UprootSecurityUprootSecurity

Phase 7 · AI Security Landscape + Governance Frameworks · Lesson 3 of 4

Watch: Classifying AI Systems Under the EU AI Act Tiers

Video

·

10 min

·

+10 pts

You just read the four EU AI Act risk tiers — unacceptable, high, limited, minimal. This short walkthrough runs the classification the way you will do it in the next exercise: take a real-looking AI system, ask what it is used for (not what model it runs on), and place it in the tier that decides its obligations. The point to watch for is how often the same technology lands in different tiers depending on the use case — a chatbot is minimal risk when it answers FAQs and high risk when it screens job applicants.

Watch for the two questions that do all the work: who does this affect, and how reversibly? A system that ranks job candidates, scores creditworthiness, or triages patients touches people's life chances — that is what pushes a use case into high risk and its heavy control set (risk management, data governance, logging, human oversight, conformity assessment). A system that just needs you to know you're talking to a bot sits in limited risk with a transparency obligation. Keep the throughline in view: the tier is not a label for its own sake — it determines which controls become mandatory and what evidence a regulator will ask to see.

Invalid YouTube ID or URL: PLACEHOLDER_EU_AI_ACT_TIERS

No environment needed

This is a conceptual walkthrough — nothing to install or run. The value is in the judgement: hearing the reasoning out loud for a few systems before you classify eight of your own. There is usually a defensible answer, and sometimes a genuinely borderline one — the video calls those out, because in practice a borderline tier is exactly when you document your reasoning and ask for a second opinion.

What to carry forward

Classify by use and impact, not by technology. The same model can be minimal risk in one product and high risk in another; what moves it is who it affects and how hard the consequences are to undo. In the exercise next, you will sort eight AI use cases into the four tiers and write the one-line reason for each — the exact artifact that, in a real EU AI Act assessment, justifies which controls a system has to carry.

Watch: Classifying AI Systems Under the EU AI Act Tiers — UprootSecurity Bootcamp