EU AI Act risk ladder

Four EU AI Act rungs (prohibited, high-risk via Annex I or III with the Art. 6(3) filter, transparency, minimal), a GPAI track and notes on other regimes.

EU AI Act risk ladder Four EU AI Act rungs (prohibited, high-risk via Annex I or III with the Art. 6(3) filter, transparency, minimal), a GPAI track and notes on other regimes. EU AI Act · four rungs for AI systems by intended purpose; GPAI models on a separate track Which rung is the system on? The ladder (chapter 18) Other regimes, not equivalents Prohibited Art. 5 From 2025-02-02; new points 2026-12-02 The practice is on the Art. 5 list, now ten points. It may not be placed on the market, put into service or used. Texas TRAIGA (HB 149) Intent-based prohibitions: behaviour manipulation, government social scoring, unlawful discrimination, certain sexual content. In force 2026-01-01. High-risk Arts. 6 to 49 Requirements of Arts. 8 to 15, provider and deployer duties, conformity assessment. Through products, Art. 6(1) From 2028-08-02 A safety component of an Annex I product, or the product itself, that needs a third-party conformity assessment. The Omnibus narrowed "safety component". Through use, Art. 6(2) From 2027-12-02 The intended purpose falls in one of the eight Annex III areas. Filter, Art. 6(3) No significant risk of harm, and one of four conditions: a narrow procedural task; it improves a completed human activity; it detects patterns without replacing human review; a preparatory task. Filtered out: document the assessment, register it (Arts. 6(4), 49(2)). Override: an Annex III system that profiles natural persons is always high-risk. Korea AI Basic Act High-impact AI: a listed Art. 2(4) area, such as hiring and loan screening, that may significantly affect, or pose a risk to, life, physical safety or fundamental rights. The operator reviews it in advance; MSIT may confirm (Art. 33). Transparency Art. 50 From 2026-08-02 It interacts with people, generates synthetic content, recognises emotions, categorises biometrically or produces deep fakes. Disclose, mark, label, whatever else the system is: an Annex III chatbot sits on two rungs. Colorado SB 26-189 A transparency note: deployers of ADMT in consequential decisions give notice of its use and a plain-language explanation within 30 days of an adverse outcome. From 2027-01-01. Minimal Arts. 4, 95 From 2025-02-02; Art. 4 reworded 2026-07-27 Everything else. No specific duties beyond AI literacy (Art. 4); voluntary codes (Art. 95). A legal category, not a risk verdict. Separate track: GPAI models Arts. 51 to 56 From 2025-08-02; Commission enforcement 2026-08-02 Model generality; systemic risk by capability, compute or designation. Model-level duties. A system built on the model is an AI system (Art. 3(66)) and sits on the ladder. California SB 53 Frontier developers: models trained above 10^26 operations; large frontier developers above USD 500M revenue. In force 2026-01-01. Source: chapter 18, The risk ladder; chapter 21 (other regimes); dates from chapter 08. As of 2026-09-24 · a reading aid, not legal advice; illustrative, not a claim of conformity
EU AI Act risk ladder The four rungs the EU AI Act puts AI systems on by intended purpose, with the two high-risk routes and the Article 6(3) filter, the separate track for GPAI models, and side notes on what Korea, Texas, California and Colorado do instead, as of 2026-09-24. Place each system on every rung it meets, then read off its duties and dates. Drawn from chapters 18 and 21.

