1
Unacceptable Risk – Prohibited (e.g., social scoring, mass surveillance)
2
High Risk – Strict requirements (e.g., AI in healthcare, hiring, finance)
3
Limited Risk – Requires transparency to users
4
Minimal Risk – No regulatory impact (e.g., spam filters)
1
Risk assessments & bias mitigation
2
High-quality, representative datasets
3
Human oversight & audit logging
4
1
Disclose training data summaries and system capabilities
2
Identify and mitigate systemic risks
3
Report serious incidents and malfunctions
4
Implement safeguards for downstream use and reuse
1
Applies to all providers whose AI outputs reach EU users
2
Enforced by European AI Board and national authorities
3
Mandatory registration for high-risk AI systems in the EU database
4
Fines up to €30 million or 6% of global annual turnover for non-compliance
1
Centralized inventory to log AI use cases, purposes, and risk categories
2
Workflow automation for documentation, classification, and internal reviews
1
Multi-lingual, omni-channel tools to collect dynamic AI interaction consent
2
Auto-tag AI-driven processes for compliance reporting
1
PII discovery and data quality audits to reduce risk in training data
2
Automated flagging of sensitive or non-compliant data
1
AI-specific RoPA and DPIA workflows
2
Compliance reporting integrated with broader privacy frameworks
1
Track third-party AI system compliance
2
Capture model declarations and risk assurances