How risk categories and roles work under the EU AI Act
The European AI Regulation (EU AI Act) introduces a risk-based approach to regulating artificial intelligence within the European Union. The underlying principle is that regulatory pressure and obligations increase proportionally with the potential risk of harm the AI application poses to citizens' safety, health, or fundamental rights.
The four risk categories at a glance
- Prohibited practices (Unacceptable risk): AI applications that pose a clear threat to human rights or safety. These include government social scoring, harmful behavioral manipulation, untargeted scraping of facial images, and emotion recognition in the workplace and educational settings.
- High risk: AI systems deployed in critical sectors such as healthcare, biometric identification, infrastructure management, education, recruitment & HR management, and access to essential services. Strict quality and transparency requirements apply here.
- Transparency obligation: Systems with a specific transparency risk, such as chatbots that communicate directly with people or AI models that generate synthetic media content (such as deepfakes). Users must be explicitly informed about the use of AI in these cases.
- Minimal risk: Applications such as spam filters, AI in video games, or simple recommendation systems. No additional legal obligations apply to this category under the regulation.
Why the role (Provider vs. Deployer) is crucial
When determining your obligations, it's not enough to look only at the category of the system. The EU AI Act draws a strict legal distinction between the Provider and the Deployer:
A Provider is the party that develops the AI system (or has it developed) and places it on the market or puts it into use under its own brand name. Providers carry the heaviest set of obligations: among other things, they must set up risk management systems, ensure data governance, draw up technical documentation, carry out conformity assessments, and affix the CE marking.
A Deployer is the organization that deploys an externally sourced or provided AI system within its professional activities. Their task lies primarily in correctly applying the system according to the provider's instructions, setting up human oversight during operational use, and monitoring any risks in the workplace.
Integration into your organization and governance
Determining the category is the first step in responsible implementation. For organizations deploying AI solutions, building a structural AI governance for SMEs is essential to guarantee compliance and operational continuity.
For high-risk AI applications, a prior AI risk analysis and DPIA is also often required to identify potential impact on fundamental rights and privacy in good time. To give employees clear guidelines on what is and isn't permitted, establishing an internal AI policy is essential. Also make sure that agreements with external software vendors are clearly contracted.
For extensive background on the structure of the legislation, you can also EU AI Act explanation on nieuws.llmnet.nl is worth consulting.


