EU AI Act compliance, built on the Act's own four risk tiers

EU AI Act teams need to know which AI systems are in scope, which risk tier each one falls into, and which duties follow. Rizzqo gives you that answer, and the evidence to back it, kept current as your systems and their risk tiers change.

4risk tiers, each with its own obligations
6core duties for high-risk systems
2026high-risk rules begin to apply

Four tiers, from banned to free

The need starts with classification: the higher the risk, the heavier the duties. Most AI sits at the lower tiers with little or nothing to do, while the most harmful uses at the top are prohibited outright. Select a tier to see what it demands and what Rizzqo tracks.

Strict obligations

High risk

Allowed, but heavily regulated

AI used in areas like hiring, credit, critical infrastructure, education or essential services. Permitted only when strict obligations are met.

What this tier requires
  • A risk management system across the whole lifecycle
  • Data governance and quality controls on training data
  • Technical documentation and automatic event logging
  • Human oversight, accuracy, robustness and cybersecurity
  • Conformity assessment before the system reaches the market

Six duties every high-risk system must meet

These are the obligations that turn a high-risk classification into real engineering and governance work. Rizzqo keeps every one of them owned, on track and backed by evidence.

Art. 9

Risk management system

A continuous, documented process to identify, evaluate and reduce risks across the system lifecycle.

Art. 10

Data governance

Training, validation and testing data must be relevant, representative and as free of errors as possible.

Art. 14

Human oversight

People must be able to understand, intervene in and override the system while it is in use.

Art. 11–12

Documentation & logging

Technical documentation and automatic event logs that make the system traceable after deployment.

Art. 15

Accuracy & robustness

Appropriate levels of accuracy, robustness and cybersecurity, sustained throughout the lifecycle.

Art. 43

Conformity assessment

Demonstrated conformity, with documentation and CE marking, before the system is placed on the market.

The dates that set your deadlines

The Act applies in waves. Prohibitions came first; obligations for general-purpose and high-risk AI follow on a staggered schedule.

Aug 2024In force
Entry into force

The Act enters into force

The regulation is adopted and the countdown to each obligation begins.

Feb 2025In force
Prohibitions

Banned practices apply

Unacceptable-risk uses become prohibited and AI literacy duties take effect.

Aug 2025In force
GPAI

General-purpose AI rules

Obligations for general-purpose AI models, including transparency and governance, start to apply.

Aug 2026Current phase
High-risk

Most high-risk rules apply

The bulk of high-risk obligations become enforceable for systems in scope.

Aug 2027Upcoming
High-risk (regulated products)

Remaining high-risk rules

High-risk AI embedded in already-regulated products reaches its full deadline.

Classify, control, prove

Rizzqo turns the Act from a legal text into something you can actually run, classify what you have, put the right duties in the right hands, and let the proof build as you go.

01

Classify your AI systems

Every AI system placed in its risk tier, so you know exactly which duties apply, and which systems you can stop worrying about.

  • Clear tier for every system
  • Only the duties that truly apply
  • Low-risk systems off your worry list
02

Assign controls and oversight

Every duty gets an owner and a clear place in the plan, so human oversight, risk management and data governance stop being paragraphs and start being work someone is accountable for.

  • A named owner for every duty
  • Accountability visible at a glance
  • Nothing left unassigned before the deadline
03

Prove conformity

Know where you stand at a glance, and reach a conformity assessment with the documentation and evidence already prepared, not scrambled together at the last minute.

  • See exactly where you stand
  • Evidence that builds as you work
  • Audit-ready, not last-minute

Part of one AI governance picture

The EU AI Act rarely stands alone. The same systems carry data-protection, information-security and AI-management duties, and Rizzqo runs them on one set of assets so a control proven once counts everywhere.

Know your tier before the deadline knows it for you.

Classify your AI systems, apply the obligations that match, and walk into a conformity assessment with the evidence already in hand.

Risk-tier classificationHigh-risk obligations mappedConformity evidence on tap