet
Limited
0
none yet
Minimal
0
none yet
Two patterns do most of the work. First, impact on people drives the tier: anything deciding access to jobs, credit, healthcare, or essential services trends toward high-risk and its full control set, while low-stakes, reversible tooling trends toward minimal. Second, transparency is its own tier: chatbots and synthetic media aren't dangerous in the high-risk sense, but people have a right to know AI is involved — that is what limited risk encodes. And the prohibited tier is small but absolute: social scoring and untargeted public biometric surveillance are off the table, not merely controlled. Getting the tier right is the first deliverable of an EU AI Act assessment, because everything downstream — which controls are mandatory, what evidence a regulator demands — follows from it. The next module turns to the most common AI-specific threat itself: prompt injection, and how to defend against it.