The EU AI Act risk tiers
Four tiers, and the one that matters to government is high-risk.
The Act sorts systems by risk rather than by technology. A small set of uses is prohibited outright — social scoring, certain biometric categorisation, some emotion inference in work and education. A larger set is high-risk, which triggers substantial obligations: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness requirements, and conformity assessment before deployment.
High-risk is where public administration mostly sits. Systems used in essential public services, in employment decisions, in law enforcement, in migration, and in justice are named. Below that, limited-risk systems carry transparency duties — people must be told they are dealing with a machine — and everything else is largely unregulated.
Obligations phase in over several years, and general-purpose model providers carry their own separate set.
Why it matters here
Australia has no equivalent statute, so the Act functions as the de facto reference point in most serious governance conversations here, and Australian agencies buying from global vendors will meet its artefacts anyway. Knowing the tiers well enough to place a proposed use case is a genuinely useful skill in a room.
The question to ask
If this were deployed in the EU, which tier would it fall into — and if it is high-risk there, why are we comfortable with less here?
Go deeper
Reviewed 2026-09-20 · All decoders