Step 1 — risk classification for your AI system
The EU AI Act regulates AI systems on a risk-tiered basis. Classify yours:
Tier 0 — Prohibited (Article 5): manipulation exploiting vulnerabilities; social scoring by public authorities; real-time remote biometric ID in public spaces (narrow exceptions); predictive policing based solely on profiling; untargeted scraping of facial images; emotion inference in workplaces and educational institutions (narrow exceptions); biometric categorization inferring race, political opinions, sexual orientation, etc. If your system matches any prohibited practice, you cannot ship it in the EU. Penalties up to €35m or 7% worldwide turnover.
Tier 1 — High-risk (Annex III): AI systems used in: (1) biometric identification + categorization not prohibited; (2) management of critical infrastructure; (3) education and vocational training (admissions, scoring, behavior detection); (4) employment, worker management, access to self-employment (recruitment screening, performance evaluation); (5) access to private/public services and benefits (credit scoring, eligibility); (6) law enforcement; (7) migration, asylum, border control; (8) administration of justice. Plus safety components of products in Annex I (medical devices, machinery, automotive, etc.).
Tier 2 — Limited risk (Article 50 transparency): AI systems that interact with natural persons (chatbots), emotion recognition / biometric categorization systems, generative AI producing synthetic content. Article 50 transparency obligations apply.
Tier 3 — Minimal risk: everything else. Largely unregulated beyond GPAI provider downstream obligations.
Practical for B2B SaaS: most B2B SaaS lands in Tier 2 or Tier 3. HR-tech, credit-tech, ed-tech land in Tier 1 (Annex III). Healthcare AI as software-medical-device lands in Annex I (Tier 1 via the safety-component path). Document the classification in your AI inventory and DPIA.