The EU AI Act, which entered into force in August 2024, does not treat all artificial intelligence the same way. Instead, it organises AI systems into four distinct risk tiers, imposing progressively heavier obligations as potential harm increases. For editors and publishers integrating AI tools into their workflows, understanding where a given system sits in that hierarchy is the first practical step toward compliance. We have already covered the Act's content-authenticity requirements for publishers and the latest status updates for 2026. This piece focuses on the risk tiers themselves.

The four tiers at a glance

The Act defines four categories of risk: unacceptable risk (systems that are outright banned), high risk (systems subject to strict pre-market and ongoing obligations), limited risk (systems carrying transparency obligations), and minimal risk (systems that are largely unregulated). Every AI application a newsroom deploys, from automated summarisation tools to algorithmic audience-targeting systems, falls somewhere on that spectrum.

Unacceptable risk: what is banned outright

The top tier covers AI practices the EU legislature deemed incompatible with fundamental rights. These include real-time remote biometric identification systems used in public spaces by law enforcement (with narrow exceptions), systems that manipulate people through subliminal techniques, tools that exploit vulnerabilities based on age or disability, and social scoring systems operated by public authorities. Newsrooms are unlikely to deploy systems in this category, but the prohibition is absolute: no business justification overrides it. This tier's prohibitions have been in force since August 2024.

High risk: the most consequential tier for compliance teams

High-risk AI systems face the most detailed obligations under the Act. Providers must conduct conformity assessments, maintain technical documentation, implement risk-management systems, ensure human oversight, and register their systems in an EU-wide database before placing them on the market. The specific categories covered by this tier are listed in Annex III of the Act.

Annex III covers eight areas, including biometric identification, critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice. The employment and worker-management category is particularly relevant to media organisations: AI systems used to make or materially influence decisions about hiring, task allocation, or performance monitoring of staff may qualify as high-risk under that heading.

It is worth noting a significant recent development here. The May 2026 AI Omnibus package postponed the application of Annex III high-risk obligations to 2 December 2027. That delay gives organisations more time to prepare, but it does not remove the obligations. Compliance teams should treat the intervening period as preparation time, not an exemption. Our coverage of what changed for publishers in 2026 explains the Omnibus postponement in more detail.

Limited risk: transparency is the key obligation

Limited-risk systems are not banned and do not require conformity assessments, but they do carry transparency obligations. The clearest example is chatbots: the Act requires that users be informed they are interacting with an AI system, not a human. Deepfake content and AI-generated images, audio, or video also fall here, with providers required to label such content as artificially generated or manipulated.

This tier is highly relevant to publishing. Newsrooms deploying AI chat interfaces, automated interview bots, or tools that generate synthetic media for editorial purposes need to ensure their disclosure practices satisfy these requirements. The debate over how publishers should label AI-assisted content maps directly onto the limited-risk tier's transparency demands.

Minimal risk: the broad base of the pyramid

The vast majority of AI systems in use today fall into the minimal-risk category. This includes AI-powered spam filters, inventory-management tools, video games using AI, and most recommendation engines. The Act imposes no mandatory obligations on these systems, though it encourages providers to adopt voluntary codes of conduct. For newsrooms, tools such as grammar checkers, basic image-cropping assistants, and content-management automations generally sit here.

How newsrooms should apply this framework

A practical first step is to map every AI tool currently in use against the four tiers. That means asking: does this system influence decisions about people (employment, access to services, safety)? Does it generate synthetic media? Does it interact with readers directly? The answers place the tool in a tier and reveal the compliance gap.

  • Audit existing tools and assign each one to a risk tier.
  • For any tool that might qualify as high-risk under Annex III, begin documentation and risk-management preparation now, ahead of the December 2027 deadline.
  • For limited-risk tools, review disclosure language facing readers and staff.
  • Embed tier classification into procurement decisions so that new tools are assessed before deployment, not after.

Our policy templates for AI writing assistants include sections that can be adapted for this kind of internal classification exercise. More broadly, connecting compliance work to the editorial values that govern synthetic media ethics in our newsrooms ensures that legal minimums and journalistic standards reinforce each other rather than pulling in opposite directions.

Sources

  • Regulation (EU) 2024/1689 of the European Parliament and of the Council (the EU AI Act), Official Journal of the European Union, August 2024.
  • Annex III, Regulation (EU) 2024/1689, listing high-risk AI system categories.
  • EU AI Act Omnibus package (May 2026), amending application dates for Annex III obligations to 2 December 2027.
  • European Commission, AI Act implementation guidance, European Commission website.