EU AI Act & Risk Classes
🖱️ Interaktiv: Ziehen zum Drehen · Lektion 2
Learning objectives
After this lesson you will be able to:
- Name and distinguish the four risk classes of the EU AI Act
- Give examples of prohibited, high-risk and low-risk AI systems
- Determine your role as a provider or deployer
- Assess the consequences of violating the EU AI Act
The EU AI Act at a glance
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive regulation of artificial intelligence. It entered into force on 2 February 2025 and is being implemented step by step.
Goal: AI systems should be safe, transparent and legally compliant — without unnecessarily hampering innovation.
💡 Key deadlines
• 2 February 2025 — entry into force; Art. 4 AI literacy is now law • 3 August 2026 — enforcement powers for national authorities • 2 February 2025 — prohibited AI practices (Art. 5) take effect • December 2027 — high-risk obligations (deferred by the Digital Omnibus)
The four risk classes
The EU AI Act follows a risk-based approach:
1. Prohibited (unacceptable risk)
Systems that violate fundamental EU rights:
- Social scoring by government agencies
- Manipulative AI systems (subliminal techniques)
- Real-time biometrics in public spaces (with narrow exceptions)
- Emotion recognition in workplaces
2. High risk
Systems with significant impact on safety or rights:
- AI in critical infrastructure
- Medical devices with AI
- Biometric identification systems
- AI in recruiting, creditworthiness, border control
- AI in law enforcement contexts
3. Limited risk
Systems with transparency obligations:
- Chatbots (must be labeled as AI)
- Deepfakes and synthetic content (labeling obligation)
4. Minimal risk
All other AI systems that trigger no specific obligations:
- AI-based games
- Spam filters
- Product recommendations
📝 Schnellprüfung
Which risk class applies to AI that pre-screens job applications?
Provider vs. deployer — your role
Provider: develops an AI system or places it on the EU market Deployer: uses an AI system within their own organization
Most organizations in the EU are deployers — they use AI tools such as ChatGPT, Copilot or specialized AI applications.
As a deployer you must:
- Train all employees in AI literacy (Art. 4)
- Document the AI systems in use
- Provide human oversight for high-risk systems
- Be transparent toward affected persons
🏢 Praxis-Szenario: Determining risk classes in a company
Your company plans three AI deployments: 1) A chatbot for customer inquiries, 2) A facial recognition system for access control, 3) A tool for automatically sorting job applications. Which risk classes apply?
Enforcement and sanctions
- Up to €35 million or 7% of worldwide annual turnover (prohibited practices)
- Up to €15 million or 3% (high-risk obligation violations)
- Up to €7.5 million or 1.5% (misleading statements)
National supervision in Germany is handled by the Bundesnetzagentur.
💡 Art. 4 applies to everyone
Unlike the high-risk obligations, Art. 4 AI literacy applies to ALL organizations that use AI — regardless of risk class or company size. SMEs are not exempt either.
✅ Wichtige Erkenntnisse
Haken setzen, um deinen Lernfortschritt zu markieren:
→ Go deeper: Permitted & prohibited uses — which AI practices are banned · Transparency obligations — labeling and documentation duties
Weiterführende Inhalte
Relevante Rechtsgrundlagen: Art. 4 · Art. 5 · Art. 6