
Regulation (EU) 2024/1689, which most people call the EU AI Act, treats AI systems as fundamentally different problems requiring fundamentally different responses. The architecture the Act uses to express this is a four-tier hierarchy that runs from systems so low-stakes they attract no specific obligations at all, up through increasing layers of scrutiny, to a handful of practices the Act removes from the market entirely rather than regulating.
At the highest end are practices that the Act prohibits altogether. As of 2 February 2025, Article 5 of the EU AI Act banned six categories of practice outright:
Social scoring by public authorities,
AI that exploits psychological vulnerabilities to manipulate behaviour,
Real-time biometric surveillance in public spaces (with narrow law-enforcement exceptions),
Systems that infer protected characteristics from biometric data,
Untargeted scraping of facial images from the internet
Emotion recognition in workplaces and educational institutions.
These practices are not subject to conformity assessment, not subject to disclosure requirements. They are simply banned. The Digital Omnibus amendment, Regulation (EU) 2026/1744, in force since 27 July 2026, has since added two further prohibitions that take effect on 2 December 2026, bringing the total to eight. One of them covers AI-generated non-consensual sexual content and child sexual abuse material, a category the original regulation did not reach.
Below the prohibition tier, the rules become more demanding as the risk increases. High-risk systems, defined in Annex III and Article 6, cover areas including critical infrastructure, employment decisions, credit scoring, access to education, and certain law-enforcement tools. A system that automates CV shortlisting sits in this tier. So does software that assigns risk scores in border control. Both must clear conformity assessments, maintain technical documentation, operate under human oversight, and register in an EU database before deployment. The requirements are demanding by design: as the Act's risk-based structure provides, the higher the risk, the stricter the requirements.
General-purpose AI models occupy a parallel track rather than a tier of its own. A foundation model trained on broad data and capable of many tasks is subject to its own obligations under Title VIII, distinct from the high-risk classification applied to deployed systems. Since 2 August 2025, providers of these models have been required to maintain technical documentation, comply with copyright law, and publish summaries of training data. Models above a certain compute threshold attract additional systemic-risk obligations, including model evaluations and incident reporting.
The two tiers below high-risk are, in practice, defined by what they do not require. Limited-risk systems, primarily chatbots and deepfake-generating tools, carry transparency obligations: the user must know they are interacting with an AI, and AI-generated content must be disclosed as such. Minimal-risk systems, which cover the largest share of AI currently deployed commercially, including spam filters, recommendation engines, and most productivity software, face no specific compliance requirements under the Act at all. Developers of these systems may voluntarily adopt codes of conduct, and some industry bodies are building these, but the law leaves them alone.
The Act's amendment in July 2026 created a second issue alongside the new prohibitions: it simultaneously extended compliance deadlines for high-risk systems, giving deployers more time to meet obligations that were already due. Trail-ML's analysis of the amendment notes that the Digital Omnibus pushed several implementation milestones while adding the new banned practices. The legislature tightened the top of the pyramid and loosened the middle at the same moment.
For companies building or deploying AI in Europe today, this creates an asymmetry. The prohibitions are the clearest rules because they are absolute: no conformity assessment makes a banned practice legal, and no business justification overrides an Article 5 ban. The high-risk tier carries the most documentation and process requirements, but those requirements are still being phased in. The minimal-risk tier, where most commercial AI lives, has no specific mandatory obligations for now. For any organisation trying to determine where its systems fall, the first question is whether a system involves anything the Act prohibits outright. Only then does it make sense to look at which other obligations apply.
To conclude, the pyramid is uneven by design: at the top, some uses are simply off-limits. In the middle, the requirements become heavier. At the base, most commercial AI still has room to move freely. The pyramid has a clear shape today, but the line at the top can still move.