Text alternative

The EU AI Act sorts AI systems by intended purpose onto four rungs and puts GPAI models on a separate track; one system can sit on two rungs at once, as an Annex III chatbot carries the high-risk duties and the Art. 50 disclosure. Prohibited (Art. 5), from 2025-02-02 with new points from 2026-12-02: the practice is on the Art. 5 list, now ten points, and may not be placed on the market, put into service or used. High-risk (Arts. 6 to 49): requirements of Arts. 8 to 15, provider and deployer duties and conformity assessment. It is reached through products (Art. 6(1)), from 2028-08-02, where a safety component of an Annex I product, or the product itself, needs a third-party conformity assessment, a notion the Omnibus narrowed; or through use (Art. 6(2)), from 2027-12-02, where the intended purpose falls in one of the eight Annex III areas. The Art. 6(3) filter takes an Annex III system out when it poses no significant risk of harm and performs a narrow procedural task, improves a completed human activity, detects patterns without replacing human review, or performs a preparatory task; the provider documents the assessment and registers it (Arts. 6(4) and 49(2)). An Annex III system that profiles natural persons is always high-risk. Transparency (Art. 50), from 2026-08-02: a system that interacts with people, generates synthetic content, recognises emotions, categorises biometrically or produces deep fakes must disclose, mark or label, whatever else it is. Minimal (Arts. 4 and 95), from 2025-02-02 with Art. 4 reworded on 2026-07-27: everything else, with no specific duties beyond AI literacy and voluntary codes; a legal category, not a risk verdict. The GPAI track (Arts. 51 to 56), from 2025-08-02 with Commission enforcement from 2026-08-02: model generality, and systemic risk by capability, compute or designation, carry model-level duties; a system built on the model is an AI system (Art. 3(66)) and sits on the ladder. Side notes from chapter 21, not equivalents: Texas TRAIGA (HB 149), in force 2026-01-01, has intent-based prohibitions (behaviour manipulation, government social scoring, unlawful discrimination, certain sexual content); the Korea AI Basic Act defines high-impact AI as a listed Art. 2(4) area, such as hiring and loan screening, that may significantly affect, or pose a risk to, life, physical safety or fundamental rights, which the operator reviews in advance and MSIT may confirm (Art. 33); Colorado SB 26-189, from 2027-01-01, a transparency note, has deployers of automated decision-making technology (ADMT) in consequential decisions give notice of its use and a plain-language explanation within 30 days of an adverse outcome; California SB 53, in force 2026-01-01, covers frontier developers of models trained above 10^26 operations and large frontier developers above USD 500M revenue. A reading aid, not legal advice; illustrative, not a claim of conformity.

Download

Every file carries the attribution band "aigovernanceengineer.com · CC BY 4.0 · v0.5.0" inside the image, and the version is in the file name, so a copy always says where it came from and which edition it shows. The SVGs keep the text live: the first follows the viewer's light or dark setting, the other two fix one theme for slides and print. The PNGs are drawn with the site's own typefaces.

Four EU AI Act rungs (prohibited, high-risk via Annex I or III with the Art. 6(3) filter, transparency, minimal), a GPAI track and notes on other regimes.
The PNG, light, 1600 px wide, as it downloads (shown here as a lighter copy).

Reuse and credit

The figure is published under CC BY 4.0: you may copy, share and adapt it, commercially too, provided you give appropriate credit, link to the licence and say if you changed it. Keep the attribution band in the image. A credit line that covers title, author, source and licence:

“EU AI Act risk ladder” by Jorge García Aibar, aigovernanceengineer.com (https://aigovernanceengineer.com/figures/eu-ai-act-risk-ladder), v0.5.0, as of 2026-09-24. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

Embed with HTML

<figure>
  <img src="https://aigovernanceengineer.com/downloads/figures/eu-ai-act-risk-ladder-v0.5.0-light-1600.png" alt="Four EU AI Act rungs (prohibited, high-risk via Annex I or III with the Art. 6(3) filter, transparency, minimal), a GPAI track and notes on other regimes." width="800" height="1146" loading="lazy">
  <figcaption>
    <a href="https://aigovernanceengineer.com/figures/eu-ai-act-risk-ladder">EU AI Act risk ladder</a> by Jorge García Aibar,
    aigovernanceengineer.com, v0.5.0, as of 2026-09-24.
    Licensed under <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a>.
  </figcaption>
</figure>

Embed with Markdown

![Four EU AI Act rungs (prohibited, high-risk via Annex I or III with the Art. 6(3) filter, transparency, minimal), a GPAI track and notes on other regimes.](https://aigovernanceengineer.com/downloads/figures/eu-ai-act-risk-ladder-v0.5.0-light-1600.png)

*[EU AI Act risk ladder](https://aigovernanceengineer.com/figures/eu-ai-act-risk-ladder) by Jorge García Aibar, aigovernanceengineer.com, v0.5.0, as of 2026-09-24. Licensed under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).*