Playbook 1 — Classify Your Risk
The EU AI Act's four tiers, mapped to what an SMB actually deploys
The AI Act sorts every AI system into four tiers. Where you land decides almost everything else: how much documentation, who assesses it, and whether it can be used at all. The tier is the whole game, and for most SMBs it is lower than the headlines suggest.
Two axes fix the tier. The first is your role. A provider builds or places an AI system on the market; a deployer uses someone else’s. Most SMBs are deployers — a CRM’s built-in AI feature, a chatbot, an AI writing tool — and deployer obligations are lighter than provider ones. The second axis is the risk tier of the system itself: unacceptable, high-risk, limited, or minimal.
| Tier | What it covers | SMB example |
|---|---|---|
| Unacceptable | Practices banned outright — manipulation, social scoring, untargeted biometric scraping | Covert behavioural manipulation of customers |
| High-risk | Systems affecting health, safety, rights, or access to essentials | Hiring and CV screening, credit scoring, biometric ID |
| Limited | Some risk, mainly to transparency | A support chatbot, AI-generated marketing copy |
| Minimal | No meaningful effect on people | Spam filter, internal search, a notes summarizer |
The useful realization is where most SMB deployments sit. A CRM with an AI assistant, a chatbot answering FAQs, a tool drafting content — those are limited risk. The heavy machinery the Act is known for — technical documentation, conformity assessment, registration in an EU database — attaches to high-risk systems and to providers, not to a company using an off-the-shelf tool for routine work.
The tiers here overlap with the ones in the Governance Playbook Series, and they should. Playbook 1 of that series asks how much governance an internal use needs; this one asks what the regulation attaches to it. The same use can be light on both, or the same use can be the one that needs the full weight.
One qualification worth keeping. The Digital Omnibus package agreed in May 2026 changed both the timetable and the burden for smaller companies, including a new size category that gives lighter treatment to some high-risk uses. So the tier you land in and the obligations you carry are not frozen — they moved once already and may move again.
A first pass:
- List every AI system you use or provide.
- Tag each as provider or deployer.
- Assign a rough tier: unacceptable, high-risk, limited, minimal.
- Mark anything touching hiring, credit, health, or safety as high-risk until proven otherwise.
- Flag the high-risk ones for a closer look before December 2027.
This is general information, not legal advice. If anything on your list lands in the high-risk tier, confirm the position with counsel before relying on it.
Next: Playbook 2 sets out what is already enforceable versus what is still ahead.