The Risk-Based Blueprint inside the EU AI Act
Europe didn't ban AI. It ranked the harm — and the high-risk band is where most real systems actually live.
Autors: Tim Crouch
Vairāk no AI SecurityEurope didn't try to govern the algorithm. It ranked the use. That is the whole blueprint, and it is easy to miss if you treat the EU AI Act as a ban list with extra paperwork.
The panic response was already underway: national drafts, contradictory borders, companies frozen between them, and citizens with no clear answer when an algorithm judged them. Crack down too hard and the market stalls. Do nothing and the rights in the Charter get handed to a black box. The Union's answer was to stop regulating the technology as a category and start regulating the risk of how it is used.
Four tiers, not one mood
The framework is a pyramid.
Unacceptable risk is banned. Subliminal manipulation that impairs free choice. Social scoring of the kind that grades people over time. Inferring emotion in a workplace or school. Real-time remote biometric identification in public by law enforcement, with only narrow exceptions such as finding a missing victim or stopping an imminent terrorist attack. The point is not efficiency. The point is that some uses violate autonomy even when they "work."
High risk is allowed — under duties. These are the systems that sit on infrastructure, hiring, credit, and other decisions that actually change someone's life. Deploying them means fundamental-rights impact assessment, representative data, bias mitigation, and human oversight that is not a rubber stamp: the operator has to understand the output and be able to override it, including stopping the system. This is the band where most serious products live, which is why security and governance work concentrates here.
Limited and minimal risk sit below that. Transparency where people need to know they are dealing with AI; otherwise, room to build. The Act is trying to put the weight on the powerful uses, not on every experiment.
General-purpose models get their own layer: cybersecurity, incident reporting to authorities, and sandboxes so smaller teams can test without drowning on day one. High-risk systems carry the accountability. Low-risk innovation is supposed to keep moving.
Why this is an AI-security problem
If you classify by vendor pitch ("it's just a chatbot"), you will mis-rank the system. If you classify by use — who it affects, what it decides, whether a human can actually stop it — the security work becomes obvious: inventory, role (provider vs deployer), data provenance, oversight, logging, and evidence that the override is real.
A single rulebook also has a market effect Europe has used before. Comply once, sell across member states. Global vendors tend to adopt the EU standard rather than maintain a second architecture. That is how a regional risk pyramid becomes a default security baseline.
The written companion to this video is our earlier note on the Act as an operating obligation: The EU AI Act turns AI governance into an operating obligation. Watch the video for the pyramid. Use that piece when you need the governance checklist.
The rule is simple enough to keep on a whiteboard: don't regulate the model; rank the use. Then put your security controls on the band where the harm actually is.