EU AI Act compliance, built on the Act's own four risk tiers
EU AI Act teams need to know which AI systems are in scope, which risk tier each one falls into, and which duties follow. Rizzqo gives you that answer, and the evidence to back it, kept current as your systems and their risk tiers change.
Four tiers, from banned to free
The need starts with classification: the higher the risk, the heavier the duties. Most AI sits at the lower tiers with little or nothing to do, while the most harmful uses at the top are prohibited outright. Select a tier to see what it demands and what Rizzqo tracks.
Unacceptable risk
Banned outright
A small set of AI uses are considered a clear threat to people and are not allowed on the market at all.
- Social scoring of people by public authorities
- Manipulative or deceptive systems that exploit vulnerabilities
- Untargeted scraping of faces to build recognition databases
- Real-time remote biometric identification in public, save narrow exceptions
High risk
Allowed, but heavily regulated
AI used in areas like hiring, credit, critical infrastructure, education or essential services. Permitted only when strict obligations are met.
- A risk management system across the whole lifecycle
- Data governance and quality controls on training data
- Technical documentation and automatic event logging
- Human oversight, accuracy, robustness and cybersecurity
- Conformity assessment before the system reaches the market
Limited risk
Tell people they are dealing with AI
Systems that interact with people or generate content carry transparency duties so no one is misled.
- Chatbots and assistants must disclose that they are AI
- Generated or manipulated media must be labelled
- Deepfakes and synthetic content must be marked as such
- Emotion-recognition use must be made known to those affected
Minimal risk
Free to use
The vast majority of AI (spam filters, recommendation engines, game AI) carries no new legal obligations under the Act.
- No mandatory obligations under the Act
- Voluntary codes of conduct are encouraged
- Good practice still applies for trust and quality
Six duties every high-risk system must meet
These are the obligations that turn a high-risk classification into real engineering and governance work. Rizzqo keeps every one of them owned, on track and backed by evidence.
Risk management system
A continuous, documented process to identify, evaluate and reduce risks across the system lifecycle.
Data governance
Training, validation and testing data must be relevant, representative and as free of errors as possible.
Human oversight
People must be able to understand, intervene in and override the system while it is in use.
Documentation & logging
Technical documentation and automatic event logs that make the system traceable after deployment.
Accuracy & robustness
Appropriate levels of accuracy, robustness and cybersecurity, sustained throughout the lifecycle.
Conformity assessment
Demonstrated conformity, with documentation and CE marking, before the system is placed on the market.
The dates that set your deadlines
The Act applies in waves. Prohibitions came first; obligations for general-purpose and high-risk AI follow on a staggered schedule.
The Act enters into force
The regulation is adopted and the countdown to each obligation begins.
Banned practices apply
Unacceptable-risk uses become prohibited and AI literacy duties take effect.
General-purpose AI rules
Obligations for general-purpose AI models, including transparency and governance, start to apply.
Most high-risk rules apply
The bulk of high-risk obligations become enforceable for systems in scope.
Remaining high-risk rules
High-risk AI embedded in already-regulated products reaches its full deadline.
Classify, control, prove
Rizzqo turns the Act from a legal text into something you can actually run, classify what you have, put the right duties in the right hands, and let the proof build as you go.
Classify your AI systems
Every AI system placed in its risk tier, so you know exactly which duties apply, and which systems you can stop worrying about.
- Clear tier for every system
- Only the duties that truly apply
- Low-risk systems off your worry list
Assign controls and oversight
Every duty gets an owner and a clear place in the plan, so human oversight, risk management and data governance stop being paragraphs and start being work someone is accountable for.
- A named owner for every duty
- Accountability visible at a glance
- Nothing left unassigned before the deadline
Prove conformity
Know where you stand at a glance, and reach a conformity assessment with the documentation and evidence already prepared, not scrambled together at the last minute.
- See exactly where you stand
- Evidence that builds as you work
- Audit-ready, not last-minute
Part of one AI governance picture
The EU AI Act rarely stands alone. The same systems carry data-protection, information-security and AI-management duties, and Rizzqo runs them on one set of assets so a control proven once counts everywhere.
Know your tier before the deadline knows it for you.
Classify your AI systems, apply the obligations that match, and walk into a conformity assessment with the evidence already in hand.